| Index | Introduction | Database | Detailed Entries | Updates | Concise List | HJT Forums | Rogues | Message Board |
If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.
See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.
Last database update :- 29th Apr, 2013
31819 items listed
You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.
Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:
A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.
Please click on the Search button
1019 results found for N
| Startup Item or Name | Status | Command or Data | Description | Tested |
|---|---|---|---|---|
| CEUSZ9TM | X | N-More.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\MoRe-N | No |
| UNC5KU | X | N-More.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\MoRe-N | No |
| dpzProtect | X | n.vbe | Added by the RUNAUTO.H WORM! | No |
| .protected | X | N/A | Smitfraud variant | No |
| /l:eng | N | N/A | Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function | No |
| /s | N | N/A | Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function | No |
| 17779Proj2002 | ? | N/A | ?? | No |
| ARCSolo Recovery | N | N/A | Backup software by Computer Associates - no longer supported | No |
| Batchreg1 | N | N/A | Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation, as that key should be deleted automatically. See here | No |
| ccApps | X | N/A | Added by the KANGAROO-A TROJAN! | No |
| DashIE | ? | N/A | Could be related to "Dash Power Shopping" tool bar in IE? | No |
| Datechecker | ? | N/A | Could be related to this? | No |
| DDT | ? | N/A | ?? | No |
| DLHelperEXE.exe | X | N/A | Downloader for Microgaming/Casino software - stealth installed | No |
| Host | X | N/A | Added by the POPDIS or STARTPAGE.F TROJANS! | No |
| hpoddt01.exe | N | N/A | Installed by the "HP Photo and Imaging Director" software. If you ask for the imaging software, this program will be started | No |
| HWinst | Y | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out | No |
| IPinst | Y | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out | No |
| IZE | ? | N/A | ?? | No |
| LASTinst | Y | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out | No |
| MC | X | N/A | Added by the SIMCSS TROJAN! | No |
| MSupdate.exe | X | N/A | CoolWebSearch parasite variant - resets home page to an adult content site | No |
| MSupdater.exe | X | N/A | CoolWebSearch parasite variant. Installs the Winshow.dll browser plugin | No |
| nAv AGENT | X | N/A | Added by the RIOSYS MACRO! Note the lower-case "n" and "v" in the name as this is not the valid Norton AntiVirus entry of the same name - indeed it closes Norton AV processes | No |
| NCClient | ? | N/A | ?? | No |
| piiserviceOE | U | N/A | Spam Inspector (nee Postal Inspector) from The Giant Company or iHateSpam from Sunbelt Software - spam filter add-ons for OE | No |
| Recover | N | N/A | Added during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete | No |
| regtmlp | ? | N/A | ?? | No |
| RTStartMute | ? | N/A | ?? | No |
| rvde | X | N/A | Related to li-speed**** | No |
| ScanRegistry | X | N/A | Added by the DINOXI or DINOXI.B WORMS! | No |
| SchedulingAgent | X | N/A | Added by the DINOXI or DINOXI.B WORMS! | No |
| SOFTinst | Y | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out | No |
| SymRun | X | N/A | Added by the KANGAROO-A TROJAN! | No |
| TDockNUndock | ? | N/A | Found on a Toshiba laptop - for use with a docking station? | No |
| TheMainStart | ? | N/A | ?? | No |
| TWarmBay | ? | N/A | Found on a Toshiba laptop. Related to hotswap bay management? | No |
| TWBbtn | ? | N/A | Found on a Toshiba laptop | No |
| UTILsInst | Y | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out | No |
| WaveTop Receiver 1 | N | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 | No |
| WaveTop Receiver 2 | N | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 | No |
| WaveTop Upload Manager | N | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 | No |
| Winlogon.exe | X | N/A | CoolWebSearch parasite variant - resets home page to an adult content site | No |
| WMBoot | N | N/A | Associated with Logitech Wingman game controllers. Not required but what does it do? | No |
| Nod3d2 Free antivirus | X | N0D32KRN.EXE | Added by the RBOT-ABQ WORM! | No |
| svtcin | X | n20050308.a.Stub.EXE | Detected by SUPERAntiSpyware as Trojan.N20050308.Process. The file is typically located in %System% | No |
| nsvcin | X | n20050308.exe | Delfin Media Viewer adware related | No |
| ntechin | X | n20050308.exe | Delfin Media Viewer adware related | No |
| tsvcin | X | n20050308.exe | Delfin Media Viewer adware related | No |
| SystemSv121 | X | n2ewma1xxsv234.exe | Added by the TIBS.TJ TROJAN! | No |
| MONPluginSrIvcs | X | n3monap23.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| MSNPluginSrIvcs | X | n3vasap23.exe | Detected by Microsoft as Backdoor:Win32/Sdbot.DI and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| [random name] | X | n?lookup.exe | PurityScan adware | No |
| [random name] | X | n?pdb.exe | PurityScan adware | No |
| [random name] | X | n?tdde.exe | PurityScan adware | No |
| [random name] | X | n?tepad.exe | PurityScan adware | No |
| anbv32 | X | nabv32.exe | Added by the TITOG.C WORM! | No |
| nacar | X | nacar.exe | Detected by McAfee as Generic PWS.y!d2u and by Malwarebytes Anti-Malware as Adware.Korad | No |
| Net Activity Diagram | U | nad.exe | Net Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start → Programs | No |
| NADaemon | N | NADAEMON.EXE | Program by NetActive which appears to be piggybacked onto some Nvidia graphics cards software. They seem to look after "digital rights management". One user reports disabling it has no detrimental affect - not required | No |
| iCn | N | NAG.EXE | iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist. Not related to the Mac icon program of the same name | No |
| Razer Naga Driver | U | NagaEpicSysTray.exe | Razer Naga gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Razer Naga Driver | U | NagaTray.exe | Razer Naga gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Naggerrunkey | N | nagger.exe | Packard Bell Free Internet Signup screen | No |
| nah_Shell | X | nah_[random].exe | Detected by Symantec as Backdoor.Snifula.E | No |
| Naimagent_UI | Y | naimag32.exe | Workstation background program for Network Associates McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan | No |
| GoOutside | X | nakedx.exe | Added by the SDBOT-AGK WORM! | No |
| Application Explorer | U | Naldesk.exe | Novell Zenworks Application Explorer Executable. "For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components." | No |
| Application Explorer | U | NalView.exe | Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications | No |
| namclean199 | X | namclean199.exe | Detected by McAfee as Downloader.a!c2a and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Startup Key | X | Name.exe | Detected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| NAMEDPIPE SYSTEM | X | namedpipe.exe | Added by the MYTOB-FH TROJAN! | No |
| nana2009 | X | nana2009.exe | Added by the POISON.PG BACKDOOR! | No |
| Ya Salam | X | NancyAjram.exe | Added by the JALABED WORM! | No |
| Nano Antivirus | X | nanoav.exe | Nano Antivirus rogue security software - not recommended, removal instructions here | No |
| Rnaomflt | U | naomf.exe | Naomi internet filtering software | No |
| Mionix NAOS 5000 | U | NAOS_Monitor.EXE | Support software for the Mionix NAOS 5000 laser gaming mouse | No |
| NAP32 | X | NAP32.exe | Premium rate adult content dialler | No |
| nvpatch | X | napatch.exe | Added by the SASSER-F WORM! | No |
| Windows Logon Service | X | napi32.exe | Added by the SPYBOT.ANDM WORM! | No |
| egikugu | X | napolecy.exe | Added by the LIOTEN.KS WORM! | No |
| napumdeadyfs | X | napumdeadyfs.exe | Detected by Sophos as Troj/Cutwail-AI and by Malwarebytes Anti-Malware as Trojan.Agent.ED | No |
| Narrator | U | Narrator.exe | Associated with the Narrator accessibility feature on Windows XP. It is used to convert text to speech | No |
| RunNarrator | U | Narrator.exe | Associated with the Narrator accessibility feature on Windows XP. It is used to convert text to speech | No |
| Windows Audio Layer | X | narsvc.exe | Added by the IRCBOT.AFT BACKDOOR! | No |
| Nas | U | nas.exe | Clearx adware | No |
| Network Administration | X | NAS.exe | Added by the ANTILAM.20.Q TROJAN! | No |
| ccApp | X | Nasty.exe | Detected by Symantec as Trojan.Obsorb | No |
| NavScan | X | Nasty.exe | Detected by Symantec as Trojan.Obsorb | No |
| 4wd!!! | X | Natal!.pif | Added by the OPASERV.AI WORM! | No |
| Natal | X | Natal.scr | Added by the OPASERV.AE WORM! | No |
| atarget | X | Natarget.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\Atarget | No |
| NateFinder | X | NateFinderUpt.exe | Detected by McAfee as Generic.dx | No |
| Nate | X | nate_as.exe | Detected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %ProgramFiles%\nate_as - see here | No |
| NATDriver | X | natsdrv.exe | Detected by Dr.Web as Trojan.DownLoader7.22726 and by Malwarebytes Anti-Malware as Trojan.Ransom | No |
| Dragon NaturallySpeaking | U | natspeak.exe | Dragon NaturallySpeaking speech recognition software from Nuance (was ScanSoft) | No |
| Natural Desktop | U | Natural Desktop.exe | Animated desktop gadget included with the Natural Desktop theme for MyColors from Stardock Corporation | No |
| Naughty.exe | X | Naughty.exe | Detected by McAfee as RDN/Generic PWS.y and by Malwarebytes Anti-Malware as Trojan.Agent.JV | No |
| Microsoft Update | X | NAV.exe | Added by the RBOT-IV WORM! | No |
| System | X | nav32.exe | Added by the RBOT-BHV WORM! | No |
| Norton Auto Protect | X | nava.exe | Added by an unidentified VIRUS, WORM or TROJAN! The file is located in %System% | No |
| Nortan Anti Virus | X | nava32.exe | Added by the FTP_ANA.C BACKDOOR! | No |
| Windows Print Spooler | X | NavAgent32.exe | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| WinNavap Service | X | navapdlls32.exe | Added by the RBOT.BLF WORM! | No |
| navapp | X | navapp.exe | NavExcel adware variant | No |
| AUTOPROTECTU | X | navapq32.exe | Added by an unidentified WORM or TROJAN! | No |
| Compaq Service Drivers | X | navapqwa.exe | Added by the SDBOT.BBQ WORM! | No |
| protecse | X | navapss32.exe | Added by the SDBOT.AFE WORM! | No |
| Norton Service Process | X | navapsvc.exe | Added by the AGOBOT-GV WORM! Note - this is not the valid Norton Anti-Virus service which has the same file and is located in %ProgramFiles%\Norton AntiVirus. This one is located in %System% | No |
| Video Process | X | Navapsvcc.exe | Added by the SPYBOT-CW WORM! | No |
| Norton Service Process | X | navapvc.exe | Added by the AGOBOT.GV BACKDOOR! | No |
| NAV Agent | Y | navapw32.exe | Background scanning process for older versions of Norton AntiVirus which continuously detects and repairs viruses and other malware | Yes |
| navapw32 | Y | navapw32.exe | Background scanning process for older versions of Norton AntiVirus which continuously detects and repairs viruses and other malware | Yes |
| Norton AntiVirus AutoProtect | Y | navapw32.exe | Background scanning process for older versions of Norton AntiVirus which continuously detects and repairs viruses and other malware | No |
| Norton Auto-Protect | Y | navapw32.exe | Background scanning process for older versions of Norton AntiVirus which continuously detects and repairs viruses and other malware | No |
| Corel Reminder | N | NAVBrowser.exe | Registration reminder for some Corel products | No |
| NavRegReminder | N | NAVBrowser.exe | Registration reminder | No |
| ScanSoft PaperPort 7 Registration Reminder | N | NAVBrowser.EXE NavLoad.ini | Registration reminder for PaperPort version 7 from Scansoft (now Nuance) | No |
| MSOfficeCfg | X | navchk.exe | Premium rate adult content dialer | No |
| NAVCheck | X | navchk.exe | Premium rate adult content dialer | No |
| QTSvc | X | navchk.exe | Premium rate adult content dialler | No |
| SchedulerMgr | X | navchk.exe | Premium rate adult content dialer | No |
| SystemService | X | navchk.exe | Premium rate adult content dialler | No |
| System Information Manager | X | Navcpe.exe | Added by the SDBOT-QB WORM! | No |
| NaverAgent | X | NaverAgent.exe | Detected by Malwarebytes Anti-Malware as Adware.K.NaverAgent. The file is located in %ProgramFiles%\naver\NaverAgent | No |
| navert.exe | X | navert.exe | Detected by Dr.Web as Trojan.Click2.51385 | No |
| Microsoft Updating | X | navguard.exe | Added by the RBOT.HW WORM! | No |
| Naviscope | U | naviscope.exe | Naviscope is a multipurpose browser enhancement that can speed up Web searches, lock out cookies, examine HTML send/receive headers, provide single-click network diagnostics, and much more | No |
| Microsoft Update | X | navmgrd.exe | Added by the SDBOT.DP BACKDOOR! | No |
| NAVMon32 | X | NAVMon32.exE | Added by the WINKO.AO WORM! | No |
| navp.exe | X | navp.exe | Added by the AGOBOT-OE WORM! | No |
| NavPass | X | NavPass.exe | Free system for gaining access to and downloading from adult content web-sites | No |
| Symantec Security Routine Addon | X | navpaw.exe | Added by the AGOBOT-ES BACKDOOR! | No |
| cpntmgc | X | navpmc.exe | Added by the SIMCSS TROJAN! | No |
| mslagent | X | navpmc.exe | Slagent adware | No |
| NAV Auto Prot | X | navprot1.exe | Added by the RBOT.ZAC WORM! | No |
| Norton AutoProtect | X | navprot32.exe | Added by the RBOT-UX WORM! Note - this is not a valid Symantec/Norton entry | No |
| NAV Auto Protect | X | navprotect.exe | Added by the RBOT.BKW WORM! Note - this is not a valid Norton AntiVirus product from Symantec | No |
| AVSTRT | X | navpsrvc.exe | Added by the FORBOT-EF WORM! | No |
| Symantec Security Routine Addon for Microsoft Windows | X | navpxaw32.exe | Added by the AGOBOT-GJ TROJAN! | No |
| NAV Scan Service | X | NAVSCAN32.EXE | Added by the SDBOT.VG WORM! | No |
| NAVSCAN32.EXE | X | NAVSCAN32.exe | Added by the SDBOT-DO WORM! | No |
| NAVSCAN64.EXE /s | X | NAVSCAN64.exe | Added by the RBOT-T WORM! | No |
| NAVSCANNER32 | X | NAVSCANNER32.EXE | Added by the RBOT.QC WORM! | No |
| Norton Antiviral Scanner | X | navscnr.exe | Added by the DELBOT-K WORM! | No |
| bootsec | X | NAVSSE.exe | Added by the FORBOT-CY WORM! | No |
| NvCplDmn | X | NAVSVC.EXE | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| Norton SpySweeper AutoUpdate | X | navsw.exe | Added by the FORBOT-AS WORM! | No |
| Norton AntiVirus Sys | X | NAVsys32.exe | Added by a variant of the WOOTBOT WORM! | No |
| NAVtask | X | NAVtask.exe | Added by the REMBOT-A BACKDOOR! | No |
| MS UniX | X | navupdate64.exe | Added by the RBOT.CRZ BACKDOOR! | No |
| NAV Auto Updates | X | navupdaters.exe | Added by the RBOT-UN WORM! | No |
| NAV Auto Updates | X | navupdaterx.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| Norton Updater | X | navupdtr.exe | Added by the SDBOT.AXV WORM! | No |
| NAVWatch | X | NAVWatcher.exe | VX2.Transponder parasite updater/installer related | No |
| NAV Auto Updates | X | navwindows.exe | Added by a variant of the SDBOT BACKDOOR! | No |
| NAV_Update | X | NAV_Update.exe | Unidentified WORM or TROJAN! | No |
| nawadll32 | X | nawadll32.exe | Added by the SDBOT-ZI WORM! | No |
| nawdll32 | X | nawdll32.exe | Added by the SDBOT-ZM WORM! | No |
| xvihkdgoy | X | naxjasb.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System% | No |
| WinDefend | X | NB.exe | Detected by Dr.Web as Trojan.MulDrop2.44757 and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
| Helloworld | X | nb32ext2.exe | Detected by Trend Micro as WORM_BOBAX.AD | No |
| RPCserv32g | X | NB32EXT2.EXE | Detected by Trend Micro as WORM_BOBAX.AD | No |
| helloworld | X | nb32ext3.exe | Detected by Trend Micro as WORM_MYTOB.JT | No |
| helloworld3 | X | nb32ext4.exe | Added by the RITDOOR.A WORM! | No |
| NBAgent | U | NBAgent.exe | Core task for Nero BackItUp version 4 which provides System Tray access and runs all backup jobs (to hard disk, Network, FTP, CD/DVD) for the files and folders that you specify to either a local folder or Nero Online Backup. Required if you have have any scheduled backups or use the Autobackup feature. Installed as part of both Nero BackItUp & Burn and Nero Multimedia Suite 10 | Yes |
