CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    Norton Personal FirewallXjah.exeAdded by a variant of the W32/SDBOT WORM!
    NvCplX(random,executable)Added by the W32/AGOBOT-APJ WORM!
    nstatXnetstat.exeadult material dialer
    NT LM Security Support ProviderXWinNTLM.exeAdded by a variant of the W32/SDBOT WORM!
    NAV AgentXsystems.exeAdded by the TARNO.C VIRUS! Note - this is not the valid Norton Antivirus entry of the same name
    NVagentXInforme.exeAdded by the W32.Vig.C VIRUS! Note: Copies it's self to multiple Drives and folders.
    NetCruiser DialerUNCDialer.exeNetCruiser Dialer from NetCruiser Software. "An Internet dialer and connection monitor with features to launch applications when a connection is detected, dial and hangup at predefined times and automatic redialing of dropped connections"
    Newsgroup ml097eXnewsgroup.exe RapidBlaster Variant
    netsv32Xsv.exeIdentified by Normon antivirus as the W32/Zapchast.AQK malware. Note: located in \%WINDIR%\ Note: Use SDFix under supervision.
    Norton FirewallX(path of the,Trojan EXE)Added by the Troj/Banker-ET TROJAN!
    Netunit32Xwunit32.exeAdded by an unidentified WORM or TROJAN!
    nmappNnmapp.exeRelated to Pure_Networks_Network_Magic This program is a non-essential process, but should not be terminated unless suspected to be causing problems. Note: Located in C:\Program Files\Pure Networks\Network Magic\
    notepad.exeXmsmsgs.exeAdded by a variant of the Troj/FAKESPY-B TROJAN! - NOTE: this particular msmsgs.exe file is located in the Windows\System32 or Winnt\System32 folder, and should not be mistaken for the MSN Messenger file of the same name!
    Norton Antivirus UpdaterXnortonav.exeAdded by the DELBOT-T WORM! Note - this is not the real Norton AV!
    Nero Updater.6.12Xwmp9.exeAdded by the W32/Agobot-AAG Worm!
    nvsv32.exeXcstr.exeAdded by a variant of the W32/SDBOT WORM!
    Nero DriveSpeedNDRIVESPEED.EXERelated to Ahead_Nero CD writing software. Non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems. Note: located in C:\PROGRA~1\Ahead\NEROTO~1\
    nsdcmd servicesXnsdcmdav.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    NI.UWFX5_0001_N57M2112X4.tmpThis is WinFixer Malware. Note: This Malware file is located in the Documents and Settings\User name\Local Settings\Temp folder.
    NoAdwareUNoAdwareNoAdware Adware/Spyware remover - initially considerered a "rogue" program - see here . The latest version has since apparently mended its ways: see note
    ntuserXntuser.exeIdentified as a variant of the Trojan-Downloader.Win32.Small.hpb malware. Note: located in %userprofile%\ [Use SDFix under supervision]
    New Csnm ManagerXcsmn.exeAdded by the SDBOT.BZS WORM!
    netservicesXrecall.exeAdded by a variant of the W32/SDBOT WORM!
    NVRTNnvrt.exeNVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports
    Nero CheckerXnerocheck.exeAdded by the Troj/Proxy-X TROJAN! Note: This is NOT related to "Nero Burning Rom" CD writing software. This trojan file is found in the Windows or Winnt folder.
    Network SecurityXsecsvc.exeAdded by the W32/Rbot-ALX WORM!
    Notepad lptt01Xnotepad.exe RapidBlaster Variant
    NLS KeyboardXkeyboard.exeAdded by a variant of the W32.SPYBOT WORM!
    nton.exeXnton.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    nvsv32.exeXnvsv33.exeAdded by the WOOTBOT.FP WORM!
    NaverPCGreenUNPCGreenUpgrader.exeRelated to Naver_Anti-virus Realtime Monitor From NHNCorp. Note: Located in \%Program Files%\Naver\NaverPCGreen\
    Nero.maX.exeAdded by the JONBARR.D VIRUS! where <digits> is 2 or 3 random digits
    NMSSupportYIntelHCTAgent.exeRelated to Intel_DH_Support A Network monitor for Intel® Hub Connect Technology. Note: Located in C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\
    Notebook MaximizerUmaximizer_startup.exeToshiba Notebook Maximizer software; adjust settings to save battery power and increase efficiency
    NOFIIN.EXEXNOFIIN.EXE Troj/Haxdoor-DP
    NaviSearchXnls.exeeXact Advertising BargainBuddy/NaviSearch adware
    nTrayFwYntrayfw.exeSoftware interface for NVIDIA ActiveArmor - hardware firewall built into nVidia nForce motherboard chipsets
    Net iDUiid.exeRelated to Net_iD Certificate for logging on to remote system. Note: Located in Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Network Service ManagerXnetsvc.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    NisumYNISUM.EXENorton Personal Firewall
    navp.exeXnavp.exeAdded by the W32/AGOBOT-OE WORM!
    Network ConnectionsXinternat.exeAdded by the TROJ/VB-ZD TROJAN!
    NvCplScanXwinasp.exeAdded by the FORBOT.BZ WORM!
    NetGuardUNetGuard.exeFBM Software ZeroSpyware 2004 spyware detector and remover; real time monitor.
    nmctxthUnmctxth.exeRelated to Pure_Networks comprehensive home and small business networking software that simplifies network configuration. Note: Located in \%Program Files%\Note: Located in \%Program Files%\
    Norton Navigator LoaderNnnloader.exeAn older Norton utility for file management under Windows 95. More information here
    NetWatch32Xnetwatch.exeAdded by the W32.MIMAIL.C WORM!
    NMSSvc?NMSSVC.EXENIC Management Service - diagnostics program for Intel Pro family network cards
    Nod32 ServiceXalserv32.exeAdded by the RBOT.DHN WORM!
    NGServerNngserver.exeSymantec/Norton Ghost Console service
    neqprvfy.exe?neqprvfy.exeAppears to be related to the downloading of some application - possibly verifying updates?
    NfoXnfomon.exeAdded by the Adware.W32.DelFin Note: Located in C:\Windows\System\nfomon\ (Win9x/Me), C:\%WINDIR%\System32\nfomon\ (XP/WinNT/2K) More: here
    norten Software IntrenetXnorten.pifAdded by W32/Rbot-AWA WORM!
    NvCplUNvStartupIntializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
    NvCplDaemonXmsmsgrs.exeAdded by the Troj/Dloader-YI TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer