Name Filename Status Description
(Default) NOTEPAD.exe X Added by the RUSTY WORM! Note - not to be confused with the valid Windows "NOTEPAD" text editor
/l:eng N/A N Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function
17779Proj2002 N/A ? ??
1CmailS NETMAIL.EXE ? ??
4wd!!! Natal!.pif X Added by the OPASERV.AI WORM!
anbv32 nabv32.exe X Added by the TITOG.C WORM!
Application Explorer Naldesk.exe U Novell Zenworks Application Explorer Executable. "For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."
ARCSolo Recovery N/A N Backup software by Computer Associates - no longer supported
Batchreg1 N/A N Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation, as that key should be deleted automatically. See here
Boot Manager Njgal.exe X Added by the KILO TROJAN!
Corel Reminder NAVBROWSER.EXE N If you don't want to register Corel products and be reminded about it every 2 weeks disable it
CostAware niIPCApp.exe U NetInternals CostAware - download quota measuring tool
cpntmgc navpmc.exe X MagicControl downloader trojan variant
DashIE N/A ? Could be related to "Dash Power Shopping" tool bar in IE?
Datechecker N/A ? Could be related to this?
DDT N/A ? ??
directx NTCmd.exe X Added by the SDBOT.D TROJAN!
Disable EHCI nousb20.exe ? ??
DLHelperEXE.exe N/A X Downloader for Microgaming/Casino software - stealth installed
Fast start Ntut.exe X Added by unidentified adware - recognized by Kaspersky antivirus as Trojan.Win32.Favadd.i
NaturalColorLoad NaturalColorLoad.exe U Natural Color help users synchronize the on screen colors with printed ones.
Generic Host Process for Win32 Services ntspcv.exe X Added by the SDBOT.S TROJAN!
GinaDll ntgina.dll X Added by the ANIG.A WORM!
Host N/A X Added by the POPDIS or STARTPAGE.F TROJANS!
hpoddt01.exe N/A N Installed by the "HP Photo and Imaging Director" software. If you ask for the imaging software, this program will be started
Hti npdor.exe U Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required
HWinst N/A Y For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
iCn NAG.EXE N iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist
Inetapi Netapi.exe X Added by the NETDEVIL.14 TROJAN!
IPinst N/A Y For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
IPv6 STUN Service netstun.exe X Added by a variant of the SDBOT WORM!
Iusage netdet.exe N Internet Usage Monitor - utility to calculate the cost and time on the internet via dial-up
IZE N/A ? ??
Kernel Loader ntkrnl.exe X Added by the CERVIVEC.A WORM!
LASTinst N/A Y For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
norton updater navupdtr.exe X Added by the SDBOT.AXV WORM!
load32 netda.exe X Added by the NIBU.E TROJAN!
Loadout Manager nost_LM.exe U Manager for the Belkin Nostromo n50 SpeedPad game controller - see here
Mcafee Anti Scan NortonScn.exe X Added by a variant of the RBOT WORM!
Microsoft NetMeeting Associates, Inc. NetMeeting.exe X Added by a variant of the LOVGATE WORM!
Microsoft Network Daemon for Win32 Netd32.exe X Added by the SDBOT.R TROJAN!
Microsoft Software Update nmon.exe X Added by the RBOT.HZ WORM!
Microsoft Synchronization Manager netscape.exe X Added by the RANDEX.AE WORM!
Microsoft System Checkup ntsysmgr.exe X Added by the DONK.S WORM!
Microsoft System Checkup ntsysman.exe X Added by the SDBOT-QW WORM!
Microsoft Update navmgrd.exe X Added by the SDBOT.DP TROJAN!
Microsoft Update NAV.exe X Added by the RBOT-IV WORM!
Microsoft Update Machine ntce.exe X Added by the RBOT-FA WORM!
MicrosoftNetwork Daemon for Win32 NETD32.EXE X Added by the RANDEX.F WORM!