| Nero BackItUp | U | NBAgent.exe | Core task for Nero BackItUp version 4 which provides System Tray access and runs all backup jobs (to hard disk, Network, FTP, CD/DVD) for the files and folders that you specify to either a local folder or Nero Online Backup. Required if you have have any scheduled backups or use the Autobackup feature. Installed as part of both Nero BackItUp & Burn and Nero Multimedia Suite 10 | Yes |
| Microsoftctfmon | X | nbb.exe | Detected by Dr.Web as Trojan.DownLoad3.6216 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| NBCore | U | NBCore.exe | Autobackup feature of Nero BackItUp version 4 which runs in the background and backs up the files and folders that you specify to either a local folder or Nero Online Backup. If there are modifications or new files, Autobackup carries out a backup update automatically, replacing the existing backup with the current one. Installed as part of both the stand alone product and Nero 9 digital media suites (CD/DVD burning, authoring, etc) | Yes |
| Nero BackItUp | U | NBCore.exe | Autobackup feature of Nero BackItUp version 4 which runs in the background and backs up the files and folders that you specify to either a local folder or Nero Online Backup. If there are modifications or new files, Autobackup carries out a backup update automatically, replacing the existing backup with the current one. Installed as part of both the stand alone product and Nero 9 digital media suites (CD/DVD burning, authoring, etc) | Yes |
| NBHGui | U | NBHGui.exe | SecurDisc support for the Nero InCD packet writing utility. "SecureDisc includes special protection properties, such as data integrity, rebuilding, encryption and duplication protection". If you don't use InCD or your optical drive doesn't support SecureDisc you can disable this | Yes |
| Nero SecurDisc client | U | NBHGui.exe | SecurDisc support for the Nero InCD packet writing utility. "SecureDisc includes special protection properties, such as data integrity, rebuilding, encryption and duplication protection". If you don't use InCD or your optical drive doesn't support SecureDisc you can disable this | Yes |
| SecurDisc | U | NBHGui.exe | SecurDisc support for the Nero InCD packet writing utility. "SecureDisc includes special protection properties, such as data integrity, rebuilding, encryption and duplication protection". If you don't use InCD or your optical drive doesn't support SecureDisc you can disable this | Yes |
| NBJ | U | NBJ.exe | Scheduler for backup jobs using Nero BackItUp in earlier versions of Nero digital media suites (CD/DVD burning, authoring, etc). If no backup jobs are scheduled this entry will remain but it will not run at start-up. If you have any scheduled backup jobs and try disabling it by a means other than the program's own option (right-click on tray icon → Settings) it will re-instate itself on the next run of Nero BackItUp | Yes |
| Nero BackItUp Scheduler | U | NBJ.exe | Scheduler for backup jobs using Nero BackItUp in earlier versions of Nero digital media suites (CD/DVD burning, authoring, etc). If no backup jobs are scheduled this entry will remain but it will not run at start-up. If you have any scheduled backup jobs and try disabling it by a means other than the program's own option (right-click on tray icon → Settings) it will re-instate itself on the next run of Nero BackItUp | Yes |
| NbkCtrl | U | NbkCtrl.exe | Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here | No |
| NovaBackup * Tray Control | U | NbkCtrl.exe | Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version number | No |
| NBKeyScan | U | NBKeyScan.exe | Nero BackItUp versions 2 thru 4 support the "Push for backup" feature that's implemented on some external hard disks - which enables the user to start a predefined backup by pushing a button on the drive. NBKeyScan is used to scan the peripherals for compatible devices and - if such devices have been found - to communicate between Nero BackItUp and the external hard drive. Installed as part of both stand alone products and Nero digital media suites (CD/DVD burning, authoring, etc) | Yes |
| Nero BackItUp | U | NBKeyScan.exe | Nero BackItUp versions 2 thru 4 support the "Push for backup" feature that's implemented on some external hard disks - which enables the user to start a predefined backup by pushing a button on the drive. NBKeyScan is used to scan the peripherals for compatible devices and - if such devices have been found - to communicate between Nero BackItUp and the external hard drive. Installed as part of both stand alone products and Nero digital media suites (CD/DVD burning, authoring, etc) | Yes |
| NotebookManager | ? | nbm.exe | Associated with Acer notebook PCs. What does it do and is it required? | No |
| Timer Setting | X | Nboot.exe | Detected by McAfee as RDN/Generic.bfr!k and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| NB Probe | U | NBProbe.exe | Monitors the status of notebooks from ASUS - including CPU (speed, temperature and fan), disk and system information | No |
| nbsession | X | nbsystem.exe | Added by the DTR BACKDOOR! | No |
| Netbios Helper | X | nbthlp.exe | Detected by McAfee as PWS-Banker.y | No |
| msgsmgr | X | nbtsdump.exe | Detected by Dr.Web as Trojan.MulDrop4.30998 | No |
| Windows Update 64 | X | nbupd64.exe | Detected by Trend Micro as WORM_WOOTBOT.JB and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| nbustrce1D | ? | nbustrce1D.exe | Device driver, possibly CD/DVD - what exactly is it and is it required in startup? | No |
| NetworkControl | X | nc.exe | NetworkControl ransomware firewall - not recommended, removal instructions here | No |
| NCD | N | ncd.exe | Norton Change Directory - from the DOS days that allows the user to change directories on their machine without typing the complete path | No |
| NetCruiser Dialer | U | NCDialer.exe | NetCruiser Dialer from NetCruiser Software. "An Internet dialer and connection monitor with features to launch applications when a connection is detected, dial and hangup at predefined times and automatic redialing of dropped connections" | No |
| name_me | X | nCkmr.exe | Detected by Dr.Web as Trojan.DownLoader7.19846 and by Malwarebytes Anti-Malware as Trojan.Downloader | No |
| NCLaunch | N | NCLAUNCH.Exe | Part of SWF Studio from Northcode Inc. - an extension to Flash. Bundled when you create a self-installing screen-saver on Win2K/XP | No |
| Nokia Connection Monitor | N | NclConf.exe | Monitors the infrared port, the serial ports and the Bluetooth for a Nokia phone connection. It is installed by the Nokia PC Suite (and Nokia PC Connectivity SDK), and the tray icon shows if a phone has been connected. If you have a conflict with another program, such as TV tuner card remote control monitor, you can disable it, and run only when needed. Available via a desktop shortcut or Start → Programs - not required | No |
| Srv RPCrom | X | NClienti386.exe | Added by the WATSOON.A TROJAN! | No |
| NclTray | N | NclTray.exe | Part of Nokia PC Suite version 5 - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." Monitors ports to see if a phone has been connected and provides System Tray access to the Connection Manager (and other PC Suite components if a phone is connected). Available via the Control Panel as "Nokia Connection Manager" | Yes |
| Nokia Status Monitor | N | NclTray.exe | Part of Nokia PC Suite version 5 - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." Monitors ports to see if a phone has been connected and provides System Tray access to the Connection Manager (and other PC Suite components if a phone is connected). Available via the Control Panel as "Nokia Connection Manager" | Yes |
| Nokia Tray Application | N | NclTray.exe | Part of Nokia PC Suite version 5 - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." Monitors ports to see if a phone has been connected and provides System Tray access to the Connection Manager (and other PC Suite components if a phone is connected). Available via the Control Panel as "Nokia Connection Manager" | Yes |
| Deewoo | X | ncntnkwd.exe | ZenoSearch adware variant | No |
| NuTCSetupEnviron | Y | ncoeenv.exe | Used by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows, so disabling this would be unwise if you are using NuTCracker or any 3rd party package that is using it. Since you might not know what is actually using it it's probably best left alone | No |
| NcpBudget | ? | ncpbudgt.exe | Related to VPN client software from WatchGuard, Lancom, NCP, Astaro, D-Link and maybe others. What does it do and is it required? | No |
| NcpMonitor | ? | ncpmon.exe | Related to VPN client software from WatchGuard, Lancom, NCP, Astaro, D-Link and maybe others. What does it do and is it required? | No |
| NcpPopup | ? | ncppopup.exe | Related to VPN client software from WatchGuard, Lancom, NCP, Astaro, D-Link and maybe others. What does it do and is it required? | No |
| Ncr3 | U | ncrcore3.exe | Network camera recording software for home/office security systems using wired or wireless Panasonic cameras that enables you to locally view, record and adjust the settings for the cameras - see here | No |
| DCASS SUBLOAD | X | ncrvs.exe | Detected by Trend Micro as WORM_RBOT.BHI | No |
| *Intelli Mouse Pro Version 2.0B* | X | ncsjapi32.exe | Added by the BUZUS-O WORM! | No |
| Intelli Mouse Pro Version 2.0B | X | ncsjapi32.exe | Added by the BUZUS-O WORM! | No |
| Nvidia Control Panel | X | ncsvc32.exe | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| Nvidia Control Panel | X | ncsvc33.exe | Detected by Malwarebytes Anti-Malware as Trojan.Sdbot. The file is located in %System% | No |
| NCSW Server | Y | NcsW.exe | LockLink access control management software. LockLink 7.0 lets users seamlessly manage both offline and online access control solutions available from IR Security & Safety | No |
| securw | X | Nctrup.exe | Added by the NOPIR.A WORM! | No |
| System Manager | X | ncvs32.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| Norton Disk Doctor | N | NDD32.EXE | Norton Disk Doctor from older versions of Norton Utilities (either as a standalone product or as part of Norton SystemWorks) - which "diagnoses and repairs a variety of disk problems. It performs several tests, checking everything from the disk's partition table to its physical surface. If Norton Disk Doctor finds a problem, it notifies you before making repairs. If you check Automatically Fix Errors, Norton Disk Doctor makes the necessary repairs automatically" | Yes |
| NDDEAGNT | ? | NDDEAGNT.EXE | WinNT default process. Network Dynamic Data Exchange (DDE) Agent, handles requests for network DDE services | No |
| Microsoft PCHealth32 | X | NDDENB.exe | Added by the PWSYAHOO-A TROJAN! | No |
| NET DEMON | X | ndemon.exe | Added by the AGOBOT-LA WORM! | No |
| Mirabilis ICQ | N | NDetect.exe | If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start → Programs | No |
| Windows Service Agent | X | ndibbeu.exe | Added by the RBOT.XVD BACKDOOR! | No |
| NDIS Adapter | X | ndis.exe | Detected by Trend Micro as WORM_SDBOT.VF | No |
| Win32 NDIS Driver | X | Ndistcp.exe | Added by the WOOTBOT.EU WORM! | No |
| Win32 NDIS | X | Ndiswin.exe | Detected by Trend Micro as WORM_RBOT.AMG | No |
| NDL Start | X | NDL.exe | Detected by Malwarebytes Anti-Malware as Trojan.Keylogger. The file is located in %CommonAppData%\HGGGXE | No |
| Video Multimedia Driver | X | ndrives32.exe | Added by the RBOT-DK WORM! | No |
| NDrv | X | NDrv.exe | PurityScan adware | No |
| Windows Security Update | X | ndsass.exe | Added by the RBOT.ESM BACKDOOR! | No |
| NDSTray | U | NDSTray.exe | ConfigFree Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required, for people who span multiple networks and want an easy way to go from wired to wireless and change addresses and other network settings, it's a must have | No |
| NDSTray.exe | U | NDSTray.exe | ConfigFree Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required, for people who span multiple networks and want an easy way to go from wired to wireless and change addresses and other network settings, it's a must have | No |
| Microsoft Windows Update | X | ndsuhyz.exe | Added by the RBOT-GVG WORM! | No |
| Compaq Services Drivers | X | ndt32.exe | Added by the RBOT.CQZ WORM! | No |
| Ndtstat | X | Ndtstat.exe | Added by a variant of the BANLOAD family of TROJANS! | No |
| NDW Start | X | NDW.exe | Detected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.STRGen | No |
| [empty] | X | ne.exe | Added by the IRCBOT-ZL TROJAN! Note - has a blank entry under the Startup Item/Name field | No |
| WINDOWS SYSTEM | X | nec.exe | Added by the MYTOB-L WORM and variants! | No |
| Necbar | N | Necbar.exe | Nec Assistant; Ark's Navigator, a graphical interface for NEC computers | No |
| NECMFK | Y | necmfk.exe | NEC wireless keyboard driver | No |
| Necutray | U | Necutray.exe | Driver for external USB storage devices (hard drives, flsh disks, etc) | No |
| nedpro0xz | X | nedpro0xz.exe | Detected by McAfee as W32/Hamweq.worm.av and by Malwarebytes Anti-Malware as Trojan.Downloader | No |
| SystemUpdate | X | Negdo.exe | Added by the CULLER-C WORM! | No |
| nemu.exe | X | nemu.exe | Detected by Kaspersky as Virus.Win32.Virut.ce and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| Price Patrol | N | neo.exe | Price Patrol by Half.com - internet shopping companion for finding the best on-line prices | No |
| MOJNPluginSrIvcs | X | neomonap23.exe | Added by the SPYBOT.MJ WORM! | No |
| neoprotect | X | neoprotect.exe | NeoProtect rogue security software - not recommended, removal instructions here | No |
| neos | X | neos.exe | Added by the BDOORB-FAM TROJAN! | No |
| neoDVDplus5 | N | neoTasks.exe | neoDVDplus video editing and DVD authoring utility from MedioStream. Superseded by neoDVD | No |
| neoTasks | N | neoTasks.exe | neoDVDplus video editing and DVD authoring utility from MedioStream. Superseded by neoDVD | No |
| Nepsa0m1P | X | Nepsa0m1P.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir% | No |
| neqprvfy.exe | ? | neqprvfy.exe | Appears to be related to the downloading of some application - possibly verifying updates? | No |
| WinXPService | X | nero.exe | Added by the IRCFLOOD.AG BACKDOOR! Note - this is not the Nero CD/DVD burning software by Ahead Software which is normally located in %ProgramFiles%\Ahead\Nero. This file is found in %System% | No |
| editsunjava | X | nerO3.exe | Detected by McAfee as BackDoor-CEP.gen.aj and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Nero 7 | X | nero32.exe | Detected by McAfee as RDN/Generic Dropper!d and by Malwarebytes Anti-Malware as Backdoor.Messa. Note - this is not a valid Nero process | No |
| NeroAutoStartClient | X | NeroASM.exe | Detected by Trend Micro as WORM_AGOBOT.VG | No |
| Ahead Software Gmbh NeroCheck | N | NeroCheck.exe | Included with some Nero digital media suites (CD/DVD burning, authoring, etc). Looks for known driver conflicts with Nero software and lists these in a log file to help the user determine what may be causing a problem. This is therefore not required if the Nero software is working correctly | Yes |
| Nero AG NeroCheck | N | NeroCheck.exe | Included with some Nero digital media suites (CD/DVD burning, authoring, etc). Looks for known driver conflicts with Nero software and lists these in a log file to help the user determine what may be causing a problem. This is therefore not required if the Nero software is working correctly | Yes |
| Nero Checker | X | nerocheck.exe | Added by the PROXY-X TROJAN! Note - this is not the legitimate file of the same name from the Nero CD/DVD burning software which is usually located in %System%. This one is located in %Windir% | No |
| NeroCheck | N | NeroCheck.exe | Included with some Nero digital media suites (CD/DVD burning, authoring, etc). Looks for known driver conflicts with Nero software and lists these in a log file to help the user determine what may be causing a problem. This is therefore not required if the Nero software is working correctly | Yes |
| NeroFilterCheck | N | NeroCheck.exe | Included with some Nero digital media suites (CD/DVD burning, authoring, etc). Looks for known driver conflicts with Nero software and lists these in a log file to help the user determine what may be causing a problem. This is therefore not required if the Nero software is working correctly | Yes |
| Sheduler | X | nerocheck.exe | Added by the TACTSLAY.B TROJAN! Note - this is not the legitmate file of the same name from the Nero CD/DVD burning software which is usually located in %System% | No |
