Arcade File Downloads UsenetGeeks
Email
Confirm email
Articles Spyware Removal File Help Startup DB Tips Service DB News Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X notes notepaad.exe"Added by the RBOT.BME WORM!"
X Notification Utility altpayV2.exe"Reported by Ewido Security Suite as WeirWeb adware"
X Notn Eber.exe"PurityScan/Clickspring adware"
X Notn wtta.exe"PurityScan/Clickspring adware"
U NovaBackup * Tray Control NbkCtrl.exe"Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version number"
? NovaPortal Single User Service NPSU.exe"??"
U NovastorSchedulerd SCHENGD.EXENovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it
X NOYPI_KANG_ASTIG Exit to DosPrompt.pif"Added by the FILUKIN.A WORM!"
X NPF Value NPFMONTR.exe"Added by a variant of the SPYBOT WORM!"
? NPFMonitor NPFMntor.exe"Norton AntiVirus Firewall Install Monitor. What does it do and is it required?"
U NPROTECT nprotect.exeNorton Protected Recycle Bin from Norton Utilities. Adds an extra layer of safety before you remove deleted files from the Recycled Bin. Can be listed twice which is valid
? NPS Event Checker npscheck.exe"Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event Checker"
X NS ns.exe"Added by the AGOBOT-HS WORM!"
X NSCheck NSCHECK.EXE"MarketScore parasite - ActiveX control used to download premium-rate dialers"
X nscntrl nscntrl.exe"Added by the DLOAD-DC TROJAN!"
X nsdcmd services nsdcmdav.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X nsdcmd vid process nsdcmdwin.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X nsdlua nsdlua.exeAll-In-One Telcom - adult content dialler
X nsdriver nssys32.exe"NetShagg adware"
X nse nse.exe"Added by the AGOBOT-ML WORM!"
U Nsengine Nsengine.exe"Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here"
U NSHelper aexnsinstallhelper.exeAltiris Express Notification Server Install helper - monitors integrity of the installation
X nssysconf [random filename]"Added by the VIVIA.A TROJAN!"
X nstat netstat.exeAdult content dialler
X NSupdate NSupdate.exe"Added by the Dial/Laet-B premium rate dialer!"
X Nsv nsvsvc.exe"Delfin Promulgate adware"
X nsvcin n20050308.exe"Delphin Media Viewer adware related"
X Nsvdr nsvdr.exeAdult content dialler
U nsys nsys.exe"NetSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X nsys32 nsys32.exe"Added by the AGOBOT-SU WORM!"
N NSystemMonitor Symmon.exeNorton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
N NT Kernel Patch ntkrnlpt.exe"FaxServe network fax software"
X NT Logging Service Syslog32.exe"Added by the DONK.B WORM and variants!"
X NT MICROSOFT SVCD ntvsvcd.exe"Added by a variant of the RBOT WORM!"
X NT security rundll32.com"Added by the RBOT-AJC WORM!"
X NT Service NTOKSRNL.EXE"Added by the RBOT-AAG WORM!"
X NT Services ntsvc.exe"Added by the AGOBOT.VJ WORM!"
X Nt System Protocol ntsystem.exe"Added by the RBOT.DSB TROJAN!"
X NT Virtual Machine [path to file]"Added by the SCAERBOT-A WORM!"
X Nt**.exe [* = random char] Nt**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
X Nt**32.exe [* = random char] Nt**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
X NT-Virtual Device Manager ntvdmn.exe"Added by the SDBOT-AAA WORM!"
X Ntcheck mapserver.exe"Added by the TOMPAI-B WORM!"
X NTCommLib3 NTCommLib3.exe"Admess adware variant"
X ntddetect ntddetect.exe"Added by the AGENT-CU TROJAN!"
X NTdhcp NTdhcp.exe"Added by the QQROB-C TROJAN!"
X NTdhcp CiKewl.exe"Added by the QQROB-N TROJAN!"
X ntdll ntdll.exe"Added by the BIONET.404 TROJAN!"
X ntdll.dll TrustCleaner.exe"Smithfraud variant"
X NTDLM csrss.exe"Added by the HALE TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""Qossrv"" subfolder"
X Ntech.patchs [trojan filename]"Added by the LEMIR.G TROJAN!"
X ntechin n20050308.exe"Delphin Media Viewer adware related"
X nternet Explorer iexplore.exe"Added by the FORBOT-CT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process
X NTFS16 ntfs16.exe"Added by the RBOT-LY WORM!"
Y NTFSCLUP NTFSCLUP.EXE"Part of ConfigSafe- ""checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99+% of the time it will only execute about a dozen instructions before exiting"""
X ntfsmonitorpro ntfs64.exe"Added by the FORBOT-EB WORM!"
X NTFSS Microsoft System filees.exe"Added by the RBOT.GAB WORM!"
X NTFSS MICROSOFT SYSTEM filess.exe"Added by the RBOT.AXZ WORM!"
Y ntl Netguard RPS.exe"ntl Netguard - anti-virus a package of services
X ntldr ntldr.exe"Browser hijacker to search-control.com (TrojanDropper.Win32.Small.ig). In addition to Registry changes found by HijackThis
N ntlfreedom "rundll32 [path] RyDial.dll QuickStart"
X ntmsevt ntmsevt.exe"Added by the STOPED-B TROJAN"
X NTP Server [path to trojan]"Added by the RANKY.F TROJAN!"
Y nTrayFw ntrayfw.exeSoftware interface for NVIDIA ActiveArmor - hardware firewall built into nVidia nForce motherboard chipsets
N NTrtc ntrtc.exe"Dell year 2000 tool to deal with non-standard applications. Only required on older Dell PCs that may need this support - see here"
X NTSet32 services.exe"Added by the WINSPY-C TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""dll32"" subfolder of the Windows or Winnt folder"
X NTSF Microsoft System fylez.exe"Added by a variant of the RBOT WORM!"
X NTSF MICROSOFT SYSTEM wntsf.exe"Added by the RBOT.ATC WORM!"
X NTSF MICROSOFT SYSTEM fufffy.exe"Added by the RBOT-AEL WORM!"
X NTSF MICROSOFT SYSTEM ntssf.exe"Added by a variant of the RBOT WORM!"
X NTSF MICROSOFT SYSTEM scvhost.exe"Added by a variant of the RBOT WORM!"
X NTSF MICROSOFT SYSTEM winsis32.exe"Added by a variant of the RBOT WORM!"
X NTSF MICROSOFT SYSTEM marya.exe"Added by the RBOT-AXY WORM!"
X NTSF MICROSOFT SYSTEM sysman.exe"Added by the RBOT.EDP WORM!"
X ntsmod ntsmod.exe"Adware downloader/installer
X NTsocket NoeWinnt.exe"Added by the ATAKA-E TROJAN!"
X NTsrv.exe NTsrv.exe"Added by a variant of the SERVU-O TROJAN!"
X Ntsysv ntsysv.exe"Added by the MIFENG-E TROJAN!"
U nTune nTune.exe"nVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards"
X ntupd32 ntupd32.exeUnidentified adware/spyware
X ntupdate dnsvc.exe"Added by the SDBOT-TC WORM!"
X NTupdater [path to trojan]"Added by the DIGARIX-D TROJAN!"
U NTVDM NTVDM.EXE"Windows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS's (Windows NT
X ntvdmd ntvdmd.exe"Adware downloader - also detected as the DLOADER-YP TROJAN!"
X ntvdscm ntvdscm.exe"Added by the SCKEYLOG-I TROJAN!"
Y NuTCSetupEnviron ncoeenv.exe"Used by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows
X NvagNT nvagNT.exe"Added by the AGOBOT-RV WORM!"
X nvc Win32 nvcvc.exe"Added by the RBOT-ADD WORM!"
X NvClipRsv svchost.exe"Added by the DUMARU-K WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder"
X NvClipRsv swchost.exe"Added by the DUMARU-AK WORM!"
