Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Norton GProtect ngrfn.exe"Added by a variant of the RBOT WORM!"
X Norton Guard 32 ntguard32.exe"Added by a variant of the RBOT WORM!"
X Norton Live Update Server cpsdv.exe"Added by the AGOBOT.EW TROJAN!"
X Norton Live Updater Cavapsvc.exe"Added by the GAOBOT.AO WORM!"
X Norton Live Updater Sochost.exe"Added by the GAOBOT.AO WORM!"
N Norton Navigator Loader nnloader.exe"An older Norton utility for file management under Windows 95. More information here"
X Norton Personal Firewall jah.exe"Added by a variant of the SDBOT WORM!"
X Norton Personal Firewall npfw.exe"Added by the RBOT-UI WORM!"
X Norton Personal Firewall lah.exe"Added by a variant of the RBOT WORM!"
X Norton Personal Firewall npfw32.exe"Added by the RBOT-UQ WORM!"
Y Norton Personal Firewall IntroWiz.exePart of Norton Personal Firewall or Norton Internet Security
U Norton Program Scheduler nsched32.exeInstalled on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95 WinNT(?) Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans
U Norton Program Scheduler NPSsvc.exeInstalled on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95 WinNT(?) Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans
? Norton Program Scheduler Event Checker npscheck.exe"Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as NPS Event Checker"
X Norton Protect npprotect.exe"Added by the RBOT-WW WORM!"
X Norton protect nvsvc.exe"Added by a variant of the RBOT WORM!"
X Norton Protect Activies csrss.exe"Added by the BANKER-CZ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""D5133"" subfolder"
X Norton Service Driver wsul.exe"Added by the RBOT-ABI WORM!"
X Norton Service Process navapvc.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Norton SpySweeper AutoUpdate navsw.exe"Added by the FORBOT-AS WORM!"
X Norton System csrs.scr"Added by the BANLOA-AFM TROJAN!"
N Norton System Doctor Sysdoc32.exeNorton Disk Doctor from Norton Utilities. Automatically runs at start-up major resource hog and best started manually form Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well
N Norton SystemWorks cfgwiz.exeNorton System Works configuration wizard. Reportedly a resource hog. Many users find they can live without loading it
X Norton Update ccUpdate.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Norton Update winsvc.exe"Added by the AGOBOT.ALP WORM!"
X Norton Update cUpdate.exe"Added by the AGOBOT.APP WORM!"
X Norton updated NVSV32.EXE"Added by the SDBOT.ABH WORM!"
X Norton Updater winset.exe"Added by a variant of the SPYBOT WORM!"
X Norton Updater lsa.exe"Added by a variant of the RBOT WORM!"
X Norton Updater NortonUpdate.exeAdded by an unidentified WORM or TROJAN!
X Norton Updater ccUpdate.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Norton Updater navupdtr.exe"Added by the SDBOT.AXV WORM!"
X Norton Wizzard nwiz.exe"Added by the GAOBOT.ADV WORM! Note - this is not the valid nVidia application that shares the same name"
X norton32 norton32.exeAdded by an unidentified VIRUS WORM or TROJAN!
X NortonAntivirus LSASS.exe"Added by the PEXMOR WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""Temp"" subfolder of the Winnt or Windows folder. It also has nothing to do with Norton AV"
X NortonAV norton_antivirus.exe"Added by the NETJOE TROJAN! Note - this is not the legitimate Symantec AV program"
X nortonav CCUPD32.EXEAdded by an unidentified WORM or TROJAN!
X nortonp nortonp.exe"Added by the JD-A TROJAN!"
X Nortons AV SYSTEM scvchost.exe"Added by a variant of the RBOT WORM!"
X Nortons AVS Systems arse.exe"Added by the RBOT.AWY WORM!"
X nortonsantivirus ccEvtMngr.exe"Added by the HZDOOR-A TROJAN!"
X NortonVPlus svchost.exe"Added by the ROAMER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X noskrnl noskrnl.exe"Added by the PEACOMM.D TROJAN!"
U Notebook Maximizer maximizer_startup.exeToshiba Notebook Maximizer software - adjust settings to save battery power and increase efficiency
U NotebookHardwareControl nhc.exe"""With Notebook Hardware Control you can easily control the hardware components of your Notebook"""
? NotebookManager nbm.exe"Associated with Acer notebook PCs. What does it do and is it required?"