Mirabilis ICQ NDetect.exe N If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
Mozilla Quick Launch Netscp6.exe N Netscape 6 and Mozilla browsers
MSupdate.exe N/A X CoolWebSearch parasite related - resets home page to an adult content site
MSupdater.exe N/A X CoolWebSearch parasite related. Installs the Winshow.dll browser plugin
MS_NETD_WIN32 netd32.EXE X Added by the RANDEX.F WORM!
myNetWatchman nwclient.exe U Sends your firewall alerts to a website, which then filters them and forwards details of suspicious activities to the host ISP they originated from. Only needs to be running when your firewall is running
MySoftware NewsFlash Newsflsh.exe N A program that runs in your task bar and receives alerts and release information on MySoftware products.
N2PTray Net2fone.exe U An Internet telephony application. Needed only if you have an account at Net2Phone, Inc
NADaemon NADAEMON.EXE N Program by NetActive which appears to be piggybacked onto some Nvidia graphics cards software. They seem to look after "digital rights management". One user reports disabling it has no detrimental affect - not required
Naggerrunkey nagger.exe N Packard Bell Free Internet Signup screen
Naimagent_UI naimag32.exe Y Workstation background program for Network Associates’ McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan
Natal Natal.scr X Added by the OPASERV.AE WORM!
NAV Agent navapw32.exe Y Norton Anti-Virus's background scanning process
nAv AGENT N/A X Added by the RIOSYS MACRO! Note the lower-case "n" and "v" in the name as this is not the valid Norton AntiVirus entry of the same name - indeed it closes Norton AV processes
NAV Auto Update Navautoupdate.exe X Added by a variant of the SPYBOT WORM!
NAV Scan Service NAVSCAN32.EXE X Added by the SDBOT.VG WORM!
navapp navapp.exe X NavExcel adware variant
navapw32 navapw32.exe Y Norton Anti-Virus's background scanning process
Naviscope naviscope.exe U Naviscope is a multipurpose browser enhancement that can speed up Web searches, lock out cookies, examine HTML send/receive headers, provide single-click network diagnostics, and much more
NaviSearch nls.exe X NaviSearch, eXact Advertising variant
navp.exe navp.exe X Added by the AGOBOT-OE WORM!
NavPass NavPass.exe X Free system for gaining access to and downloading from adult content web-sites
NAVSCANNER32 NAVSCANNER32.EXE X Added by the RBOT.QC WORM!
NAVUpd navupd.dll X Added by the NAVU TROJAN!

Please note, C:\Windows\System32\rundll32.exe is a legitimate program and should not be deleted.
NBJ NBJ.exe U Ahead Nero BackItUp backup program. Only required for if you have scheduled back-ups
NbkCtrl NbkCtrl.exe U Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here
NCClient N/A ? ??
NCD ncd.exe N Norton Change Directory - from the DOS days that allows the user to change directories on their machine without typing the complete path
NCLAUNCH NCLAUNCH.Exe U Part of SWF Studio from Northcode Inc - an extension to Flash. Bundled when you create a self-installing screen-saver on Win2K/XP.
NDDEAGNT NDDEAGNT.EXE ? WinNT default process. Network Dynamic Data Exchange (DDE) Agent, handles requests for network DDE services
NDIS Adapter ndis.exe X Added by the SDBOT.VF WORM!
NDplDeamon nstask32.exe X Added by the RANDEX.E WORM!
NDrv NDrv.exe X PurityScan/Clickspring adware
NDSTray NDSTray.exe U ConfigFreeT Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required, for people who span multiple networks and want an easy way to go from wired to wireless and change addresses and other network settings, it's a must have
Necbar Necbar.exe N Nec Assistant; Ark's Navigator, a graphical interface for NEC computers
NECMFK necmfk.exe Y NEC wireless keyboard driver
Necutray Necutray.exe U Driver for external USB storage devices (hard drives, flsh disks, etc)
neqprvfy.exe neqprvfy.exe ? Appears to be related to the downloading of some application - possibly verifying updates?