| NeroFil | X | NeroFil.EXE | Added by the RBOT.EAM BACKDOOR! | No |
| NeroCheck | X | NeroFilter.EXE | Added by the RBOT.DAO WORM! | No |
| NeroLoader | X | NeroLoader.exe | Detected by Sophos as Troj/Bancban-EJ | No |
| Nero MediaHome | U | NeroMediaHome.exe | Nero MediaHome is a UPnP AV (Audio/Video) Media Server. This allows your computer to link up you other home entertainment electronic devices (ie, televisions, stereos) to create a unified media centre, sharing media files such as MP3's and videos | Yes |
| Nero MediaHome 4 | U | NeroMediaHome.exe | Nero MediaHome is a UPnP AV (Audio/Video) Media Server. This allows your computer to link up you other home entertainment electronic devices (ie, televisions, stereos) to create a unified media centre, sharing media files such as MP3's and videos | Yes |
| NeroMediaHome | U | NeroMediaHome.exe | Nero MediaHome is a UPnP AV (Audio/Video) Media Server. This allows your computer to link up you other home entertainment electronic devices (ie, televisions, stereos) to create a unified media centre, sharing media files such as MP3's and videos | Yes |
| NeroMediaHome | X | NeroUpgrade.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System% | No |
| SERV PacK2 | X | nerx.exe | Added by the SDBOT-ACP WORM! | No |
| Microsoft Neser Experience | X | nese.exe | Added by the RBOT-YH WORM! | No |
| MSDN | X | nese.exe | Added by the SDBOT.AHY WORM! | No |
| Net**.exe [* = random char] | X | Net**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| Net**32.exe [* = random char] | X | Net**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| system32 | X | NeT-BoT.exe | Added by the AGOBOT-LJ WORM! | No |
| d3b723be6cda7831128c70a6114bebc5 | X | net.exe | Detected by Dr.Web as Trojan.DownLoader7.13092 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| HKCU | X | net.exe | Detected by Kaspersky as Backdoor.Win32.IRCBot.rcz and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %ProgramFiles%\NetMeeting | No |
| HKLM | X | net.exe | Detected by Kaspersky as Backdoor.Win32.IRCBot.rcz and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %ProgramFiles%\NetMeeting | No |
| Policies | X | net.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%\install | No |
| Policies | X | net.exe | Detected by Kaspersky as Backdoor.Win32.IRCBot.rcz and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %ProgramFiles%\NetMeeting | No |
| Policies | X | net.exe | Detected by Kaspersky as Trojan.Win32.Buzus.emdc and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\Net | No |
| net | X | net.net | Added by the MDROP-CIF TROJAN! | No |
| net24E0EFEEsecurity | X | net24E0EFEEsecurity.cpl | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| N2PTray | U | Net2fone.exe | An Internet telephony application. Needed only if you have an account at Net2Phone, Inc | No |
| Net4Switch | U | Net4Switch.exe | ASUS Net4Switch utility as provided on their range of notebooks - which "helps users to quickly configure the notebook PC's network settings and easily switch between different network environments. A wizard guides users to create and edit configuration settings as well as diagnose problems in the settings for timely connection" | No |
| netLoader | X | net64.exe | Detected by McAfee as RDN/Generic.dx!a and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
| net905BF052security | X | net905BF052security.cpl | Detected by Malwarebytes Anti-Malware as Trojan.Agent.CPL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Microsoft Update 32 | X | neta.exe | Added by the RBOT-AMI WORM! | No |
| NetAccelerator | U | NetAccel.exe | NetAccelerator is a "software utility that optimizes your internet access up to 1200% faster!. NetAccelerator speeds all modems allowing you to download faster, browse faster, surf faster!. Only required if you find it helps improve your performance | No |
| Net Accelerator | U | NetAccelerator.exe | Rizal NetAccelerator - "Optimizing Dial-Up, Lan, Cable, DSL, and Satellite connections do you want to speed up your Internet access up to 200% - 300% ???". Only required if you find it helps improve your performance | No |
| NetAdm7 | X | NETADM7.EXE | Added by the BANCOS.F TROJAN! | No |
| Inetapi | X | Netapi.exe | Added by the NETDEVIL.14 BACKDOOR! | No |
| Netapi | X | Netapi.exe | Added by the NETDEVIL.14 BACKDOOR! | No |
| Microsoft System Checkup | X | netapi32.exe | Added by the DONK-E WORM! | No |
| netapi32 | X | netapi32.exe | Added by unidentified malware. The file is located in %System% | No |
| NetAppel | N | NetAppel.exe | NetAppel - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype | Yes |
| Netbeans | X | netbeans.exe | Added by the DELBOT-R WORM! | No |
| NetBioy Client | X | netbioy.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| 00notify33 | ? | NetBrowser.exe | Part of Best Network Security, 1st Network Admin and Corporate Network Security (and maybe others) - network-based password-protected security software that lets you impose access restrictions to all your PC workstations you have in your corporate network to stop users from tampering with them. The exact purpose of this startup entry is unknown at present | Yes |
| NetBrowser | ? | NetBrowser.exe | Part of Best Network Security, 1st Network Admin and Corporate Network Security (and maybe others) - network-based password-protected security software that lets you impose access restrictions to all your PC workstations you have in your corporate network to stop users from tampering with them. The exact purpose of this startup entry is unknown at present | Yes |
| NetBrowser.exe | ? | NetBrowser.exe | Part of Best Network Security, 1st Network Admin and Corporate Network Security (and maybe others) - network-based password-protected security software that lets you impose access restrictions to all your PC workstations you have in your corporate network to stop users from tampering with them. The exact purpose of this startup entry is unknown at present | Yes |
| boby | X | netburn.scr | Added by the BANCBAN-OX TROJAN! | No |
| Paradyne ADSL Network Driver V2.3 | X | netcfgx32.exe | Added by the DELF-EYS TROJAN! | No |
| Netline User | N | netchk.exe | Netline supplies internet related products and services and this program identifies user ID and IP information. Found installed along with the Falcon 4 game, for example | No |
| Windows Networks | X | netcog.exe | Detected by Trend Micro as WORM_MYTOB.FH | No |
| netconfig | X | netconfig.exe | Added by the NETWARE TROJAN! | No |
| Networks Configurator | X | NetConfs.exe | Added by the RBOT-OX WORM! | No |
| vtmesys | X | netcxcfm.exe | Added by a variant of the RBOT-GNA WORM! | No |
| Microsoft Network Daemon for Win32 | X | netd32.exe | Added by the SDBOT.R TROJAN! | No |
| MicrosoftNetwork Daemon for Win32 | X | NETD32.EXE | Added by the RANDEX.F WORM! | No |
| MS_NETD_WIN32 | X | netd32.exe | Added by the RANDEX.F WORM! | No |
| load32 | X | netda.exe | Added by the NIBU.E TROJAN! | No |
| netdaemon | X | netdaemon /v | Malware designed to "kill" a number of antispyware applications (SpyBot, Giant, SpyDoctor, SpySweeper, SpyHunter, Anvir, WinPatrol, and more) | No |
| xload32 | X | netdd.exe | Added by the NETSPY TROJAN! | No |
| [random name] | X | netdde.exe | PurityScan adware. Do not confuse with the legitimate Network DDE - DDE Communication (netdde.exe) process which is always located in %System% and should not figure in Msconfig/Startup! | No |
| Iusage | N | netdet.exe | Internet Usage Monitor - utility to calculate the cost and time on the internet via dial-up | No |
| NetWork Device Switch | U | NetDevSW.exe | Toshiba laptops with built-in Wi-Fi. Allows switching between Wi-Fi and internal ethernet. Only necessary if you have regular need to switch back and forward between these network interfaces. Located in Startup folder so make own shortcut to it and disable if not really necessary | No |
| 4684735485910 | X | netdll32.exe | Added by the SDBOT-DEV WORM! | No |
| Netdll32 | X | netdll32.exe | Added by the CRYPTER.A TROJAN! | No |
| Netdllex | X | netdllex.exe | Added by the CRYPTER.A TROJAN! | No |
| netfilt4 | X | netfilt4.exe | Detected by Trend Micro as TROJ_PROXY.FX | No |
| MSDRV | X | NetFilter.exe | Added by the INTERRUPDATE TROJAN! | No |
| NETFP32.EXE | X | NETFP32.EXE | Added by the AGENT.CD TROJAN! | No |
| netfxupdate | ? | netfxupdate.exe | Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan | No |
| NetFxUpdate_v1.0.3705 | ? | netfxupdate.exe | Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan | No |
| NETGEARGenie | N | NETGEARGenie.exe | NETGEARGenie network management utility | No |
| NetGuard | U | NetGuard.exe | FBM Software ZeroSpyware 2004 spyware detector and remover - real time monitor | No |
| Windows System Configuration | X | nether.exe | Added by the OPANKI-AB WORM! | No |
| ASDPLUGIN | X | netherlands.exe | AsdPlug premium rate adult content dialer | No |
| HELPER | X | Netherlands.exe | AsdPlug premium rate adult content dialer variant | No |
| Nethosts | X | Nethosts#.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen - where ~ represents a number and the file is located in %AppData% | No |
| hdlpscom | X | netilxgn.exe | Added by the RBOT-FXD WORM! | No |
| Microsoft WinUpdate | X | netip.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %System% | No |
| SystemMap32 | X | Netisp32.vbs | Added by the REDIST.C WORM! | No |
| NetworkKey | X | netkey.exe | Added by the IRCBOT-AJ TROJAN! | No |
| Net Functions Library | X | Netlib.exe | Added by the AGOBOT.AGY WORM! | No |
| Netlib | X | Netlib.exe | Added by a variant of the TOXBOT WORM! | No |
| Netlimiter | U | Netlimiter.exe | Netlimiter - "An internet traffic control tool to monitor applications which access the internet and actively control their internet traffic. Use it o set (download/upload) speed limits for applications or even single connection. NetLimiter also allows you to share your internet connection bandwidth among all applications running on your PC" | No |
| netlimiter | X | netlimiter.vbs | Detected by Malwarebytes Anti-Malware as Trojan.Agent.VBS. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| NetLink | X | netlink32.exe | Added by the GAOBOT.WO WORM! | No |
| HKCDC | X | netlog.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.RGen. The file is located in %AppData%\Microsoft | No |
| HKLMC | X | netlog.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.RGen. The file is located in %AppData%\Microsoft | No |
| policies | X | netlog.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.RGen. The file is located in %AppData%\Microsoft | No |
| Microsoft System Checkup | X | netlogin32.exe | Added by the SDBOT-GN BACKDOOR! | No |
| Netlog Music Tool | U | NetlogMusicTool.exe | Music tool for Netlog - "an online platform where users can keep in touch with and extend their social network." Automatically publishes your playlist on your profile, allowing your friends to see what your listening too and you to search for others listening to the same music. No longer appears to be available to download | No |
| vtmesys | X | netlprto.exe | Added by the RBOT-GNA WORM! | No |
| 1CmailS | ? | NETMAIL.EXE | ?? | No |
| Netman_Server.exe | X | Netman_Server.exe | Detected by McAfee as RDN/Generic.bfr!cp and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| {29123221-3AF8-488c-85DE-6B3EC59E8074} | X | netmedia.exe | NetMedia adware | No |
| Microsoft NetMeeting Associates, Inc. | X | NetMeeting.exe | Added by the LOVGATE.AB WORM! | No |
| C:\Program Files\NetMeter\NetMeter.exe | U | NetMeter.exe | "Net Meter is a small, customizable network bandwidth monitoring program for Win9x/Me/NT4/2K/XP. NetMeter is and will always stay freeware. The program has been tested extensively on Win2K/XP, but it should work just as well on all other Win32 operating systems" | No |
| NetMeter | U | NetMeter.exe | "Net Meter is a small, customizable network bandwidth monitoring program for Win9x/Me/NT4/2K/XP. NetMeter is and will always stay freeware. The program has been tested extensively on Win2K/XP, but it should work just as well on all other Win32 operating systems" | No |
| NetMon | X | netmon.exe | Added by the MIMAIL.M WORM! | No |
| Netmonw | X | Netmonw.exe | Added by the BDOOR-FX BACKDOOR! | No |
| netmsg | U | netmsg.exe | Net_Message is a small tool to send messages across the network, using the Windows Messenger Service, so there is no client install required to receive the messages. It has a number of other features as well | No |
| OpenHardwareMonitor | X | netnvm32.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeMS. The file is located in %System% | No |
| Network ODBC | X | NetODBC.exe | Detected by Symantec as W32.Snaban | No |
| netpc32.exe | X | netpc32.exe | Malware, probably a CoolWebSearch parasite variant | No |
| NetPerSec | N | NetPerSec.exe | NetPerSec - measures the real-time speed of your Internet connection | No |
| NliaClient | U | Netpia.exe | Netpia NLIA System - "In the existing Internet address system, the Domain Name System (DNS) layer runs on the IP address layer. In the NLIA system, however, the upper layer is implemented on DNS" | No |
| Netprotocol | X | netprotocol.exe | Detected by Kaspersky as Trojan.Win32.Jorik.Buterat.dp and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| NetPumper | X | NetPumperIEProxy.exe | NetPumper download manager - bundles Cydoor and SaveNow adware, see here | No |
| Premeter | U | Netratings.exe | NetRatings Premeter spyware | No |
| Help Temp Files | X | netreg.exe | Added by the FORBOT-EM WORM! | No |
| Netropa Internet Receiver | X | Netropa.exe | Netropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware | No |
| NetRun | U | NetRun.exe | NetRun - will 'RUN' a 'List' of programs only when a internet connection is detected, and close/kill the same 'List' when the connection is lost | No |
| Microsoft Synchronization Manager | X | netscape.exe | Detected by Trend Micro as WORM_SDBOT.RJ | No |
| Netscape Messenger | N | NETSCAPE.EXE | In Netscape 6 (I know for sure with 6.2.1, maybe with 6.0) Netscape.exe is the main executable file for Netscape Navigator, Netscape Mail and News, and Netscape Messenger (the new name for the embedded AIM, no doubt to make it sound like Windows Messenger, the XP version of MSN Messenger). Basically, netscape.exe can be more than just Netscape Messenger, and Messenger can be more then just AIM in disguise, depending on the version of Netscape installed | No |
| Mozilla Quick Launch | N | Netscp6.exe | Netscape 6 and Mozilla browsers | No |
| Netscp6 | N | Netscp6.exe | Netscape 6 | No |
| Messenger Protocol | X | netsender.exe | Added by the SDBOT-ACC WORM! | No |
| SystemNetwork | X | NETSERV.EXE | Added by the NETCONTROL VIRUS! | No |
| Akamai NetSession Interface | U | netsession_win.exe | Akamai download manager as used by companies such as Adobe and Corel to download and install their online products. Required for the download to start and complete but once finished it can be disabled and re-instated at a later date if needed | No |
| Bsqx | X | netsfigx.exe | Added by the AUTORUN-BDL WORM! | No |
| Lisa | X | netsfigx.exe | Added by the AUTORUN-BDL WORM! | No |
| Networks Controler | X | Netsis.exe | Detected by Sophos as W32/Rbot-NG | No |
| Microsoft | X | netsrv.exe | Added by the RBOT-GOS WORM! | No |
| NET protection system | X | netst.exe | Detected by GFI as Backdoor.Rizo.A. The file is located in %System%\Com | No |
| nstat | X | netstat.exe | Adult content dialler | No |
| Win32.Trojan.Downloader | X | netstat2.exe | Added by the PAINTER TROJAN! | No |
| NvCplScan | X | netstat32.exe | Added by the SDBOT.BRL WORM! | No |
| Mozilla Firebird v0.8 Internet Browser | X | netstats.exe | Added by the IRCBOT.MC BACKDOOR! | No |
| MSN | X | netstats.exe | Added by the IRCBOT.UXP WORM! | No |
| IPv6 STUN Service | X | netstun.exe | Added by a variant of the SDBOT BACKDOOR! | No |
| Optimum Online | X | Netsurf.exe | OptimumOnline ISP software related spyware - displays advertising popups and collects information about user activity | No |
| netsv32 | X | netsv32.exe | Added by the SDBOT-PX WORM! | No |
| Network Services | X | netsvacs.exe | Added by the GAOBOT.AIS WORM! | No |
| Internet Services | X | Netsvc.exe | Added by the MYTOB.MN WORM! | No |