N NoteBurner VTBurnerGUI.exe"NoteBurner from NoteBurner Inc. - ""a versatile music converter that can be used as MP3 music converter AAC audio converter WAV to MP3 converter M4A to MP3 converter and RM to MP3 converter"""
X NotePad [worm filename]"Added by the SILLYFDC-G WORM!"
X Notepad ntoepad.exe"Added by the DELBOT-AK WORM!"
X Notepad lptt01 notepad.exe"RapidBlaster variant (in a ""Notepad"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not Windows Notepad which has the same executable name"
X Notepad ml097e notepad.exe"RapidBlaster variant (in a ""Notepad"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not Windows Notepad which has the same executable name"
X notepad.exe upx.exeAdded by a variant of the AGENT.AH TROJAN!
X notepad.exe msmsgs.exe"Added by a variant of the FAKESPY-B TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name!"
X notepad.exe msmsgs.exe"Added by the ZLOB-I TROJAN!
X notepad.exe msmsgs.exe"Added by the ZLOB-I and ZLOB-H TROJANS! Note - not to be confused with msmsgs.exe the well known MSN Instant Messaging application!"
X notepad2.exe popuper.exe"Added by the PUPER-E TROJAN!"
X notes notepaad.exe"Added by the RBOT.BME WORM!"
U NoticeP.exe NoticeP.exe"Part of iSync which allows ""you to transfer songs from any music downloading software to your iTunes? library"". The trial version displays advertisements which disappear if you purchase the software"
X Notification Utility altpayV2.exe"Reported by Ewido Security Suite as WeirWeb adware"
X Notn Eber.exe"PurityScan/Clickspring adware"
X Notn wtta.exe"PurityScan/Clickspring adware"
U NovaBackup * Tray Control NbkCtrl.exe"Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version number"
? NovaPortal Single User Service NPSU.exe"??"
U NovastorSchedulerd SCHENGD.EXENovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it
X novsvida.exe novsvida.exe"GlobalAccess dialer"
X NoWayVirus pgs.exe"NoWayVirus misleading security software - not recommended see here"
X NOYPI_KANG_ASTIG Exit to DosPrompt.pif"Added by the FILUKIN.A WORM!"
X np upnp.exe"Added by the YABE.AE TROJAN!"
X NPF Value NPFMONTR.exe"Added by the RBOT-AWD WORM!"
? NPFMonitor NPFMntor.exe"Norton AntiVirus Firewall Install Monitor. What does it do and is it required?"
X npkmnc npkmnc.exe"WebVia adware"
U NPROTECT nprotect.exeNorton Protected Recycle Bin from Norton Utilities. Adds an extra layer of safety before you remove deleted files from the Recycled Bin. Can be listed twice which is valid
? NPS Event Checker npscheck.exe"Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event Checker"
X NS ns.exe"Added by the AGOBOT-HS WORM!"
X NSCheck NSCHECK.EXE"MarketScore parasite - ActiveX control used to download premium-rate dialers"
X nscntrl nscntrl.exe"Added by the DLOAD-DC TROJAN!"
X nsdcmd services nsdcmdav.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X nsdcmd vid process nsdcmdwin.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X nsdlua nsdlua.exeAll-In-One Telcom - adult content dialler
X nsdriver nssys32.exe"NetShagg adware"
X nse nse.exe"Added by the AGOBOT-ML WORM!"
U Nsengine Nsengine.exe"Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here"
U NSHelper aexnsinstallhelper.exeAltiris Express Notification Server Install helper - monitors integrity of the installation
U NSK NSK.exe"Ardakey keystroke logger/monitoring program - remove unless you installed it yourself!"
U NSRKey NSRTray.exe"System Tray access to Norton Save & Restore backup utility"
X nssysconf [random filename]"Added by the VIVIA.A TROJAN!"
X nstat netstat.exeAdult content dialler
X NSupdate NSupdate.exe"Added by the Dial/Laet-B premium rate dialer!"
X Nsv nsvsvc.exe"Delfin Promulgate adware"
X nsvcin n20050308.exe"Delfin Media Viewer adware related"
X Nsvdr nsvdr.exeAdult content dialler
U nsys nsys.exe"NetSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X nsys32 nsys32.exe"Added by the AGOBOT-SU WORM!"