? NVCLOCK "rundll32 nvclock.dll fnNvclock"
? NvColorInit "rundll32.exe NvQtwk.dll NvColorInit"
X NVCOM NVCOM.exe"Added by the AGOBOT-SB WORM!"
U NvCpl "rundll32.exe NvCpl.dll NvStartup"
X NvCpl NvCpl.EXE"Added by the YANZ.B WORM!"
X NvCpl [random filename]"Added by the AGOBOT-APJ WORM!"
X NvCpl windowsp.exe"Added by a variant of the SDBOT WORM!"
X NvCpl rundl32.exe"Added by the AGOBOT-TO WORM! Note - the valid version of this entry has the command line as ""rundll32.exe NvCpl.dll
X NvCpl32Deamon nvcpl.exe"Added by the RPCSDBOT.B WORM!"
X NvCplD m2gr32.exe"""Switch"" premium rate adult content dialler"
X NvCplD ntcpl.exe"Switch adult content dialler"
N NvCplDaemon "rundll32.exe NvQtwk.dll NvCplDaemon"
U NvCplDaemon "rundll32.exe NvCpl.dll NvStartup"
X NvCplDaemon msmsgrs.exe"Added by the DLOADER-YI TROJAN!"
X NvCplDaemon32 anvshell32.exe"Added by the XU TROJAN!"
X NvCplDeamon nvdisp.exe"Added by the PEEPVIE-I TROJAN!"
X NvCplDmn NAVSVC.EXE"Added by an unidentified VIRUS
X NvCplScan msc32.exe"Added by the FORBOT-DD WORM!"
X NvCplScan winasp.exe"Added by the FORBOT.BZ WORM!"
X NvCplScan nvsc32.exe"Added by the BROPIA.N WORM!"
X NvCplScan kav32.exe"Added by the FORBOT-EW WORM!"
X nvctrl.exe nvctrl.exe"Added by the ZLOB.G TROJAN!"
X nvd32 lptt01 nvd32.exe"RapidBlaster variant (in a ""nvd32"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X nvd32 ml097e nvd32.exe"RapidBlaster variant (in a ""nvd32"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
U NVHotkey rundll32.exe [path] nvHotkey.dll"Enables the use of ""hot keys"" for changing setting on Nvidia graphics"
X Nvid [8 random charachters]Unidentified adware
X Nvid32 Nvid32.exe"Added by the GEMA TROJAN!"
X Nvidex32 Nvidex32.exe"Added by the GEMA TROJAN!"
Y NVIDIA ActiveArmor ntrayfw.exeSoftware interface for NVIDIA ActiveArmor - hardware firewall built into nVidia nForce motherboard chipsets
X Nvidia Control Daemon nksvc32.exeAdded by an unidentified WORM or TROJAN!
X Nvidia Control Panel ncsvc32.exe"Added by an unidentified VIRUS
X NVIDIA Driver MSPMSPSU.EXE"Added by the WOOTBOT.Y WORM!"
X nVidia Drivers nVidiaDrvers.exe"Added by the SDBOT-AFX WORM! Note - this is not related to any nVidia based motherboard or graphics card"
N NVIDIA nForce APU1 Utilities NVATray.exe"nVidia's nForce Audio Processing Unit (APU)- ""provides 3D positional audio and DirectX 8.0 compatibility
U NVIDIA nTune nTune.exe"nVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards"
U NVidia System Utility NVSystemUtility.exe"NVidia System Utility lets you adjust bus speeds
X NVIDIA Video drivers video_32D.exe"Added by the AGOBOT.KV WORM!"
X NVIDIA Video drivers video_32sD.exe"Added by the RBOT-BB WORM!"
X Nvidia32 nvidia32.exe"CoolWebSearch parasite variant - also detected as the HOSTS-B TROJAN!"
N NvidiaQuickTweak "rundll32.exe NvQtwk.dll NvTaskbarInit"
X nvidll32 nvidll32.exe"Added by the RBOT-XK WORM!"
U NVIEW "rundll32.exe nview.dll nViewLoadHook"
X nviload32 nviload32.exe"Added by the SDBOT-VT WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list