| Network Service Manager | X | netsvc.exe | Added by a variant of the AGOBOT WORM! | No |
| Network Services | X | netsvc.exe | Detected by Trend Micro as WORM_AGOBOT.ML | No |
| Run Services as Application | X | netsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Services Administrator | X | netsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Spooler SubSystem Application | X | netsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Tcp Application Manager | X | netsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Windows .Net Manager | X | netsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Windows Local Services | X | netsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Windows Service Manager | X | netsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Windows Web Services | X | netsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Video Process | X | netsvcs.exe | Detected by Trend Micro as WORM_AGOBOT.LH | No |
| Google Web Services | X | netsvcss.exe | Detected by Dr.Web as Trojan.DownLoader2.17374 and by Malwarebytes Anti-Malware as Worm.Agent | No |
| winsock2 | X | netsvr.exe | Detected by Trend Micro as WORM_AGOBOT.LY | No |
| NetSwitcher Tray Application | U | NetSwTray.exe | "NetSwitcher is a great tool for mobile computer users. If you've ever had to change your network settings every time you sit down at a client's site or fumble with your IP address configuration every time you plug into your home network, NetSwitcher is the tool for you" | No |
| NetSwitcher Tray Application | U | NETSWT~1.EXE | "NetSwitcher is a great tool for mobile computer users. If you've ever had to change your network settings every time you sit down at a client's site or fumble with your IP address configuration every time you plug into your home network, NetSwitcher is the tool for you" | No |
| RSync | X | netsync.exe | Detected by Symantec as Spyware.SafeSurfing | No |
| Windows Netsystem Layer | X | Netsystem.exe | Detected by Trend Micro as WORM_RBOT.BEI | No |
| NettGain2000 Verifier | Y | NettGain2000 Verifier.exe | Part of the Starband satellite client that attempts to optimize your satellite connection to increase speed | No |
| NetTime | U | NETTIME.EXE | From a visitor - "This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols, e.g. NTP." | No |
| NetTurbo | U | netturbo.exe | NetTurbo from SharewareOnline.com. "Accelerate Your Internet Connections by up to 600%". If you find it helps your connectivity leave it enabled | No |
| netupdate32 | X | netupdate32.exe | Added by the RBOT-GQZ WORM! | No |
| Chckup | X | Netverchk.exe | Covert Sys Exec malware variant | No |
| Microsoft Internel Corporat | X | netvhost.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| netview | X | netview.exe | Added by the BIFROSE.L BACKDOOR! | No |
| ShellRun | X | netview.exe | Detected by Dr.Web as Trojan.MulDrop3.18306 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| FASTTRACKNETVISION | X | NETVISION.exe | DialCar-Z premium rate dialer | No |
| ModemOnHold | U | netWaiting.exe | NetWaiting/Modem-on-Hold - allows you to place your Internet connection on hold while you take a voice call (if Call Waiting is supported by your phone company). See here for more information | No |
| NetWatch32 | X | netwatch.exe | Added by the MIMAIL.C WORM! | No |
| Network | X | netwin.exe | Added by the SILLYFDC-CG WORM! | No |
| Win Net Wks32 | X | netwks32.exe | Detected by Trend Micro as WORM_RBOT.AA | No |
| Network controller | X | Network controller.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% | No |
| Microsoft Update 32 | X | network.exe | Added by the RBOT-ARZ WORM! | No |
| NETWORK.EXE | X | NETWORK.EXE | Added by the DELF-GM TROJAN! | No |
| NetworkClient | X | NetworkClient.exe | Added by the LEMUR WORM! | No |
| Windows Services | X | NetworkDriver32.exe | Detected by Sophos as W32/Rbot-ACR and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
| Windows Services | X | NetworkDrivers.exe | Detected by Sophos as W32/Sdbot-YO and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
| Microsoft Network Neighbourhood | X | networknbh.exe | Added by the RBOT.DMN WORM! | No |
| Microsoft Network | X | Networksystem.exe | Added by the SDBOT-AAI WORM! | No |
| Microsoft xpsp2 | X | Networksystem.exe | Added by a variant of W32/Sdbot.worm | No |
| NetWorx | N | networx.exe | NetWorx from SoftPerfect Research - "is a simple and free, yet powerful tool that helps you objectively evaluate your bandwidth situation. You can use it to collect bandwidth usage data and measure the speed of your Internet or any other network connection" | No |
| Network Sharing Center | X | netwrkcnt .exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp% | No |
| WinSig | X | NetXP.exe | Added by the BANKER-FN TROJAN! | No |
| Xpnet | X | NetXp.exe | Added by the BANCBAN-AT TROJAN! | No |
| Windows Media Upgrade | X | NeUpgrade.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| NeuroMedia(IESpeaker) | X | NeuroMedia.exe | Part of an older freeware version of IESpeaker - a program that allows you to listen to web pages. NeuroMedia.exe only downloads advertisments. Not included in the paid-for version currently available | No |
| Qffqqft | X | nevat.exe | Detected by Trend Micro as TROJ_DROPPER.CR | No |
| 2256a916c776d4838169e5d1ff3b1f29 | X | New Microsoft Word Document.exe | Detected by Dr.Web as Trojan.DownLoader6.53733 and by Malwarebytes Anti-Malware as Trojan.Dropper | No |
| VBC.EXE | X | New.exe | Detected by McAfee as Generic.dx!bh3v and by Malwarebytes Anti-Malware as Backdoor.Messa.Gen | No |
| New2Clean | X | New2CleanLaunch.exe | New2Clean rogue security software - not recommended, removal instructions here | No |
| [various names] | X | new32.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Onet.pl AutoUpdate | ? | NewAutoUpdate.exe | Related to the Onet.pl Polish web portal | No |
| Ci Servs | X | newbin.exe | Added by the RIMECUD-BC TROJAN! | No |
| [various names] | X | newbreed.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| newcontr8nd7 | X | newcont8rnd7.exe | Detected by McAfee as W32/Pinkslipbot.gen.be and by Malwarebytes Anti-Malware as Trojan.MPGen | No |
| oaiyhlyv | X | newdevi.exe | Added by the AGENT-QTM TROJAN! | No |
| Microsoft Windows DLL Services Configuration | X | newdll.exe | Added by the SDBOT-ZR WORM! | No |
| Microsoft Windows DLL Services Configuration | X | newdll2.exe | Added by the SDBOT-ABD WORM! | No |
| newdotnet.exe | X | newdotnet.exe | Detected by McAfee as Generic VB | No |
| newframework.exe | X | newframework.exe | Detected by McAfee as Generic VB | No |
| NewFrn | X | newfrn.exe | Added by the ACTUX.A TROJAN! | No |
| newlock | U | newlock.exe | Part of Access Manager, 1st Security Agent, Security Administrator and PC Security Tweaker (and maybe others) - which which let you control which users are allowed to access your PC and the level of access each user may have. You can choose to tweak access to lots of Control Panel applet functions, including Display, Network, Passwords, Printers, System, Add/Remove Programs, etc. For more details please see the "00saskda" or "zzsecagent" | Yes |
| newlock.exe | U | newlock.exe | Part of Access Manager, 1st Security Agent, Security Administrator and PC Security Tweaker (and maybe others) - which which let you control which users are allowed to access your PC and the level of access each user may have. You can choose to tweak access to lots of Control Panel applet functions, including Display, Network, Passwords, Printers, System, Add/Remove Programs, etc. For more details please see the "00saskda" or "zzsecagent" entries | Yes |
| zzsecagent | U | newlock.exe login shutdown | Part of Access Manager, 1st Security Agent, Security Administrator and PC Security Tweaker (and maybe others) - which which let you control which users are allowed to access your PC and the level of access each user may have. You can choose to tweak access to lots of Control Panel applet functions, including Display, Network, Passwords, Printers, System, Add/Remove Programs, etc. This entry is enabled if you select to start the Screen Lock feature when booting via Restrictions → Common Restrictions → Boot → Always Check Password on Boot | Yes |
| 00saskda | ? | newlock.exe saskda | Part of Access Manager, 1st Security Agent, Security Administrator and PC Security Tweaker (and maybe others) - which let you control which users are allowed to access your PC and the level of access each user may have. You can choose to tweak access to lots of Control Panel applet functions, including Display, Network, Passwords, Printers, System, Add/Remove Programs, etc. The exact purpose of this startup entry is unknown at present but it appears to be related to the "Screen Lock" feature | Yes |
| DivXCodec | X | NEWMAIL.exe | Added by the DELF-RQ BACKDOOR! | No |
| SystemSv12 | X | newmaxxsv234.exe | Added by the TIBS-TS TROJAN! | No |
| AutoStart PC Studio | N | NewPCStudio.exe | SAMSUNG New PC Studio - "is the application to organize the contents between Samsung mobile and PC. NPS provides you with convenient access to your device, data management via easy backup and sync, and powerful multimedia features". This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menu | Yes |
| New PC Studio | N | NewPCStudio.exe | SAMSUNG New PC Studio - "is the application to organize the contents between Samsung mobile and PC. NPS provides you with convenient access to your device, data management via easy backup and sync, and powerful multimedia features". This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menu | Yes |
| NewPCStudio | N | NewPCStudio.exe | SAMSUNG New PC Studio - "is the application to organize the contents between Samsung mobile and PC. NPS provides you with convenient access to your device, data management via easy backup and sync, and powerful multimedia features". This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menu | Yes |
| popuppers | X | newpop63.exe | Medload adware | No |
| newprotect | X | newprotect_up.exe | NewProtect rogue security software - not recommended, removal instructions here | No |
| Newsalrt | N | NEWSALRT.EXE | MSNBC News system tray utility to alert you to new news | No |
| newsfeed12 | X | newsd.exe | Detected by Trend Micro as TROJ_AGENT.MX | No |
| supernews12 | X | newsd32.exe | Adware, also detected as the DLOADER-JN TROJAN! | No |
| MySoftware NewsFlash | N | Newsflsh.exe | Runs in your task bar and receives alerts and release information on MySoftware products from Avenquest | No |
| Newsgroup lptt01 | X | newsgroup.exe | RapidBlaster variant (in a "newsgroup" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| Newsgroup ml097e | X | newsgroup.exe | RapidBlaster variant (in a "newsgroup" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| InstallProvider | X | newsoftware2007install.exe | Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended | No |
| NewsUpd | N | newsupd.exe | For Creative Soundblaster Live! series soundcards. System tray application for News updates. Available via Start → Programs. Also spyware - see here. | No |
| NewtonKnowsUpd | X | NewtKnow.exe [path] NewtnUpd.dll,runkey | NewtonKnows spyware. Both files are located in %ProgramFiles%\Newton Knows | No |
| newupelevmds | X | newupelevmds.exe | Detected by Malwarebytes Anti-Malware as Adware.Kraddare. The file is located in %ProgramFiles%\newupelev | No |
| HELPER | X | new_zealand.exe | AsdPlug premium rate adult content dialer variant | No |
| Nex | X | nex.exe | Added by the AGENT-FPQ TROJAN! | No |
| Nexus Radio | N | Nexus Radio.exe | Nexus Radio by Talam Group, LLC - "is a free internet radio service that allows members to listen to music, and create unique personal profiles in order to communicate with other Nexus Radio members" | No |
| Nexus | U | Nexus.exe | Nexus Dock by Winstep - "is a FREE professional dock for Windows. With Nexus, your most frequently used applications are only a mouse click away - and Nexus turns working with your computer into a fun and exciting experience" | No |
| HKCU | X | nfconfig.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBKrypt. The file is located in %Windir%\install | No |
| HKLM | X | nfconfig.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBKrypt. The file is located in %Windir%\install | No |
| Policies | X | nfconfig.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBKrypt. The file is located in %Windir%\install | No |
| Nfo | X | nfomon.exe | PromulGate adware | No |
| NGClient | U | ngctw32.exe | Symantec Ghost Server software - needed for a "a Ghost multicast" (transfer images to multiple machines). Can be launched manually | No |
| Windows Global Init | X | ngpsvc.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| ngpw36 | X | ngpw36.exe | AdBlaster adware | No |
| Norton GProtect | X | ngrfn.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| NGServer | N | ngserver.exe | Symantec/Norton Ghost Console service | No |
| nHancer | U | nHancer.exe | System Tray access to nHancer which is an advanced control panel and profile editor for NVIDIA graphic cards - offering enhanced features above those available via the standard NVIDIA control panel such as additional Anti-Aliasing and Anisotropic Filtering modes | Yes |
| NotebookHardwareControl | U | nhc.exe | "With Notebook Hardware Control you can easily control the hardware components of your Notebook" | No |
| lMKuOKzbgaiwaEB_RwVlzLCjHA | X | NIamMWNHdGknyQ.exe | Detected by Sophos as Troj/Ranbyus-I and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| WDNS SYSTEM | X | nibie.exe | Added by the MYTOB-BY WORM! | No |
| WINDOWS SYSTEM | X | nibie.exe | Added by the MYTOB-BY WORM! | No |
| WinXP CentOS Driver | X | nicloader.exe | Detected by Trend Micro as WORM_AGOBOT.ALF | No |
| nieguideplus | X | nieguideup.exe | Detected by Malwarebytes Anti-Malware as Adware.K.IEGuide. The file is located in %ProgramFiles%\nieguideplus | No |
| NetMeter | U | NielsenOnline.exe | Neilsen//NetRatings NetMeter market research software - provides "the industry's global standard for Internet and digital media measurement and analysis, offering technology-driven Internet information solutions for media, advertising, ecommerce and financial companies" | No |
| NielsenOnline | U | NielsenOnline.exe | Neilsen//NetRatings NetSight market research software - provides "the industry's global standard for Internet and digital media measurement and analysis, offering technology-driven Internet information solutions for media, advertising, ecommerce and financial companies" | No |
| CostAware | U | niIPCApp.exe | NetInternals CostAware - download quota measuring tool | No |
| Nike+ Connect | N | Nike+ Connect daemon.exe | Related to the Nike+ range of running accessories such as the Nike+ SportBand | No |
| Nike+ Utility | N | Nike+ Utility.exe | Related to the Nike+ range of running accessories such as the Nike+ SportBand | No |
| nikLaus | X | nikLaus.exe | Added by the NIKLAS WORM! | No |
| Net-It Launcher | N | NILaunch.exe | Net-It - web publishing software | No |
| Windows Service Agent | X | nimcoo.exe | Added by the RBOT.EWV WORM! | No |
| WINDOWS SYSTEM | X | ninfoie.exe | Added by the MYTOB-EP WORM! | No |
| NInit | N | NInit.exe | Norton Uninstall Deluxe. Monitors programs being installed and logs them for removing later. Available via Start → Programs for manual logging - not required | No |
| Microsoft Winedows Updateing | X | NinKey.exe | Added by a variant of the SPYBOT WORM! See here | No |
| Microsoft Winedows Updateing | X | NinKey.exe | Detected by McAfee as W32/Sdbot.worm!mk | No |
| Run Nintendo Wi-Fi USB Connector Registration Tool | U | NintendoWFCReg.exe | Related to Wi-Fi USB Connector from Nintendo | No |
| iPrint LPT Redirector | ? | nipplpte.exe | Related to Novell® iPrint - a "best-of-breed printing solution for businesses running as traditional enterprises, for those operating entirely on the Net, and for those anywhere on the large spectrum in between." Is it required? | No |
| NiroFile Updated | X | NiroFile.exe | Added by a variant of the IRCBOT TROJAN! | No |
| nisdisa | X | nisdisa.exe | Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example | No |