NeroAutoStartClient NeroASM.exe X Added by the AGOBOT.VG WORM!
NeroCheck nerocheck.exe U Associated with "Nero Burning Rom" CD writing software. Checks for driver issues
NeroFilterCheck NeroCheck.exe U Associated with "Nero Burning Rom" CD writing software. Checks for driver issues
NeroNETTrayIcon NNServiceCtrl.exe N System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network
Net Accelerator NetAccelerator.exe U Rizal NetAccelerator - "Optimizing Dial-Up, Lan, Cable, DSL, and Satellite connections do you want to speed up your Internet access up to 200% - 300% ???". Only required if you find it helps improve your performance
Net Activity Diagram nad.exe U Net Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start -> Programs
Net-It Launcher NILaunch.exe N Net-It - web publishing software
NetAccelerator NetAccel.exe U NetAccelerator is a "software utility that optimizes your internet access up to 1200% faster!. NetAccelerator speeds all modems allowing you to download faster, browse faster, surf faster!. Only required if you find it helps improve your performance
NetAdm7 NETADM7.EXE X Added by the BANCOS.F TROJAN!
Netapi Netapi.exe X Added by the NETDEVIL.14 TROJAN!
netconfig netconfig.exe X Added by the NETCONF TROJAN!
NetCruiser Dialer NCDialer.exe U NetCruiser Dialer from NetCruiser Software. "An Internet dialer and connection monitor with features to launch applications when a connection is detected, dial and hangup at predefined times and automatic redialing of dropped connections"
netdaemon netdaemon /v X Malware designed to "kill" a number of antispyware applications (SpyBot, Giant, SpyDoctor, SpySweeper, SpyHunter, Anvir, WinPatrol, and more)
netdll32 netdll32.exe X Added by the CRYPTER.A TROJAN!
netdllex netdllex.Exe X Added by the CRYPTER.A TROJAN!
NETFP32.EXE NETFP32.EXE X Added by the AGENT.CD TROJAN!
netfxupdate netfxupdate.exe ? Would appear to be a valid Microsoft .NET file (see here) but this suggest's it's a trojan?
NetFxUpdate_v1.0.3705 netfxupdate.exe ? Would appear to be a valid Microsoft .NET file (see here) but this suggest's it's a trojan?
NetGuard NetGuard.exe U FBM Software ZeroSpyware 2004 spyware detector and remover - real time monitor
Netlimiter Netlimiter.exe U Netlimiter - "An internet traffic control tool to monitor applications which access the internet and actively control their internet traffic. Use it o set (download/upload) speed limits for applications or even single connection. NetLimiter also allows you to share your internet connection bandwidth among all applications running on your PC."
Netline User netchk.exe N Netline supplies internet related products and services and this program identifies user ID and IP information. Found installed along with the Falcon 4 game, for example
NetLink netlink32.exe X Added by the GAOBOT.WO WORM!
NetManagerService ntss.exe X Added by the BESTPICS.A TROJAN!
NetMeter NetMeter.exe X NetRatings software by Opistat . "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!
NetMon netmon.exe X Added by the MIMAIL.M WORM!
netmsg netmsg.exe U Net_Message is a small tool to send messages across the network, using the Windows Messenger Service, so there is no client install required to receive the messages. It has a number of other features as well
netpc32.exe netpc32.exe X Malware, probably CoolWebSearch parasite related
NetPerSec NetPerSec.exe N NetPerSec - measures the real-time speed of your Internet connection
NetPumper NetPumperIEProxy.exe X NetPumper download manager - bundles Cydoor and SaveNow adware, see here
NetReach nrcheck.exe X Added by an unidentified VIRUS, WORM or TROJAN!