N NSystemMonitor Symmon.exeNorton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
N NT Kernel Patch ntkrnlpt.exe"FaxServe network fax software"
X NT LM Security Support Provider WinNTLM.exe"Added by a variant of the SDBOT WORM!"
X NT Logging Service Syslog32.exe"Added by the DONK.B WORM and variants!"
X NT MICROSOFT SVCD ntvsvcd.exe"Added by a variant of the RBOT WORM!"
X NT security rundll32.com"Added by the RBOT-AJC WORM!"
X NT Service NTOKSRNL.EXE"Added by the RBOT-AAG WORM!"
X NT Services ntsvc.exe"Added by the AGOBOT.VJ WORM!"
X Nt System Protocol ntsystem.exe"Added by the RBOT.DSB TROJAN!"
X NT Virtual Machine [path to file]"Added by the SCAERBOT-A WORM!"
X NT Windows System Manager Loader csrlss.exe"Added by the AGOBOT.OX WORM!"
X Nt**.exe [* = random char] Nt**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
X Nt**32.exe [* = random char] Nt**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
X NT-Virtual Device Manager ntvdmn.exe"Added by the SDBOT-AAA WORM!"
X Ntcheck mapserver.exe"Added by the TOMPAI-B WORM!"
X NTCommLib3 NTCommLib3.exe"Admess adware variant"
X ntddetect ntddetect.exe"Added by the AGENT-CU TROJAN!"
X NTdhcp NTdhcp.exe"Added by the QQROB-C TROJAN!"
X NTdhcp CiKewl.exe"Added by the QQROB-N TROJAN!"
X ntdll ntdll.exe"Added by the BIONET.404 TROJAN!"
X ntdll.dll TrustCleaner.exe"Smitfraud variant"
X NTDLM csrss.exe"Added by the HALE TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Qossrv"" subfolder"
X Ntech.patchs [trojan filename]"Added by the LEMIR.G TROJAN!"
X ntechin n20050308.exe"Delfin Media Viewer adware related"
X nternet Explorer iexplore.exe"Added by the FORBOT-CT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X NTFS16 ntfs16.exe"Added by the RBOT-LY WORM!"
Y NTFSCLUP NTFSCLUP.EXE"Part of ConfigSafe- ""checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99+% of the time it will only execute about a dozen instructions before exiting"""
X ntfsmonitorpro ntfs64.exe"Added by the FORBOT-EB WORM!"
X NTFSS Microsoft System filees.exe"Added by the RBOT.GAB WORM!"
X NTFSS MICROSOFT SYSTEM filess.exe"Added by the RBOT.AXZ WORM!"
X ntfyapp ntfyapp.exe"Detected by PCTools as the ZHELATIN WORM! See here"
Y ntl Netguard RPS.exe"ntl Netguard - anti-virus a package of services specifically designed to keep you safe and secure with their ntlworld online services"
X ntldr ntldr.exeBrowser hijacker to search-control.com (TrojanDropper.Win32.Small.ig). In addition to Registry changes found by HijackThis also creates the following system files: C:WINDOWSSYSTEM tldr.exe C:m.exe C:WINDOWSSearch-For-You.url C: .bat C:q.exe C: .bat
N ntlfreedom rundll32 [path] RyDial.dll QuickStart"NTL Freedom dial-up ISP software - not required"
X ntmsevt ntmsevt.exe"Added by the STOPED-B TROJAN"
X NTP Server [path to trojan]"Added by the RANKY.F TROJAN!"
Y nTrayFw ntrayfw.exeSoftware interface for NVIDIA ActiveArmor - hardware firewall built into nVidia nForce motherboard chipsets
N NTrtc ntrtc.exeDell year 2000 tool to deal with non-standard applications. Only required on older Dell PCs that may need this support
X NTSet32 services.exe"Added by the WINSPY-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dll32"
X NTSF Microsoft System fylez.exe"Added by a variant of the RBOT WORM!"
X NTSF MICROSOFT SYSTEM wntsf.exe"Added by the RBOT.ATC WORM!"
X NTSF MICROSOFT SYSTEM fufffy.exe"Added by the RBOT-AEL WORM!"
X NTSF MICROSOFT SYSTEM ntssf.exe"Added by a variant of the RBOT WORM!"