| nisserv | Y | NISSERV.EXE | Part of Symantec's now discontinued Norton Personal Firewall and also included in older versions of Norton Internet Security. Also part of their now discontinued Symantec Client Firewall (part of Symantec Client Security for business customers). Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| Nisum | Y | NISUM.EXE | Part of Symantec's now discontinued Norton Personal Firewall and also included in older versions of Norton Internet Security. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| niSvcLoc | U | niSvcLoc.exe | Related to National Instruments Corp. LabView | No |
| WinNite | X | niteaim.exe | Added by the OPANKI.B WORM! | No |
| Wkyo86 | X | Nitip.exe | Added by the PITIN-A WORM! | No |
| Nitro PDF Printer Monitor | U | NitroPDFPrinterMonitor.exe | Printer monitor for Nitro PDF Professional from Nitro PDF, Inc. - "complete, affordable and easy-to-use set of tools to work with PDF documents" | No |
| Microsoft Security Monitor Process | X | nitty.exe | Added by the RBOT.AEU BACKDOOR! | No |
| niu | X | niu.exe | Added by the SILLYFDC.BCS WORM! | No |
| Video Process | X | Nivopsvc.exe | Added by the AGOBOT-GT WORM! | No |
| NJG40 | X | NJG40.EXE | Added by the BANCOS.D TROJAN! | No |
| Boot Manager | X | Njgal.exe | Added by the KILO TROJAN! | No |
| NJIL | X | njil.exe | Added by the DELF-ELF TROJAN! | No |
| BArVzWJrY | X | njUOghDDY.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Msn Messenger | X | nkbf.exe | Added by the RBOT-GMQ WORM! | No |
| NkbMonitor.exe | N | NkbMonitor.exe | Part of Nikon PictureProject - image management for Nikon digital cameras | No |
| Nikon Message Center 2 | N | NkMC2.exe | Application for Nikon digital camera products that informs users of the latest information regarding updates to Nikon software and firmware upgrades. Currently supports the Camera Control Pro and ViewNX applications | No |
| Nikon Monitor | N | nkmonitor.exe | Monitors for a Nikon CoolPix camera being connected via USB port. As soon as it detects a CoolPix camera it executes the Nikon View software to enable the user to transfer images from the camera to the PC | No |
| MSN Service Utilities | X | nkn.exe | Added by the KELVIR-BC WORM! | No |
| Nvidia Control Daemon | X | nksvc32.exe | Added by an unidentified WORM or TROJAN! | No |
| NkvMon.exe | N | NkvMon.exe | Nikon View 5 - for transferring pictures from Nikon digital cameras | No |
| NkVwMon.exe | N | NkVwMon.exe | Nikon View - for transferring pictures from Nikon digital cameras | No |
| Nkwkwx | X | Nkwkwx.scr | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %AppData% | No |
| Microsoft (R) Windows Network Latency Controller | X | nlc.exe | Added by a generic password stealer TROJAN - see here | No |
| Microsoft Update Machine | X | nlczty.exe | Added by the RBOT-GUR WORM! | No |
| sv18h5jckqdfo6zgc2i0nlzh0uwz2q93wa | X | nlkptmqe.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %System% | No |
| NaviSearch | X | nls.exe | NaviSearch adware | No |
| NLS Monitor | X | nlsmon.exe | Added by the RBOT-AXJ WORM! | No |
| foffice | X | nm.exe | Added by the DELF-CB TROJAN! | No |
| ujm | U | nm32.exe | Stranget keystroke logger/monitoring program - remove unless you installed it yourself! Found in %Windir%\fyt | No |
| nmapp | U | nmapp.exe | Pure Networks "Network Magic eliminates common frustrations and saves time by simplifying and automating set up, management and repair of home networks, and makes printer and file sharing effortless" | No |
| Microsof Value | X | nmatt.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} | U | NMBgMonitor.exe | Looks for new files which can be included in Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 7 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the link. If you have trouble disabling Nero Scout try here | Yes |
| Nero Home | U | NMBgMonitor.exe | Looks for new files which can be included in Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 7 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the link. If you have trouble disabling Nero Scout try here | Yes |
| NMBgMonitor | U | NMBgMonitor.exe | Looks for new files which can be included in Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 7 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the link. If you have trouble disabling Nero Scout try here | Yes |
| NMBgMonitor.exe | X | NMBgMonitor.exe | Added by the BRAVO-G TROJAN! Note - this is not the legitimate Nero Scout entry, which is normally located in %CommonFiles%\Nero\Lib. This one is located in %System% | No |
| NetManageImport | U | nmcpdata.exe | NetManage business software related | No |
| nmctxth | U | nmctxth.exe | Related to Pure Networks comprehensive home and small business networking software that simplifies network configuration | No |
| [various names] | X | nmdllw.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Nero Home | Y | NMFirstStart.exe | Appears to be related to the first run of Nero Home, which "combines television and the recording of television programs with playback of DVD-Videos and audio/video files in an easy-to-use interface" and "can also catalog them and organize them into individual libraries." Included in versions 7 and 8 of Nero digital media suites (CD/DVD burning, authoring, etc). Loads only on the first reboot after installation via the HKCU\RunOnce key | Yes |
| NeroHomeFirstStart | Y | NMFirstStart.exe | Appears to be related to the first run of Nero Home, which "combines television and the recording of television programs with playback of DVD-Videos and audio/video files in an easy-to-use interface" and "can also catalog them and organize them into individual libraries." Included in versions 7 and 8 of Nero digital media suites (CD/DVD burning, authoring, etc). Loads only on the first reboot after installation via the HKCU\RunOnce key | Yes |
| IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} | U | NMIndexStoreSvr.exe | Indexing and storage service for Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 8 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the link | Yes |
| Nero Home | U | NMIndexStoreSvr.exe | Indexing and storage service for Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 8 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the link | Yes |
| NMIndexStoreSvr | U | NMIndexStoreSvr.exe | Indexing and storage service for Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 8 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the link | Yes |
| _Cat1 | X | nmmst.exe | Detected by Trend Micro as TROJ_SMALL.SD | No |
| System Document Application | X | nmod.exe | Added by the SDBOT-ABB WORM! | No |
| Microsoft Software Update | X | nmon.exe | Added by the RBOT.HZ WORM! | No |
| NMPSystray | U | NMPSystray.exe | System Tray access to NotesMedic from Cassetica Software Inc. - which "contains a suite of Tools that make life easier when using Lotus Notes" | No |
| Riau | X | nmrc.exe | PurityScan adware | No |
| Windows driver update | X | nmsmtp32.exe | Added by the SDBOT-JT WORM! | No |
| NMSSvc | ? | NMSSVC.EXE | NIC Management Service - diagnostics program for Intel Pro family network cards | No |
| _Cat2 | X | nmstt.exe | Detected by Kaspersky as Trojan-Downloader.Win32.Small.ahg. The file is located in %Windir% | No |
| NMSVC | Y | nmSvc.exe | Covenant Eyes - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Disabling it means loss of internet connection until renabled - therefore required if you use it | No |
| nMTaskBarService | ? | nMtsk.exe | Taskbar control for ISDN NetMod modem. What does it do and is it required? | No |
| Windows Zero Spooler | X | nmvcs.exe | Added by the SLENFBOT.JQ WORM! | No |
| Windows Audio Components | X | nncsvc.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
| Windows Audio Startup | X | nndsvc.exe | Added by the IRCBOT-AAE TROJAN! | No |
| Windows Audio System | X | nndsvc.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
| NNLL | U | nnll.exe | Net Nanny internet filter | No |
| Norton Navigator Loader | N | nnloader.exe | An older Norton utility for file management under Windows 95. More information here | No |
| nmgr | X | nnmgr.exe | FFToolBar adware toolbar | No |
| nnqcouu | X | nnqcouu.exe | The Abi Network adware | No |
| NeroNETTrayIcon | N | NNServiceCtrl.exe | System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network | No |
| NNTray | U | nnstart.exe | Net Nanny internet filter | No |
| NNSvc | U | nnsvc.exe | Net Nanny internet filter. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| IBM Lotus Notes Preloader | ? | nntspreld.exe | Preloader for IBM Lotus Notes. Is it required on modern, faster systems? | No |
| Microsoft Update | X | nnwyaupdt | Added by the RBOT.RHK BACKDOOR! | No |
| PopUp Stopper | X | NO POPUP.EXE | Added by the SPYBOT-DC WORM! | No |
| System Information Manager | X | no.exe | Added by the SPYBOT.NO WORM! | No |
| NoAds | U | NoAds.exe | Blocks advertisement banners in Internet Explorer | No |
| NoAdware | X | NoAdware.exe | NoAdware - spyware remover. This version is not recommended - see here | No |
| NoAdware3 | U | NoAdware3.exe | NoAdware - spyware remover. Initially not recommended due to false positives and aggressive advertising but the later versions have since improved - see here | No |
| NoAdware4 | U | NoAdware4.exe | NoAdware - spyware remover. Initially not recommended due to false positives and aggressive advertising but the later versions have since improved - see here | No |
| nobfudycomal | X | nobfudycomal.exe | Detected by Sophos as Troj/Bckdr-RPP and by Malwarebytes Anti-Malware as Trojan.Ransom.Gen | No |
| NortonOnlineBackupReminder | N | NobuActivation.exe | Activation reminder for Norton Online Backup | No |
| Dell DataSafe Online | U | NOBuClient.exe | System Tray access to and notifications for the Dell DataSafe Online storage utility | Yes |
| NOBuClient | U | NOBuClient.exe | System Tray access to and notifications for Symantec's Norton Online Backup and Dell DataSafe Online storage utilities | Yes |
| Norton Online Backup | U | NOBuClient.exe | System Tray access to and notifications for Symantec's Norton Online Backup online storage utility | Yes |
| NortonOnlineBackup | U | NOBuClient.exe | System Tray access to and notifications for Symantec's Norton Online Backup online storage utility | Yes |
| ActiveScript32 | X | nod.exe | Added by the SOHANA-AJ WORM! | No |
| Nod23 Service | X | nod23.exe | Added by the RBOT-GMK WORM! | No |
| nod32 antivirus | X | nod32.exe | Added by the VB-FFT TROJAN! Note - this is not Eset's NOD32 antivirus | No |
| Windows Service Agent | X | nod32.exe | Added by the RBOT.BNG BACKDOOR! | No |
| NOD321 | X | NOD321.exe | Detected by McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| Nod32CC | U | nod32cc.exe | Control Center part of Eset's NOD32 antivirus. Leave this enabled if you want to update your virus data files via the click of a button | No |
| Nod32 Free antivirus | X | nod32krn.exe | Added by the RBOT-AAO WORM! Note - this is not Eset's NOD32 antivirus which shares the same filename and is normally found in %ProgramFiles%\Eset. This one is located in %System% | No |
| NOD32kernel | Y | Nod32krn.exe | Eset's NOD32 antivirus. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| nod32kui | Y | nod32kui.exe | Eset's NOD32 antivirus | No |
| Nod32 Service | X | nod6.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Nod32 Service | X | nod64.exe | Added by the RBOT.ESJ WORM! | No |
| nodsos | X | nodabc.exe | Added by the PWS-BLE TROJAN! | No |
| NodeMnger | ? | Nodemngr.exe | Part of the Dell OpenManage Client installation - to allow Dell representatives to remote logon? | No |
| NoDNS | X | NoDNS.exe | Added by the CLICKER.WI TROJAN! | No |
| nod32 | X | nodqq.exe | Detected by Sophos as W32/Autorun-BBV | No |
| Nod29 Service | X | nodwr.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| NTsocket | X | NoeWinnt.exe | Detected by Sophos as Troj/Ataka-E | No |
| NOFIIN.EXE | X | NOFIIN.EXE | Added by the HAXDOOR-DP TROJAN! | No |
| WINDOWS-SHELL | X | nofud.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| Nokia Check | X | nokiacheck.exe | Added by the RBOT.CDC WORM! | No |
| Nokia M Platform | U | NokiaMServer | Part of Nokia Ovi Player (and the older Nokia Music) music manager, Nokia Photos photo and video manager or Nokia Ovi Suite mobile device manager. Used to watch for any new file types that have been associated with these utilities | Yes |
| NokiaMServer | U | NokiaMServer | Part of Nokia Ovi Player (and the older Nokia Music) music manager, Nokia Photos photo and video manager or Nokia Ovi Suite mobile device manager. Used to watch for any new file types that have been associated with these utilities | Yes |
| Nokia FastStart | N | NokiaMusic.exe | Part of the Nokia Music music manager - which has now been replaced by Ovi Player. "With Nokia Music, you can play music, discover and buy new music, transfer music between your compatible PC and your compatible Nokia mobile devices, and rip and burn audio CDs". If enabled, this entry will reduce the time taken for Nokia Music to run by a few seconds for the first time after Windows has loaded | Yes |
| Nokia Music | N | NokiaMusic.exe | Part of the Nokia Music music manager - which has now been replaced by Ovi Player. "With Nokia Music, you can play music, discover and buy new music, transfer music between your compatible PC and your compatible Nokia mobile devices, and rip and burn audio CDs". If enabled, this entry will reduce the time taken for Nokia Music to run by a few seconds for the first time after Windows has loaded | Yes |
| NokiaMusic | N | NokiaMusic.exe | Part of the Nokia Music music manager - which has now been replaced by Ovi Player. "With Nokia Music, you can play music, discover and buy new music, transfer music between your compatible PC and your compatible Nokia mobile devices, and rip and burn audio CDs". If enabled, this entry will reduce the time taken for Nokia Music to run by a few seconds for the first time after Windows has loaded | Yes |
| Nokia Ovi Player | N | NokiaOviPlayer.exe | Part of the Nokia Ovi Player - which is "a free PC application for playing and organising your music, discovering and downloading new music on Ovi, transferring songs and playlists between your compatible PC and compatible Nokia mobile devices, and ripping and burning your audio CDs". If enabled, this entry will reduce the time taken for Nokia Music to run by a few seconds for the first time after Windows has loaded | Yes |
| NokiaMusic FastStart | N | NokiaOviPlayer.exe | Part of the Nokia Ovi Player - which is "a free PC application for playing and organising your music, discovering and downloading new music on Ovi, transferring songs and playlists between your compatible PC and compatible Nokia mobile devices, and ripping and burning your audio CDs". If enabled, this entry will reduce the time taken for Nokia Music to run by a few seconds for the first time after Windows has loaded | Yes |
| NokiaOviPlayer | N | NokiaOviPlayer.exe | Part of the Nokia Ovi Player - which is "a free PC application for playing and organising your music, discovering and downloading new music on Ovi, transferring songs and playlists between your compatible PC and compatible Nokia mobile devices, and ripping and burning your audio CDs". If enabled, this entry will reduce the time taken for Nokia Music to run by a few seconds for the first time after Windows has loaded | Yes |
| Nokia Ovi Suite | N | NokiaOviSuite.exe | First generation of Nokia Ovi Suite for managing Nokia mobile devices - "gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer, and experience a new way of browsing your photos, videos and music. Furthermore, you can share photos quickly and safely through the Share on Ovi service" | Yes |
| Nokia Ovi Suite 2 | N | NokiaOviSuite.exe | Second generation of Nokia Ovi Suite for managing Nokia mobile devices - which "gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer, and experience a new way of browsing your photos, videos and music. Furthermore, you can share photos quickly and safely through the Share on Ovi service" | Yes |
| NokiaOviSuite | N | NokiaOviSuite.exe | Nokia Ovi Suite for managing Nokia mobile devices - "gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer, and experience a new way of browsing your photos, videos and music. Furthermore, you can share photos quickly and safely through the Share on Ovi service" | Yes |