Netropa Internet Receiver Netropa.exe X Netropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware
NetRun NetRun.exe U NetRun - will 'RUN' a 'List' of programs only when a internet connection is detected, and close/kill the same 'List' when the connection is lost
Netscape Messenger NETSCAPE.EXE N In Netscape 6 (I know for sure with 6.2.1, maybe with 6.0) Netscape.exe is the main executable file for Netscape Navigator, Netscape Mail and News, and Netscape Messenger (the new name for the embedded AIM, no doubt to make it sound like Windows Messenger, the XP version of MSN Messenger). Basically, netscape.exe can be more than just Netscape Messenger, and Messenger can be more then just AIM in disguise, depending on the version of Netscape installed
Netscp6 Netscp6.exe N Netscape 6
NetShow Powerpoint Helper NSPPTHLP.EXE U If disabled, user created fonts can no longer be seen by other programs
NetStat Live Nsl.exe N AnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data
netsv32 netsv32.exe X Added by the SDBOT-PX WORM!
NetTime NETTIME.EXE U From a visitor - "This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols, e.g. NTP."
NetTurbo netturbo.exe U NetTurbo from SharewareOnline.com. "Accelerate Your Internet Connections by up to 600%". If you find it helps your connectivity leave it enabled
NetWatch32 netwatch.exe X Added by the MIMAIL.C WORM!
Netword Agent nwant33.exe N An interesting browser utility that allows you to navigate by typing a single word or phrase (a "NetWord") related to what you're looking for into your browser's location field. It also puts an icon in the system tray icon that is a circle with the letter N in the center to access the menu faster. Available via Start -> Programs
Network Administration NAS.exe X Added by the ANTILAM.20.Q TROJAN!
NetWork Device Switch NetDevSW.exe U Toshiba laptops with built-in Wi-Fi. Allows switching between Wi-Fi and internal ethernet. Only necessary if you have regular need to switch back and forward between these network interfaces. Located in Startup folder so make own shortcut to it and disable if not really necessary
Network Service Manager netsvc.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
Network Service Manager netsvc.exe X Added by a variant of the GAOBOT/AGOBOT WORM!
NetworkClient NetworkClient.exe X Added by the LEMUR WORM!
Networks Configurator NetConfs.exe X Added by the RBOT-OX WORM!
Networks Controler Netsis.exe X Added by the RBOT-NG WORM!
Netzip Smart Downloader npnzdad.exe X Advertising spyware
NetZIPFolders nzfprop.exe N Netzip Classic zip file manager
NeuroMedia(IESpeaker) NeuroMedia.exe X Part of an older freeware version of IESpeaker - a program that allows you to listen to web pages. NeuroMedia.exe only downloads advertisments. Not included in the paid-for version currently available
New.net Startup newdotnet4_5.dll X NewDotNet foistware

Please note: C:\Windows\System32\rundll32.exe is a legitimate program and should not be deleted.
Newsalrt NEWSALRT.EXE N MSNBC News system tray utility to alert you to new news
Newsgroup lptt01 newsgroup.exe X Variant of the RapidBlaster parasite (in a "newsgroup" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Newsgroup ml097e newsgroup.exe X Variant of the RapidBlaster parasite (in a "newsgroup" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
NewsUpd newsupd.exe N For Creative Soundblaster Live! series soundcards. System tray application for News updates. Available via Start -> Programs. Also spyware - see here.
NewtonKnowsUpd NewtKnow.exe ...NewtnUpd.dll, runkey X NewtonKnow hijacker
NFM Service NPDOR9x.exe U Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required
NGClient ngctw32.exe U Symantec Ghost Server software - needed for a "a Ghost multicast" (transfer images to multiple machines). Can be launched manually
NGServer ngserver.exe N Symantec/Norton Ghost Console service
nikLaus nikLaus.exe X Added by the NIKLAS WORM!