X NTSF MICROSOFT SYSTEM scvhost.exe"Added by a variant of the RBOT WORM!"
X NTSF MICROSOFT SYSTEM winsis32.exe"Added by a variant of the RBOT WORM!"
X NTSF MICROSOFT SYSTEM marya.exe"Added by the RBOT-AXY WORM!"
X NTSF MICROSOFT SYSTEM sysman.exe"Added by the RBOT.EDP WORM!"
X ntsmod ntsmod.exe"Adware downloader/installer probably VX2/Look2Me related - also detected as the WIN32.VB.RL TROJAN!"
X NTsocket NoeWinnt.exe"Added by the ATAKA-E TROJAN!"
X NTSpool NTSpool.exe"Added by the AGENT-GPY TROJAN!"
X NTsrv.exe NTsrv.exe"Added by a variant of the SERVU-O TROJAN!"
X Ntsysv ntsysv.exe"Added by the MIFENG-E TROJAN!"
U nTune nTune.exe"nVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards"
U nTuneCmd nTuneCmd.exe"nVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards"
X ntupd32 ntupd32.exe"Unidentified malware - see here"
X ntupdate dnsvc.exe"Added by the SDBOT-TC WORM!"
X NTupdater [path to trojan]"Added by the DIGARIX-D TROJAN!"
X ntuser ctfmun.exe"Detected by Symantec as the SILLYFDC WORM! See here"
X ntuser ntuser.exe"Added by the SMALL!SD5 TROJAN!"
X ntuser spool.exe"Detected by Symantec as the SILLYFDC WORM! See here"
X ntuser spools.exe"Detected by Symantec as the SILLYFDC WORM! See here"
X ntuser svchost.exe"Added by a variant of the WORM_SOCKS.D WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""driver"" sub-folder"
U NTVDM NTVDM.EXE"Windows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS's (Windows NT 2K and XP). Required if hardware on a machine with these OS's needs 16-bit DOS drivers. You can find a bit more about NTVDM here"
X ntvdmd ntvdmd.exe"Adware downloader - also detected as the DLOADER-YP TROJAN!"
X ntvdscm ntvdscm.exe"Added by the SCKEYLOG-I TROJAN!"
X ntx32 ntx32.exeAdded by an unidentified WORM or TROJAN!
X Numerical Xterm Agent 0x32.exe"Added by the RBOT-FWP WORM!"
X Numerical Xterm Agents 2x32.exe"Added by the RBOT-FWY WORM!"
X Numerical Xtermz Agent 1x32.exe"Added by the RBOT-FWX WORM!"
Y NuTCSetupEnviron ncoeenv.exe"Used by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows so disabling this would be unwise if you are using NuTCracker or any 3rd party package that is using it. Since you might not know what is actually using it it's probably best left alone"
U NuvaTime NuvaTime.exe"NuvaTime - reminder for women using NuvaRing"
X NvagNT nvagNT.exe"Added by the AGOBOT-RV WORM!"
X nvc Win32 nvcvc.exe"Added by the RBOT-ADD WORM!"
X NvCCCpl NvCCCpl.exe"Added by the NOGATA-A TROJAN!"
X nvchost winlogon.exe"Added by the KLONE-J TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X NvClipRsv svchost.exe"Added by the DUMARU-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X NvClipRsv swchost.exe"Added by the DUMARU-AK WORM!"
? NVCLOCK rundll32 nvclock.dll fnNvclock"Overclocking utility for nVidia based graphics cards?"
X nvcoi nvcoi.exe"Added by the DLOADER.TYO TROJAN!"
? NvColorInit rundll32.exe NvQtwk.dll NvColorInit"Associated with Nvidia based graphics cards"
X NVCOM NVCOM.exe"Added by the AGOBOT-SB WORM!"
U NvCpl rundll32.exe NvCpl.dll NvStartupIntializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
X NvCpl NvCpl.EXE"Added by the YANZ.B WORM!"
X NvCpl [random filename]"Added by the AGOBOT-APJ WORM!"
X NvCpl windowsp.exe"Added by a variant of the SDBOT WORM!"
X NvCpl rundl32.exe"Added by the AGOBOT-TO WORM! Note - the valid version of this entry has the command line as ""rundll32.exe NvCpl.dllNvStartup"""
X NvCPL32 nvcpl32.exe"Added by the AGOBOT.DAA WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list