| NokiaOviSuite.exe | N | NokiaOviSuite.exe | First generation of Nokia Ovi Suite for managing Nokia mobile devices - "gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer, and experience a new way of browsing your photos, videos and music. Furthermore, you can share photos quickly and safely through the Share on Ovi service" | Yes |
| NokiaOviSuite2 | N | NokiaOviSuite.exe | Second generation of Nokia Ovi Suite for managing Nokia mobile devices - which "gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer, and experience a new way of browsing your photos, videos and music. Furthermore, you can share photos quickly and safely through the Share on Ovi service" | Yes |
| NokKernel install | U | Nok_install.exe | Installer for the NokNet Workstation Monitor surveillance software. Uninstall this software unless you put it there yourself | No |
| NomdCheck | N | nomdchek.exe | Part of Intel's Native Audio | No |
| Microsoft Explorer2 | X | nome.exe | Detected by Trend Micro as WORM_RANDEX.AA | No |
| nomtray | U | nomtray.exe | System Tray access to NetMotion Wireless options - including connectivity status (see here) | No |
| Nonoh | N | Nonoh.exe | Nonoh - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype | Yes |
| Microsoft Nod32 Service | X | nood32.exe | Added by the RBOT.EJP WORM! | No |
| Eptr | X | nopdb.exe | Added by an unidentified WORM or TROJAN! | No |
| NOPDBS | X | NOPDBS.exe | Added by the BANCBAN-AS TROJAN! | No |
| [various names] | X | NopeZ.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| NoPopUp | U | nopopup.exe | NoPopUp 2003 by NEXT-Soft - popup blocker | No |
| Bron-Spizaetus | X | norBtok.exe | Added by the RONTOKBRO.B WORM! | No |
| Nord | X | nordsys.exe | Added by the DREF-S WORM! | No |
| normally.exe | X | normally.exe | Detected by Dr.Web as Trojan.DownLoader8.24079 and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| NortE Antivirus | X | norte.exe | Detected by Trend Micro as WORM_RBOT.BQQ | No |
| NortE Antivirus | X | norten.exe | Added by the RBOT-AFF WORM! | No |
| norten Software Intrenet | X | norten.pif | Added by the RBOT-AWA WORM! | No |
| Protection | X | Norton Internet Security.exe | Added by the ELITPER.E WORM! | No |
| Wxp4 | X | Norton Update.exe | Added by the ERKEZ.D WORM! | No |
| Microsoft Norton Antivirus | X | norton.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| System Service Manager | X | norton.exe | Added by the GAOBOT.AJE WORM! | No |
| Windows System Service Configuration Loader | X | norton.exe | Added by the AGOBOT.GN WORM! | No |
| MS Unix Binary | X | Norton2005Update.exe | Added by a variant of the RBOT WORM! | No |
| norton32 | X | norton32.exe | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| Norton AntiBot | Y | NortonAntiBot.exe | Control Center for Norton Antibot from Symantec - which "provides advanced, real-time protection against emerging threats, including bots that are used to perpetrate identity theft and other online crimes" and "protects your PC from unauthorized access and tampering, detects and stops attempts by hackers to take remote control of your computer, and delivers extra protection against emerging 'zero-day' threats." Designed to work with existing antivirus software but now discontinued | Yes |
| NortonAntiBot | Y | NortonAntiBot.exe | Control Center for Norton Antibot from Symantec - which "provides advanced, real-time protection against emerging threats, including bots that are used to perpetrate identity theft and other online crimes" and "protects your PC from unauthorized access and tampering, detects and stops attempts by hackers to take remote control of your computer, and delivers extra protection against emerging 'zero-day' threats." Designed to work with existing antivirus software but now discontinued | Yes |
| Norton Antivirus | X | nortonav.exe | Added by the RBOT-AYE TROJAN! Note - this is not the real Norton AV! | No |
| Norton Antivirus Updater | X | nortonav.exe | Added by the DELBOT-T WORM! Note - this is not the real Norton AV! | No |
| Windows Xp | X | nortonguard.exe | Added by the MYTOB-DZ WORM! | No |
| nortonp | X | nortonp.exe | Added by the JD-A TROJAN! | No |
| Mcafee Anti Scan | X | NortonScn.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| Norton Updater | X | NortonUpdate.exe | Added by an unidentified WORM or TROJAN! | No |
| NortonAV | X | norton_antivirus.exe | Added by the NETJOE TROJAN! Note - this is not the legitimate Symantec AV program | No |
| noskrnl | X | noskrnl.exe | Detected by Symantec as Trojan.Peacomm.D | No |
| Loadout Manager | U | nost_LM.exe | Manager for the Belkin Nostromo n50 SpeedPad game controller - see here | No |
| notes | X | notepaad.exe | Added by the RBOT.BME WORM! | No |
| (Default) | X | NOTEPAD.exe | Added by the RUSTY WORM! Note - not to be confused with the valid Windows "NOTEPAD" text editor! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| [random name] | X | notepad.exe | PurityScan adware. Note - this is not Windows Notepad which has the same executable name | No |
| Lao Antivirus | X | NOTEPAD.EXE | Detected by Dr.Web as Win32.HLLW.Autoruner1.2826 and by Malwarebytes Anti-Malware as Worm.AutoRun | No |
| Microsoft | X | notepad.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. Note - this is not the legitimate text editor of the same filename which is located in %Windir%. This version is located in %AppData%\FlashPlayer | No |
| Microsoft | X | notepad.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. Note - this is not the legitimate text editor of the same filename which is located in %Windir%. This version is located in %Windir%\FlashPlayer | No |
| Microsoft | X | notepad.exe | Detected by Malwarebytes Anti-Malware as Trojan.Autoit. Note - this is not the legitimate text editor of the same filename which is located in %Windir%. This version is located in %System%\FlashPlayer | No |
| Microsoft NotePad | X | notepad.exe | Added by a variant of Win32/Rbot | No |
| Notepad lptt01 | X | notepad.exe | RapidBlaster variant (in a "windows" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not Windows Notepad which has the same executable name | No |
| Notepad ml097e | X | notepad.exe | RapidBlaster variant (in a "windows" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not Windows Notepad which has the same executable name | No |
| EYORE | X | Notepad.scr | Added by the GIMLET-A WORM! | No |
| Windows Autostart Loader | X | notepad32.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| msdtcc | X | notepod.exe | Detected by Trend Micro as TROJ_VB.FPW | No |
| notes | X | notes.exe | Added by the SYKIPOT BACKDOOR! | No |
| NoticeP.exe | U | NoticeP.exe | Part of iSync which allows "you to transfer songs from any music downloading software to your iTunes® library". The trial version displays advertisements which disappear if you purchase the software | No |
| Notify Mail | N | NOTIFY.EXE | E-mail notification utility | No |
| pagofile | X | notoped.exe | Detected by Trend Micro as TROJ_VB.FPW and by Malwarebytes Anti-Malware as Email.Worm.NTO | No |
| bee0c4d45bcdd7deadce6b70f4861060 | X | Notpad.exe | Detected by Dr.Web as Trojan.DownLoader8.31864 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ | No |
| Media service | X | notpad.exe | Detected by Trend Micro as WORM_SDBOT.CHU and by Malwarebytes Anti-Malware as Backdoor.SDBot | No |
| system23 | X | notPad.exe | Added by the ESTEEMS.D TROJAN! | No |
| gabougool | X | nounina.exe | Detected by Sophos as Troj/Agent-JVX | No |
| Vista&Senven | X | Nourinfo.exe | Added by the AGENT-QXP TROJAN! | No |
| Disable EHCI | ? | nousb20.exe | ?? | No |
| Operations Typhoon Rising Registration | N | NOVG.EXE | Joint Operations registration reminder | No |
| novsvida.exe | X | novsvida.exe | GlobalAccess dialer | No |
| NaverPCGreen | U | NPCGreenUpgrader.exe | Related to Naver_Anti-virus Realtime Monitor From NHNCorp | No |
| Disk Panel Setup | X | npcsvc.exe | Added by the SLENFBOT.JV WORM! | No |
| Hti | U | npdor.exe | Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required | No |
| NFM Service | U | NPDOR9x.exe | Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required | No |
| IBM ThinkPad Utility | U | NPDTray.exe | System Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and multiple display options. Scheme selection and settings are also available via Fn+F7 key combination on some models | Yes |
| NPDTray | U | NPDTray.exe | System Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and multiple display options. Scheme selection and settings are also available via Fn+F7 key combination on some models | Yes |
| ThinkPad Presentation Director | U | NPDTray.exe | System Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and multiple display options. Scheme selection and settings are also available via Fn+F7 key combination on some models | Yes |
| Windows Network Logon | X | npesvc.exe | Added by the AGENT.ERZ TROJAN! | No |
| GLF Network Lan Monitor | X | NPFMNTOR.exe | Added by the RBOT-AGY WORM! | No |
| NPFMonitor | Y | NPFMntor.exe | Firewall install monitor for older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Helps detect immediately after boot-up whether the firewall part is currently installed and working properly, whether it is currently enabled or disabled, and what features of the firewall are turned on. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| NPF Value | X | NPFMONTR.exe | Added by the RBOT-AWD WORM! | No |
| Norton Personal Firewall | X | npfw.exe | Added by the RBOT-UI WORM! | No |
| Norton Personal Firewall | X | npfw32.exe | Added by the RBOT-UQ WORM! | No |
| userinit | X | npgkij.exe | Detected by McAfee as Generic BackDoor.acx and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| npkmnc | X | npkmnc.exe | WebVia adware | No |
| Norton Personal Firewall | X | npmsys.exe | Detected by Sophos as W32/Rbot-ALO | No |
| Netzip Smart Downloader | X | npnzdad.exe | Advertising spyware | No |
| RealDownload Express | X | npnzdad.exe | Advertising spyware | No |
| Norton Protect | X | npprotect.exe | Added by the RBOT-WW WORM! | No |
| Windows Audio Panel | X | nppsvc.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
| NPROTECT | X | NPROTECT.exe | Detected by Symantec as Trojan.Syginre. Note - this is not the legitimate file used by the Norton Protected Recycled Bin feature from older versions of Norton Utilities and is located in %Root% | No |
| NPROTECT | U | NPROTECT.EXE | Supports the Norton Protected Recycled Bin feature of older versions of Norton Utilities (either as a standalone product or as part of Norton SystemWorks). Adds an extra layer of safety to the deletion of information from the standard Windows Recycled Bin. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| AutoStartNPSAgent | N | NPSAgent.exe | Installed with the SAMSUNG New PC Studio mobile device management utility. Detects when a supported mobile device is connection and optionally automatically loads the main program | Yes |
| NPSAgent | N | NPSAgent.exe | Installed with the SAMSUNG New PC Studio mobile device management utility. Detects when a supported mobile device is connection and optionally automatically loads the main program | Yes |
| Samsung PC Studio | N | NPSAgent.exe | Installed with the SAMSUNG New PC Studio mobile device management utility. Detects when a supported mobile device is connection and optionally automatically loads the main program | Yes |
| Norton Program Scheduler Event Checker | ? | npscheck.exe | Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as NPS Event Checker | No |
| NPS Event Checker | ? | npscheck.exe | Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event Checker | No |
| Norton Program Scheduler | U | NPSsvc.exe | Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans | No |
| Windows Protected Storage | X | npssvc.exe | Added by the IRCBOT.AUL BACKDOOR! | No |
| NovaPortal Single User Service | ? | NPSU.exe | ?? | No |
| NQaKwkjGRxPmQog.exe | X | NQaKwkjGRxPmQog.exe | Detected by Malwarebytes Anti-Malware as Trojan.Foury. The file is located in %CommonAppData% | No |
| WinLoader | X | nqvrcni.exe | Detected by Dr.Web as Trojan.MulDrop4.14194 | No |
| NR7 | X | NR7.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| NetReach | X | nrcheck.exe | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| QTime | X | nrchk.exe | Premium rate adult content dialler | No |
| ScheduIe | X | nrchk.exe | Premium rate adult content dialler | No |
| Microsoft (R) Windows Vista/NT Runtime Compatibility Service | X | nrcs.exe | Added by the RANKY.X TROJAN! | No |
| Premeter | X | nrpr.exe | NetRatings Premeter spyware | No |
| nrtwcf | X | nrtwcf.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %ProgramFiles%\WinRAR | No |
| NS | X | ns.exe | Added by the AGOBOT-HS WORM! | No |
| Run32 | X | ns.exe | Detected by Sophos as Troj/DwnLdr-KNN and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| NLS MonBoard | X | NSBARD.EXE | Added by the SPYBOT.T BACKDOOR! | No |
| Win32load | X | nscagent.exe | Detected by McAfee as Downloader-BON | No |
| Scanner File Utility | Y | NsCatCom.exe | Kycocera Mita network copier/printer/scanner process to dump scanned documents onto a workstation | No |
| NSCheck | X | nscheck.exe | MarketScore parasite - ActiveX control used to download premium-rate diallers | No |
| Norton Program Scheduler | U | nsched32.exe | Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans | No |
| nscntrl | X | nscntrl.exe | Added by the DLOAD-DC TROJAN! | No |
| [various names] | X | NsCplTray.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| NSCSysTrayUI | U | NSCSysTrayUI.exe | System Tray access to the NetworkScan utility for some Samsung AIO devices which allows scanning and printing over a network | No |
| NSCSysTrayUI_XEROX | U | NSCSysUI_XEROX.exe | System Tray access to the NetworkScan utility for some Xerox AIO devices which allows scanning and printing over a network | No |
| nsdcmd services | X | nsdcmdav.exe | Added by a variant of the AGOBOT WORM! | No |
| nsdcmd vid process | X | nsdcmdwin.exe | Added by a variant of the AGOBOT WORM! | No |
| nsdlua | X | nsdlua.exe | All-In-One Telcom - adult content dialler | No |
| nse | X | nse.exe | Detected by Sophos as W32/Agobot-ML | No |
| Network Security | X | NSecurity.exe | Added by the IRCBOT.AAV WORM! | No |
| Nsengine | U | Nsengine.exe | Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here | No |
| nservice32 | X | nservice32.exe | Detected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| signup | X | nsignup.exe | Detected by Dr.Web as Trojan.DownLoader7.12599 and by Malwarebytes Anti-Malware as Adware.KorAd | No |
| NSK | U | NSK.exe | Ardakey keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| NetStat Live | N | Nsl.exe | AnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data | No |
| [3-4 random letters] | X | nslookup.exe | PurityScan adware. Not to be confused with the legitimate nslookup.exe which is found in the System32 folder | No |
| PI_NsLookup.exe | X | NsLookup.exe | Detected by Sophos as Troj/Agent-ZBG and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Microsoft (R) Windows Network Security Management Service | X | nsms.exe | Detected by Trend Micro as TROJ_RANKY.LC | No |
| Microsoft CSRSS Service | X | nsmscrs.exe | Added by the RBOT-BPT WORM! | No |
| NetShow Powerpoint Helper | U | NSPPTHLP.EXE | If disabled, user created fonts can no longer be seen by other programs | No |
| Windows Media Powerpoint Helper | N | NSPPTHLP.EXE | German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start → Programs | No |
| Windows Network Session | X | nspsvc.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Norton Save and Restore | U | NSRTray.exe | System Tray access to and notifications for Symantec's Norton Save and Restore 1.0 backup software (either as a standalone product or as part of Norton SystemWorks Premier) - which is a renamed version of Norton Ghost | Yes |
| NSRKey | U | NSRTray.exe | System Tray access to and notifications for Symantec's Norton Save and Restore 1.0 backup software (either as a standalone product or as part of Norton SystemWorks Premier) - which is a renamed version of Norton Ghost | Yes |
| NSRTray | U | NSRTray.exe | System Tray access to and notifications for Symantec's Norton Save and Restore 1.0 backup software (either as a standalone product or as part of Norton SystemWorks Premier) - which is a renamed version of Norton Ghost | Yes |