NInit NInit.exe N Norton Uninstall Deluxe. Monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging - not required
nisserv NISSERV.EXE Y Norton Personal Firewall
Nisum NISUM.EXE Y Norton Personal Firewall
NJG40 NJG40.EXE X Added by the BANCOS.D TROJAN!
NkvMon.exe NkvMon.exe N Nikon View 5 - for transferring pictures from Nikon digital cameras
NkVwMon.exe NkVwMon.exe N Nikon View - for transferring pictures from Nikon digital cameras
NMSSvc NMSSVC.EXE ? NIC Management Service - diagnostics program for Intel Pro family network cards
NMSVC nmSvc.exe Y Covenant Eyes - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Disabling it means loss of internet connection until renabled - therefore required if you use it
NNSvc nnsvc.exe U NetNanny internet filter
NoAds NoAds.exe U Blocks advertisement banners in Internet Explorer
NoAdware NoAdware.exe U NoAdware Adware/Spyware remover - initially considerered a "rogue" program - see here . Has since apparently mended its ways: see note
Nod32CC nod32cc.exe U Control Center part of Eset's NOD32 virus-scanner. Leave this enabled if you want to update your virus data files via the click of a button
NOD32kernel Nod32krn.exe Y Nod32 Antivirus Version 2
nod32kui nod32kui.exe Y Nod32 Antivirus Version 2
NodeMnger Nodemngr.exe ? Part of the Dell OpenManage Client installation - to allow Dell representatives to remote logon?
Nokia Connection Monitor NclConf.exe N Monitors the infrared port, the serial ports and the Bluetooth for a Nokia phone connection. It is installed by the Nokia PC Suite (and Nokia PC Connectivity SDK), and the tray icon shows if a phone has been connected. If you have a conflict with another program, such as TV tuner card remote control monitor, you can disable it, and run only when needed. Available via a desktop shortcut or Start -> Programs - not required
Nokia Tray Application NclTray.exe U Nokia PC Suite 5 - "A collection of powerful tools that you can use to manage your phone features and data." Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on
NomdCheck nomdchek.exe N Part of Intel's Native Audio
nomtray nomtray.exe U System Tray access to NetMotion Wireless options - including connectivity status (see here)
Norton AntiVirus Sys NAVsys32.exe X Added by a variant of the WOOTBOT WORM!
Norton Auto Protect nava.exe X Added by an unidentified WORM or TROJAN!
Norton Auto-Protect navapw32.exe Y Norton Anti-Virus's background scanning process
Norton Disk Doctor Ndd32.exe N Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, checking for disk errors. Better than ScanDisk but can be started manually via Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well
Norton Guard 32 ntguard32.exe X Added by a variant of the RBOT WORM!
Norton Navigator Loader nnloader.exe N An older Norton utility for file management under Windows 95. More information here
Norton Program Scheduler nsched32.exe U Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans
Norton Program Scheduler NPSsvc.exe U Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans
Norton Program Scheduler Event Checker npscheck.exe ? Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as NPS Event Checker
Norton Service Process navapvc.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
Norton SpySweeper AutoUpdate navsw.exe X Added by the FORBOT-AS WORM!
Norton Wizzard nwiz.exe X Added by the GAOBOT.ZX or GAOBOT.ADV WORMS! Note - this is not the valid nVidia application that shares the same name
norton32 norton32.exe X Added by an unidentified VIRUS, WORM or TROJAN!
NortonAV norton_antivirus.exe X Added by the NETJOE TROJAN! Note - this is not the legitimate Symantec AV program
NotebookManager nbm.exe ? Associated with Acer notebook PCs. What does it do and is it required?
Notepad lptt01 notepad.exe X Variant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not Windows Notepad which has the same executable name
Notepad ml097e notepad.exe X Variant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not Windows Notepad which has the same executable name
NovaBackup * Tray Control NbkCtrl.exe U Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version number
NovaPortal Single User Service NPSU.exe ? ??
NPFMonitor NPFMntor.exe ? Norton AntiVirus Firewall Install Monitor. What does it do and is it required?