| ScanRegistry | X | nsrvnt.exe | Detected by Symantec as Backdoor.Nerte | No |
| SystemService | U | nsserver.exe | NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| TSService | ? | NSSERVICE.EXE | ?? | No |
| nsdriver | X | nssys32.exe | NetShagg adware | No |
| NDplDeamon | X | nstask32.exe | Added by the RANDEX.E WORM! | No |
| Pofatch | X | nstrue.exe | Added by the RANDEX.Z WORM! | No |
| NSupdate | X | NSupdate.exe | Added by the Dial/Laet-B premium rate dialer! | No |
| Nokia | X | nsu_ui_client.exe | Added by the BANKER-FAQ TROJAN! Note - this is not the legitimate Nokia Software Updater which shares the same filename and is located in %ProgramFiles%\Nokia\Nokia Software Updater. This one is located in %Windir% | No |
| Nokia Software Updater | Y | nsu_ui_client.exe | Utility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devices | Yes |
| nsu_ui_client | Y | nsu_ui_client.exe | Utility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devices | Yes |
| nsu_ui_client.exe | Y | nsu_ui_client.exe | Utility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devices | Yes |
| Nsvdr | X | nsvdr.exe | Adult content dialler | No |
| Nsv | X | nsvsvc.exe | Delfin PromulGate adware | No |
| NSWCfg.exe | U | NSWCfg.exe | Information wizard for older versions of Symantec's now discontinued Norton SystemWorks system utility suite. On the first run after installation this entry looks after registration, subscription and confirms the default configuration settings | Yes |
| Norton SystemWorks | N | NswUiTray.exe | System Tray access to Symantec's now discontinued Norton SystemWorks 2009 security and utility suite | Yes |
| NswUiTray | N | NswUiTray.exe | System Tray access to Symantec's now discontinued Norton SystemWorks 2009 security and utility suite | Yes |
| nsys | U | nsys.exe | NetSpy keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| nsys32 | X | nsys32.exe | Added by the AGOBOT-SU WORM! | No |
| [various names] | X | NSYSCPLSTR.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Nt**.exe [* = random char] | X | Nt**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| Nt**32.exe [* = random char] | X | Nt**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| Reg Service | X | NT32.exe | Detected by Trend Micro as BKDR_AGOBOT.G | No |
| NT Video API32 | X | NTAPI32.exe | Added by the RBOT-FW WORM! | No |
| ntasvr | X | ntasvr.exe | Detected by Emsisoft as Adware.Win32.NateSrch!A2. The file is located in %ProgramFiles%\Nate\AddressSearch | No |
| NET Bios Stats | X | ntbstats.exe | Added by the SDBOT-ZX WORM! | No |
| Microsoft Update Machine | X | ntce.exe | Added by the RBOT-FA WORM! | No |
| directx | X | NTCmd.exe | Added by the SDBOT.D TROJAN! | No |
| NvCplD | X | ntcpl.exe | EnterOne - Switch dialer and hijacker variant, see here | No |
| ntddetect | X | ntddetect.exe | Added by the AGENT-CU TROJAN! | No |
| rundll32 | X | ntdevice.exe | Added by the AGENT-OUM TROJAN! | No |
| NTdhcp | X | NTdhcp.exe | Added by the QQROB-C TROJAN! | No |
| MSN service | X | NTDKRN.EXE | Added by the RBOT.UJ WORM! | No |
| ntdll | X | ntdll.exe | Added by the BIONET.404 TROJAN! | No |
| Windows Installer | X | ntdll.exe | Added by an unidentified WORM or TROJAN! | No |
| Configuration Loader | X | ntdm.exe | Detected by Trend Micro as WORM_AGOBOT.RV | No |
| Microsoft NT Drivers | X | ntdrv.exe | Added by the SDBOT.AJN TROJAN! | No |
| Internet | X | nteusodp.exe | Added by the RBOT-GFJ WORM! | No |
| Windows File System Frame | X | ntframe.exe | Added by an unidentified WORM or TROJAN! | No |
| systemStart | X | Ntfs.exe | Added by the AUTORUN-JM WORM! | No |
| NTFS16 | X | ntfs16.exe | Added by the RBOT-LY WORM! | No |
| ntfsmonitorpro | X | ntfs64.exe | Added by the FORBOT-EB WORM! | No |
| ConfigSafe | Y | NTFSCLUP.EXE | Part of ConfigSafe - "checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99+% of the time it will only execute about a dozen instructions before exiting" | No |
| NTFSCLUP | Y | NTFSCLUP.EXE | Part of ConfigSafe - "checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99+% of the time it will only execute about a dozen instructions before exiting" | No |
| *ntfsqueuedns.exe | X | ntfsqueuedns.exe | Added by the FAKEAV-EMN TROJAN! | No |
| ntfyapp | X | ntfyapp.exe | Added by the ZHELATIN WORM! | No |
| GinaDll | X | ntgina.dll | Detected by Trend Micro as WORM_ANIG.A | No |
| Norton Guard 32 | X | ntguard32.exe | Added by a variant of Win32/Rbot | No |
| WSAConfiguration | X | ntguard32.exe | Added by a variant of the AGOBOT WORM! | No |
| WinSocketComponent | X | nthost.exe | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| ntiMUI | U | ntiMUI.exe | Part of NTI CD & DVD Maker from NTI Corporation - now superseded by NTI Media Maker | No |
| AdobeReaderPro | X | ntkernell32.exe | Added by the RBOT-ATY WORM! | No |
| Compaq Service Drivers | X | NtKernelSystem.exe | Added by a variant of W32/Sdbot.worm | No |
| Kernel Loader | X | ntkrnl.exe | Added by the CERVIVEC.A WORM! | No |
| NT Kernel Patch | N | ntkrnlpt.exe | Part of Bitware from 2Point Communications, Inc - "a Windows based solution that allows users to integrate your voice messaging and faxing to an individual PC." Now known as Simply Messenger PRO | No |
| ntldr | X | ntldr.exe | Browser hijacker re-directing to search-control.com. In addition to the registry changes found by HijackThis it also creates the following system files: %System%\ntldr.exe, C:\m.exe, %Windir%\Search-For-You.url, C:\n.bat, C:\q.exe and C:\r.bat | No |
| Win Patch | X | ntldr.exe | Added by the SDBOT-GS WORM! | No |
| shell32 | X | ntldrt.exe | Added by the JLOK-A WORM! | No |
| sysclx | X | ntldrt.exe | Added by the JLOK-A WORM! | No |
| Windows NT 32 | X | ntlogin32.exe | Added by the RANDEX.BRD WORM! | No |
| Windows NT Login | X | ntlogin32.exe | Added by the SDBOT.WG WORM! | No |
| csrss | X | ntmdi.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeAdobe. The file is located in %UserProfile% | No |
| ntmsevt | X | ntmsevt.exe | Added by the STOPED-B TROJAN | No |
| FastStart | X | ntnut32.exe | Added by the STARTPAGE.L TROJAN! | No |
| Notepad | X | ntoepad.exe | Added by the DELBOT-AK WORM! | No |
| ntokrnl | X | ntokrnl.exe | Added by the BANKER.AWA TROJAN! | No |
| NT Service | X | NTOKSRNL.EXE | Added by the RBOT-AAG WORM! | No |
| NvCplD | X | ntopengl.exe | EnterOne - Switch dialer and hijacker variant, see here | No |
| userinit | X | ntos.exe | Detected by Symantec as Trojan.Gpcoder.E and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Osa32 | X | NTOSA32.exe | Added by the ANIG WORM! | No |
| RealActive | X | ntoscore.exe | Added by the VIRUT.VQ VIRUS! | No |
| sittachasnahalbasya | X | ntoskernel.exe | Added by the HANSAH-A WORM! | No |
| Kernal Fault Check | X | ntosrkl.exe | Added by a variant of W32/Sdbot.worm | No |
| nTrayFw | Y | ntrayfw.exe | System Tray access to the NVIDIA ActiveArmor hardware-optimized firewall built into some older nForce 3 and 4 series motherboard chipsets | No |
| NVIDIA ActiveArmor | Y | ntrayfw.exe | System Tray access to the NVIDIA ActiveArmor hardware-optimized firewall built into some older nForce 3 and 4 series motherboard chipsets | No |
| NTrtc | N | ntrtc.exe | Dell year 2000 tool to deal with non-standard applications. Only required on older Dell PCs that may need this support | No |
| MS taskbar | X | nts.exe | Added by the RBOT-AGB WORM! | No |
| EasySync Pro - LtNts4 | U | NtsAgent.exe | Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - "a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems" | No |
| Laplink PDASync 3.0 - LtNts4 | U | NtsAgnt.exe | Laplink PDASync for (IBM) Lotus Notes 4 - PDA synchronisation utility | No |
| XTNDConnect PC - LtNts4 | U | NtsAgnt.exe | (IBM) Lotus Notes 4 specific translator for XTNDConnect PC - "award-winning desktop-sync application that enables you to easily synchronize your contacts, calendar, tasks, email and notes between your mobile devices and popular PC applications" | No |
| Intec Service Drivers | X | ntservice.exe | Added by the RBOT.FGW BACKDOOR! | No |
| Microsoft Update | X | ntservice.exe | Added by the AGENT-DIS TROJAN! | No |
| NTSF MICROSOFT SYSTEM | X | ntsf.exe | Detected by Trend Micro as WORM_RBOT.ARQ and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| NTSF MICROSOFT SYSTEM | X | ntsfd.exe | Detected by Sophos as W32/Rbot-BAP and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| ntsmod | X | ntsmod.exe | Adware downloader/installer, probably VX2/Look2Me related - also detected as the WIN32.VB.RL TROJAN! | No |
| Generic Host Process for Win32 Services | X | ntspcv.exe | Added by the SDBOT.S TROJAN! | No |
| NTSpool | X | NTSpool.exe | Detected by Sophos as Troj/Agent-GPY | No |
| NTsrv.exe | X | NTsrv.exe | Added by a variant of the SERVU-O TROJAN! | No |
| System Server Manager | X | Ntsrvc.exe | Added by the DARKSKY.B BACKDOOR! | No |
| NetManagerService | X | ntss.exe | Detected by Trend Micro as BESTPICS.A BACKDOOR! | No |
| Network Translation System Service | X | ntss.exe | Added by the UNPDOOR TROJAN! | No |
| NTSF MICROSOFT SYSTEM | X | ntssf.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %System% | No |
| Messenger | X | ntsubsys.exe | Added by the SDBOT.BGE WORM! | No |
| NetService | X | ntsvc.exe | Added by the QQPASS-DU TROJAN! | No |
| NT Services | X | ntsvc.exe | Added by the AGOBOT.VJ WORM! | No |
| Windows NT Net Service Monitor | X | ntsvc.exe | Added by the SDBOT-DKY WORM! | No |
| Microsoft | X | ntsvr.exe | Added by a variant of W32.Spybot.Worm. The file is located in %System% | No |
| VxD Driver Initialization | X | ntsvxd.exe | Added by the SDBOT-LW WORM! | No |
| Compaq Service Drivers | X | ntsys32.exe | Detected by Trend Micro as WORM_RBOT.CIW | No |
| Configuration | X | ntsys32.exe | Added by the SDBOT-LN WORM! | No |
| Winsock2 driver | X | ntsys32.exe | Added by the SPYBOT-DD WORM! | No |
| Nt System Kernel | X | ntsyskrnl.exe | Added by the AGOBOT.IK WORM! | No |
| Microsoft System Checkup | X | ntsysman.exe | Added by the SDBOT-QW WORM! | No |
| Microsoft System Checkup | X | ntsysmgr.exe | Added by the DONK.S WORM! | No |
| Configuration | X | ntsyst32.exe | Added by the SDBOT-LT WORM! | No |
| gwiz | X | ntsystem.exe | Added by the NITWIZ.A TROJAN! | No |
| Microsoft Update Machine | X | ntsystem.exe | Added by the RBOT.GF WORM! | No |
| Nt System Protocol | X | ntsystem.exe | Added by the RBOT.DSB BACKDOOR! | No |
| Video Process | X | ntsystm.exe | Added by the GAOBOT.ZX WORM! | No |
| Ntsysv | X | ntsysv.exe | Added by the MIFENG-E TROJAN! | No |
| nTune | U | nTune.exe | Older version of the NVIDIA nTune utilty for monitoring and modifying the settings (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards from within Windows. Now part of NVIDIA System Tools | No |
| NVIDIA nTune | U | nTune.exe | Older version of the NVIDIA nTune utilty for monitoring and modifying the settings (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards from within Windows. Now part of NVIDIA System Tools | No |
| nTuneCmd | U | nTuneCmd.exe | Now part of NVIDIA System Tools under the "Peformance" tag. NVIDIA nTune is utilty for monitoring and modifying the settings (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards from within Windows. Until version 6.01 (when System Tools was released) graphics settings weren't retained in a profile but now they are. From version 6.05, nTuneCmd is no longer loaded via the registry "Run" keys but instead runs via the Performance Service (nTuneService.exe) | Yes |
| NVIDIA nTune | U | nTuneCmd.exe | Now part of NVIDIA System Tools under the "Peformance" tag. NVIDIA nTune is utilty for monitoring and modifying the settings (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards from within Windows. Until version 6.01 (when System Tools was released) graphics settings weren't retained in a profile but now they are. From version 6.05, nTuneCmd is no longer loaded via the registry "Run" keys but instead runs via the Performance Service (nTuneService.exe) | Yes |
| ntupd32 | X | ntupd32.exe | Unidentified malware - see here | No |
| ntuser | X | ntuser.exe | Added by an unidentified TROJAN! See here | No |
| Fast start | X | Ntut.exe | Adware - detected by Kaspersky as the FAVADD.I TROJAN! | No |
| Kernel Fault Check | X | ntvbm.exe | Added by the RBOT-CKP WORM! | No |
| [random name] | X | ntvdm.exe | PurityScan adware. Do not confuse with the legitimate ntvdm.exe process which is always located in %System% and should not figure in Msconfig/Startup! | No |
| NTVDM | U | NTVDM.EXE | Windows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS's (Windows NT, 2K and XP). Required if hardware on a machine with these OS's needs 16-bit DOS drivers. You can find a bit more about NTVDM here | No |
| Graphic Loader | X | ntvdm32.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| ntvdmd | X | ntvdmd.exe | Adware downloader - also detected as the DLOADER-YP TROJAN! | No |
| NT-Virtual Device Manager | X | ntvdmn.exe | Added by the SDBOT-AAA WORM! | No |
| ntvdscm | X | ntvdscm.exe | Added by the SCKEYLOG-I TROJAN! | No |
| NT MICROSOFT SVCD | X | ntvsvcd.exe | Added by a variant of Win32/Rbot | No |
| ntwk.exe | X | ntwk.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %AppData% | No |
| ntx32 | X | ntx32.exe | Added by an unidentified WORM or TROJAN! | No |
| dxdll32 | X | ntxdll.exe | Added by the GAOBOT.CPX WORM! | No |
| ntxp2 | X | ntxp2.exe | Added by the VB-API TROJAN! | No |
| NT_Kernal | X | NT_Kernal.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% | No |
| Norton Utilities | N | nu.exe | Part of version 14.* of Symantec's Norton Utilities PC tune up suite. This entry will be present if you optionally select any of the following startup options (via Administer → Settings): "Custom Scan", "Privacy Clean & Full Scan" or "Send to tray" | Yes |
| NortonUtilities | N | nu.exe | Part of version 14.* of Symantec's Norton Utilities PC tune up suite. This entry will be present if you optionally select any of the following startup options (via Administer → Settings): "Custom Scan", "Privacy Clean & Full Scan" or "Send to tray" | Yes |
| nu | N | nu.exe | Part of version 14.* of Symantec's Norton Utilities PC tune up suite. This entry will be present if you optionally select any of the following startup options (via Administer → Settings): "Custom Scan", "Privacy Clean & Full Scan" or "Send to tray" | Yes |
| uptolate | X | nucle.exe | Added by a variant of the BIFROSE TROJAN! | No |
| nudylvataxno | X | nudylvataxno.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %UserProfile% | No |
| Audio SPP Solutions Engine PnP-X Builder | X | nuikcmdeioi.exe | Detected by McAfee as Downloader.a!dch and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| [various names] | X | NukeSpan.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Microsoft Installshield | X | nundll32.exe | Added by the AGOBOT-AHZ WORM! | No |
| AhnLab V3Lite Update Process | X | nusb3mon.exe | Detected by Microsoft as TrojanDownloader:Win32/Navattle.A and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is neither a legitimate AhnLab V3 entry or the Renesas (was NEC) USB 3.0 monitor which has the same filename and is normally located in %ProgramFiles%\[vendor]\USB 3.0 Host Controller Driver\Application - this one is located in %System% | No |
| NUSB3MON | U | nusb3mon.exe | Supports USB 3.0 ports based upon the Renesas (was NEC) range of controllers on both system motherboards and external disk drives. Disabling it didn't seem to have any ill effects on USB 3.0 transfer speeds but it may be required to support power management features | Yes |
| USB 3.0 Monitor | U | nusb3mon.exe | Supports USB 3.0 ports based upon the Renesas (was NEC) range of controllers on both system motherboards and external disk drives. Disabling it didn't seem to have any ill effects on USB 3.0 transfer speeds but it may be required to support power management features | Yes |
| NuvaTime | U | NuvaTime.exe | NuvaTime - reminder for women using NuvaRing | No |
| NUAgentInstallPath | U | NU_Install.exe | Installer associated with Chily Employee Activity Monitoring surveillance software. Uninstall this software unless you put it there yourself | No |
| NvagNT | X | nvagNT.exe | Added by the AGOBOT-RV WORM! | No |
| Microsoft System Checkup | X | nvapi32.exe | Added by the DONK.B WORM! | No |
| NVIDIA nForce APU1 Utilities | N | NVATray.exe | nVidia's nForce Audio Processing Unit (APU)- "provides 3D positional audio and DirectX 8.0 compatibility, and encodes and decodes Dolby Digital 5.1 audio in real time" | No |
| NvCCCpl | X | NvCCCpl.exe | Added by the NOGATA-A TROJAN! | No |
| NvCCpl | X | NvCCpl.exe | Added by the CHILIN-A WORM! | No |
| nVidia Chip4 | X | NVCHIP4.EXE | Added by the LAMECADA-D BACKDOOR! | No |
| winlogon | X | nvchost.exe | Added by an unidentified WORM or TROJAN! | No |
| nvcoi | X | nvcoi.exe | Added by the DLOADER.TYO TROJAN! | No |
| NVCOM | X | NVCOM.exe | Added by the AGOBOT-SB WORM! | No |
| NvCpl | X | NvCpl.EXE | Added by the YANZ.B WORM! | No |
| NvCpl32Deamon | X | nvcpl.exe | Added by the SPYBOT.S WORM! | No |
| NvCPL32 | X | nvcpl32.exe | Detected by Trend Micro as WORM_AGOBOT.DAA | No |
| nvcpll | X | nvcpll.exe | Added by the BANCBAN-PF TROJAN! | No |
| FireWire Services | X | nvcsv32.exe | Detected by Trend Micro as WORM_RBOT.AUM | No |
| HD Media | X | nvcsvc.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Windir% | No |
| nvctrl.exe | X | nvctrl.exe | Added by the ZLOB.G TROJAN! | No |
| NaverVaccine | X | NVCUpgrader.exe | Detected by Kaspersky as Trojan.Win32.Scar.rfw and by Malwarebytes Anti-Malware as Adware.K.NaverVaccine. The file is located in %ProgramFiles%\Naver\NaverVaccine | No |
| Win32 nvc | X | nvcva.exe | Added by the RBOT-ABF WORM! | No |
| nvc Win32 | X | nvcvc.exe | Added by the RBOT-ADD WORM! | No |
| nvd32 lptt01 | X | nvd32.exe | RapidBlaster variant (in a "NvidStar" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| nvd32 ml097e | X | nvd32.exe | RapidBlaster variant (in a "NvidStar" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| Postdavatch | X | nvdas.exe | Added by the RANDEX.T WORM! | No |
| Postpatch | X | nvdes.exe | Added by the RANDEX.T WORM! | No |
| NvCplDeamon | X | nvdisp.exe | Added by the PEEPVIE-I TROJAN! | No |
| NVDispDrv | X | NVDispDRV.EXE | Added by the WINKO.AO WORM! | No |
| NVIDIA PANEL | X | nvdpnl.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData% | No |
| NVidiaDrv | X | nvfsvm.com | Added by the DELF-A BACKDOOR! | No |
| Messenger Service | X | nvhost.exe | Added by the JLOK-A WORM! | No |
| Nvid32 | X | Nvid32.exe | Added by the GEMA TROJAN! | No |
| Nvidex32 | X | Nvidex32.exe | Added by the GEMA TROJAN! | No |
| DRIVERSS | X | nvidia.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen. The file is located in %AppData%\drivers | No |
| Microsoft Nvidia Video | X | nvidia.exe | Added by a variant of W32/Sdbot.worm | No |
| nvidia: | X | nvidia.exe | Detected by Symantec as W32.Kueight | No |
| Nvidia32 | X | nvidia32.exe | CoolWebSearch parasite variant - also detected as the HOSTS-B TROJAN! | No |
| NVIDIA Drivers | X | NVIDIADrivers.exe | Detected by Dr.Web as Trojan.KillFiles.10692 and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| nVidia Drivers | X | nVidiaDrvers.exe | Added by the SDBOT-AFX WORM! Note - this is not related to any nVidia based motherboard or graphics card | No |
| nVidia Application Drivers | X | nvidiav32.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| nvidll32 | X | nvidll32.exe | Added by the RBOT-XK WORM! | No |
| nviload32 | X | nviload32.exe | Added by the SDBOT-VT WORM! | No |
| nvirundll | X | nvirundll.exe | Added by the SPYBOT.NPS WORM! | No |
| nvjxue | X | nvjxue.exe | Added by the EYEVEG-J WORM! | No |
| NVmax | Y | NVmax.exe | NVmax is a old tweaking utility for NVidia graphics cards. In the startup list if the user chooses to overclock their card | No |
| NVMixerTray | N | NVMixerTray.exe | System Tray access to audio controls from nVidia's motherboard ForceWare software | No |
| NVIDIA System Monitor | U | NVMonitor.exe | NVIDIA System Monitor - part of NVIDIA System Tools. Utility for monitoring and logging system statistics (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards | Yes |
| NVMonitor | U | NVMonitor.exe | NVIDIA System Monitor - part of NVIDIA System Tools. Utility for monitoring and logging system statistics (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards | Yes |
| nvmsgdwn | X | NVMSGDWN.EXE | Added by the GRABER-D TROJAN! | No |
| PCMCIA Resource Monitor | ? | nvp2pmon.exe | NVIDIA nForce P2P Driver. What does it do and is it required? | No |
| NvPvrNetMon | U | NvPvrNetMon.exe | Network monitor for the Personal Video Recorder function of the NVIDIA ForceWare Multimedia application - "makes sure you don't miss your favorite show. If you won't be home to watch the show, just use the PVR to set future recordings" | No |
| NVIDIA® NVRAID | U | nvraidservice.exe | Part of NVIDIA® MediaShield Storage - NVIDIA's management utility for creating and monitoring hard disk RAID arrays for the controllers integrated on their motherboards. Includes a Disk Alert System for troubleshooting with notifications via the System Tray. Not required if you don't have a RAID array or if you created the array at the BIOS level. Some users complain that it can report false errors | Yes |
| NVRaidService | U | nvraidservice.exe | Part of NVIDIA® MediaShield Storage - NVIDIA's management utility for creating and monitoring hard disk RAID arrays for the controllers integrated on their motherboards. Includes a Disk Alert System for troubleshooting with notifications via the System Tray. Not required if you don't have a RAID array or if you created the array at the BIOS level. Some users complain that it can report false errors | Yes |
| NVRT | N | nvrt.exe | NVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports | No |
| NVRTClk | ? | NVRTClk.exe | Related to a Gigabyte video card. What does it do, and is it required? | No |
| NvCplScan | X | nvsc32.exe | Detected by Symantec as W32.Bropia.N | No |
| win-xp | X | nvsc32.exe | Detected by Symantec as W32.Bropia.N | No |
| 32.exe | X | nvscv32.exe | Added by the AGENT-LOL TROJAN! | No |
| FireWire Service | X | nvscv32.exe | Detected by Trend Micro as WORM_SDBOT.AXT | No |
| nvscv32 | X | nvscv32.exe | Detected by McAfee as W32/Fujacks.s | No |
| NVSystem32 | X | nvscv32.exe | Added by the AGOBOT-NO WORM! | No |
| svcshare | X | nvscv32.exe | Added by the FUJACKS-Z WORM! | No |
| Winsock Driver | X | nvscv32.exe | Added by the AGOBOT-FD WORM! | No |
| Net Command Senter | X | nvscvse.exe | Added by the IRCBOT!DF6280E5 VIRUS! | No |
| nvsmudfm | X | nvsmudfm.exe | Detected by Malwarebytes Anti-Malware as Adware.PinSearch. The file is located in %System% | No |
| ctfmon | X | nvsv32.exe | Detected by McAfee as Generic Dropper!fhr and by Malwarebytes Anti-Malware as Trojan.Delf | No |
| Norton updated | X | nvsv32.exe | Detected by Trend Micro as WORM_SDBOT.ABH | No |
| nvsv32.exe | X | nvsv32.exe | Detected by Sophos as W32/Forbot-DI | No |
| nvsv32.exe | X | nvsv33.exe | Added by the WOOTBOT.FP WORM! | No |
| Generic Service Process | X | nvsvc.exe | Detected by Trend Micro as WORM_AGOBOT.BY. Note - this is not the valid "NVIDIA Driver Helper Service" and is located in %System% | No |
| Norton protect | X | nvsvc.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| nvsvc | X | nvsvc.exe | Added by the BANKER-HQ TROJAN! Note - this is not the valid "NVIDIA Driver Helper Service" and is located in %System% | No |
| NVSVC | X | nvsvc.exe | Detected by Trend Micro as WORM_AGOBOT.ALX. Note - this is not the valid "NVIDIA Driver Helper Service" and is located in %System% | No |
| NvSvc | N | nvsvc.exe | NVIDIA Driver Helper Service - installed when you change from the WDM drivers to nVidia's latest versions but not requied. Extreme shutdown delays can be encountered with this service active, but no adverse side effects with it disabled. NOTE: If using drivers other than nVidia's, such as Asus, this service may have been renamed to reflect that | No |
| Symantec Security Addon | X | nvsvc.exe | Added by the AGOBOT-EN WORM! Note - do NOT confuse with the legitimate NVIDIA Driver Helper Service file of the same name | No |
| nvsvc16 | U | nvsvc16.exe | MySuperSPy surveillance software. Uninstall this software unless you put it there yourself | No |
| NVIDIA driver monitor | X | nvsvc32.exe | Detected by Sophos as Troj~Agent-OZH and by Malwarebytes Anti-Malware as Trojan.Crypt | No |
| nVidia Display Driver | X | nvsvc64.exe | Detected by Sophos as W32/IRCBot-YK. Note - this is not related to any nVidia based graphics card | No |
| Network Security XP | X | nvsvc86.exe | Added by the RBOT-GUI WORM! | No |
| Office Monitor | X | nvsvc86.exe | Added by the IRCBOT.BVO BACKDOOR! | No |
| clfmon | X | nvsvca32.exe | Added by the TACTSLAY.E TROJAN! | No |
| nvsvca32 | X | nvsvca32.exe | Added by the TACTSLAY.E TROJAN! | No |
| nVidia System Drivers | X | nvsys32.exe | Added by an unidentified WORM or TROJAN! See here | No |
| nVidia Display Drivers (x86) | X | nvsys86.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| NVRotateSysTray | ? | nvsysrot.dll | Related to NVIDIA nView Control Panel. What does it do and is it required? | No |
| NVidia System Utility | U | NVSystemUtility.exe | NVidia System Utility - older version of the NVIDIA nTune utilty for monitoring and modifying the settings (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards from within Windows. Now part of NVIDIA System Tools | No |
| System File Drivers | X | nvsysvc32.exe | Added by the AGOBOT.WJ WORM! | No |
| Nvidia Control Center4 | X | NvTaskbarIne.exe | Detected by Trend Micro as TROJ_BREDOLAB.KO | No |
| Nvidia Control Center3 | X | NvTaskbarInh.exe | Detected by Sophos as Troj/DelfInj-Y | No |
| Nvidia Control Center2 | X | NvTaskbarIni.exe | Detected by Trend Micro as WORM_PROLACO.CU | No |
| Nvidia Control Center | X | NvTaskbarInit.exe | Added by the HILOTI-AY TROJAN! | No |
| Windows ARP Detectionc | X | nvudlsp.exe | Added by the AGENT.LMW BACKDOOR! | No |
| 9UmxQPSiTJMbA | X | NVUKZ.exe | Detected by Sophos as Troj/Agent-LMN | No |
| zvb0dl2X8tt | X | NVUKZ.exe | Added by the AGENT-LMN TROJAN! | No |
| nvvdir | X | nvvdir.exe | Detected by Malwarebytes Anti-Malware as Trojan.Dropper. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| NvVideoCenter | X | NvVid.exe | Added by the HAXDOOR-DO TROJAN! | No |
| CLCKR | X | nvvsvc.exe | Added by the AGENT-TQK TROJAN! | No |
| Microsoft® Windows® Operating System | X | nvxdsinc.exe | Detected by Dr.Web as Trojan.DownLoader5.40693 and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
| kernel32 | X | nvxdsync.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp% | No |
| MSConfig | X | nvxp.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Netword Agent | N | nwant33.exe | An interesting browser utility that allows you to navigate by typing a single word or phrase (a "NetWord") related to what you're looking for into your browser's location field. It also puts an icon in the system tray icon that is a circle with the letter N in the center to access the menu faster. Available via Start → Programs | No |
| myNetWatchman | U | nwclient.exe | Sends your firewall alerts to a website, which then filters them and forwards details of suspicious activities to the host ISP they originated from. Only needs to be running when your firewall is running | No |
| Norman Worl System Ability | X | nwcss32.exe | Added by the DELF.IO TROJAN! | No |
| Windows Services Ts | X | nwdpqqoiwm.exe | Added by the RBOT-GRV WORM! | No |
| Zeno | X | nwinrqez.exe | Added by unidentified malware. The file is located in %System% | No |
| csrss | X | nwiz.exe | Added by the CHODE-J WORM! | No |
| Norton Wizzard | X | nwiz.exe | Added by the GAOBOT.ADV WORM! Note - this is not the valid nVidia application that shares the same name | No |
| nwiz | U | nwiz.exe | Part of NVIDIA's NVIEW Display Management Software - included in drivers for consumer and professional graphics products. This entry runs the "NVIDIA Display Setup Wizard" if you connect (or already have connected) an additional display once the drivers have been installed. In later drivers it also loads the "nView Desktop Manager" (if you enable it via Control Panel → NVIDIA nView Desktop Manager) if you want to use features such as Hot Keys and Zoom. In both cases nwiz.exe doesn't remain in memory | Yes |
| nwiz.exe | U | nwiz.exe | Part of NVIDIA's NVIEW Display Management Software - included in drivers for consumer and professional graphics products. This entry runs the "NVIDIA Display Setup Wizard" if you connect (or already have connected) an additional display once the drivers have been installed. In later drivers it also loads the "nView Desktop Manager" (if you enable it via Control Panel → NVIDIA nView Desktop Manager) if you want to use features such as Hot Keys and Zoom. In both cases nwiz.exe doesn't remain in memory | Yes |
| NvUpdater | X | nwiz32.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| nwiz32 | X | nwiz32.exe | Added by the SINBANK-A TROJAN! | No |
| Microsoft Autorun1 | X | nwizdh.exe | Detected by Symantec as W32.Ogleon.A | No |
| Microsoft Autorun20 | X | nwizfy.exe | Detected by Symantec as W32.Ogleon.A | No |
| Microsoft Autorun3 | X | nwizhx2.exe | Detected by Symantec as W32.Ogleon.A | No |
| nwizs | X | nwizs.exe | Added by the QUESHARE WORM! Note - the file is located in %ProgramFiles%\NVIDIA Corporation\PhysX\Common but is not a valid NVIDA PhysX file | No |
| Microsoft Autorun7 | X | nwiztlbu.exe | Detected by Symantec as W32.Ogleon.A | No |
| Microsoft Autorun11 | X | nwizwlwzs.exe | Detected by Symantec as W32.Ogleon.A | No |
| Microsoft Autorun10 | X | nwizwmgjs.exe | Detected by Symantec as W32.Ogleon.A | No |
| Microsoft Autorun12 | X | nwizzhuxians.exe | Detected by Symantec as W32.Ogleon.A | No |
| Nwpopup | Y | Nwpopup.exe | Broadcast message handler part of Novell Netware that displays server, printer and other messages | No |
| nwrecmsg | U | nwrecmsg.exe | Broadcast message handler part of Novell Netware that displays server, printer and other messages - can cause crashes | No |
| NWTRAY | Y | nwtray.exe | Novell Netware. Displays the red "N" tray icon which can be disabled (by right-click on the icon) but is also needed by the client | No |
| Microsoft Windows | X | nwxdse.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Windir%\Set | No |
| Microsoft Office | X | Nxcao.exe | Added by the RBOT-ZE WORM! | No |
| Microsoft Office | X | nxcxtpr.exe | Added by the RBOT-YG WORM! | No |
| Dialog Tracker | U | Nxdlghlp.exe | ExplorerPlus advanced file management alternative to Windows Explorer from Novatix. No longer available | No |
| Nyet.exe | X | Nyet.exe | Added by the DELF.MP TROJAN! | No |
| nylycwamkosu | X | nylycwamkosu.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| NZ01 | X | NZ01.exe | Added by the SCAR-K TROJAN! | No |
| NetZIPFolders | N | nzfprop.exe | Netzip Classic zip file manager | No |
| WindowsUpdate | X | Nzil.exe | Added by the CULLER-C WORM! | No |
| McAfee Online Virus Scanner | X | nzm.exe | Added by the IRCBOT.XV WORM! | No |
| SystemX | X | nzm.exe | Added by a variant of Win32/Rbot | No |
| Microsoft Svchost local services | X | nzm23.exe | Added by the RBOT-GMC WORM! | No |
| spc_w | N | nzspc.exe | NetZero Search Enhancement related | No |
| nzwnt.exe | X | nzwnt.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.NT. The file is located in %Windir% - see here | No |
| mikrosoft.exe | X | N_K.exe | Detected by Dr.Web as Trojan.Siggen5.11268 and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| mikrosoft_servises.exe | X | N_K.exe | Detected by Dr.Web as Trojan.Siggen5.11268 and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| N_K.exe | X | N_K.exe | Detected by Dr.Web as Trojan.Siggen5.11268 and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| servises_mikrosoft.exe | X | N_K.exe | Detected by Dr.Web as Trojan.Siggen5.11268 and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| sirvises.exe | X | N_K.exe | Detected by Dr.Web as Trojan.Siggen5.11268 and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).
"Status" key:
Variables:
DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.
WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.
As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.
There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program
NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.
SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.
Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved
| Privacy Policy | Site Map | Home |