NPROTECT nprotect.exe U Norton Protected Recycle Bin from Norton Utilities. Adds an extra layer of safety before you remove deleted files from the Recycled Bin. Can be listed twice which is valid - see here
NPS Event Checker npscheck.exe ? Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event Checker
NS ns.exe X Added by the AGOBOT-HS WORM!
NSCheck NSCHECK.EXE X NetSetter/Marketscore foistware
nscntrl nscntrl.exe X Adult content dialler
nsdlua nsdlua.exe X All-In-One Telcom - adult content dialler
nsdriver nssys32.exe X Added by an unidentified VIRUS, WORM or TROJAN!
nse nse.exe X Added by the AGOBOT-ML WORM!
Nsengine Nsengine.exe U Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here
nstat netstat.exe X Adult content dialler
NSupdate NSupdate.exe X Added by the Dial/Laet-B premium rate dialer.
Nsvdr nsvdr.exe X Adult content dialler
NT Kernel Patch ntkrnlpt.exe N FaxServe network fax software
NT Services ntsvc.exe X Added by the AGOBOT.VJ WORM!
ntdll ntdll.exe X Added by the BIONET.404 TROJAN!
NTFS16 ntfs16.exe X Added by the RBOT-LY WORM!
NTFSCLUP NTFSCLUP.EXE Y Part of ConfigSafe- "checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99+% of the time it will only execute about a dozen instructions before exiting"
ntldr ntldr.exe X Browser hijacker to search-control.com (TrojanDropper.Win32.Small.ig). In addition to Registry changes found by HijackThis, also creates the following system files: C:\WINDOWS\SYSTEM\ntldr.exe, C:\m.exe, C:\WINDOWS\Search-For-You.url, C:\n.bat, C:\q.exe, C:\r.bat
NTrtc ntrtc.exe N Dell year 2000 tool to deal with non-standard applications. Only required on older Dell PCs that may need this support - see here
NTsocket NoeWinnt.exe X Added by the ATAKA-E TROJAN!
NTsrv.exe NTsrv.exe X Added by a variant of the SERVU-O TROJAN!
NTVDM NTVDM.EXE U Windows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS's (Windows NT, 2K and XP). Required if hardware on a machine with these OS's needs 16-bit DOS drivers. You can find a bit more about NTVDM here
ntvdscm ntvdscm.exe X Added by the SCKEYLOG.O TROJAN!
NuTCSetupEnviron ncoeenv.exe Y Used by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows, so disabling this would be unwise if you are using NuTCracker or any 3rd party package that is using it. Since you might not know what is actually using it it's probably best left alone
NvColorInit NVQTWK.DLL ? Associated with Nvidia based graphics cards
NvCplDaemon NvCpl.dll U Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card.

Please note: %system%\rundll32.exe is a legitimate program and should not be deleted.
NvCpl NvCpl.EXE X Added by the YANZ.B WORM!
NvCpl NvCpl.EXE X Added by the YANZ.B WORM!
NvCplD ntcpl.exe X Switch adult content dialler
NvCplDaemon NvQtwk.dll N System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here)
NvCplDaemon NvCpl.dll U Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
NvCplDmn NAVSVC.EXE X Added by an unidentified VIRUS, WORM or TROJAN!
NvCplScan nvsc32.exe X Added by a variant of the IRC.BOT TROJAN!
nvd32 lptt01 nvd32.exe X Variant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
nvd32 ml097e nvd32.exe X Variant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Nvid32 Nvid32.exe X Added by the GEMA TROJAN!
Nvidex32 Nvidex32.exe X Added by the GEMA TROJAN!
Nvidia Control Panel ncsvc32.exe X Added by an unidentified VIRUS, WORM or TROJAN!
NVIDIA nForce APU1 Utilities NVATray.exe N nVidia's nForce Audio Processing Unit (APU)- "provides 3D positional audio and DirectX 8.0 compatibility, and encodes and decodes Dolby Digital 5.1 audio in real time"
Nvidia32 nvidia32.exe X CoolWebSearch parasite variant
NVmax NVmax.exe Y NVmax is a old tweaking utility for NVidia graphics cards. In the startup list if the user chooses to overclock their card
NvMediaCenter NvMCTray.dll U System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
NVMixerTray NVMixerTray.exe N System Tray access to audio controls from nVidia's motherboard ForceWare software
NVQuickTweak NVQTWK.DLL N System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties.

Please note: C:\Windows\System32\rundll32.exe is a legitimate program and should not be deleted.
NVRT nvrt.exe N NVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports
NVRTClk NVRTClk.exe ? Related to a Gigabyte video card. What does it do, and is it required?
nvsv32.exe nvsv32.exe X Added by the FORBOT-DI WORM!
NvSvc nvsvc.exe N NVIDIA Driver Helper Service - installed when you change from the WDM drivers to nVidia's latest versions but not requied. Extreme shutdown delays can be encountered with this service active, but no adverse side effects with it disabled. NOTE: If using drivers other than nVidia's, such as Asus, this service may have been renamed to reflect that
NVSystem32 nvscv32.exe X Added by the AGOBOT-NO WORM!
nwiz nwiz.exe N Associated with the newer versions of nVidia graphics cards drivers. Allows you to immensely improve desktop layouts by setting preferences and optimizations. However, this isn't necessary for the operation of your system
Nwpopup Nwpopup.exe Y Broadcast message handler part of Novell Netware that displays server, printer and other messages
nwrecmsg nwrecmsg.exe U Broadcast message handler part of Novell Netware that displays server, printer and other messages - can cause crashes
NWTRAY nwtray.exe Y Novell Netware. Displays the red "N" tray icon which can be disabled (by right-click on the icon) but is also needed by the client
Optimum Online Netsurf.exe X An Optimum Online application that is used to display advertisements.
Osa32 NTOSA32.exe X Added by the ANIG WORM!
piiserviceOE N/A U Spam Inspector (nee Postal Inspector) from The Giant Company or iHateSpam from Sunbelt Software - spam filter add-ons for OE
Pofatch nstrue.exe X Added by the RANDEX.Z WORM!
Premeter nrpr.exe X NetRatings software by Opistat . "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!
Price Patrol neo.exe N Price Patrol by Half.com - internet shopping companion for finding the best on-line prices
QTSvc navchk.exe X Premium rate adult content dialler
RealDownload Express npnzdad.exe X Advertising spyware
Recover N/A N Added during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete
regtmlp N/A ? ??
RTStartMute N/A ? ??
rvde N/A X Related to li-speed****
ScanRegistry nsrvnt.exe X Added by the NERTE TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe
SOFTinst N/A Y For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
Srv RPCrom NClienti386.exe X Added by the WATSOON.A TROJAN!
Symantec Security Addon nvsvc.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
Symantec Security Routine Addon for Microsoft Windows navpxaw32.exe X Added by the AGOBOT-GJ TROJAN!
System Document Application nmod.exe X Added by the SDBOT-ABB WORM!
System File Drivers nvsysvc32.exe X Added by the AGOBOT.WJ WORM!
System Information Manager Navcpe.exe X Added by the SDBOT-QB WORM!
system32 NeT-BoT.exe X Added by the AGOBOT-LJ WORM!
SystemMap32 Netisp32.vbs X Added by the REDIST.C WORM!
SystemNetwork NETSERV.EXE X Added by the NETCONTROL VIRUS!
SystemService navchk.exe X Premium rate adult content dialler
TDockNUndock N/A ? Found on a Toshiba laptop - for use with a docking station?
TheMainStart N/A ? ??
TSService NSSERVICE.EXE ? ??
TWarmBay N/A ? Found on a Toshiba laptop. Related to hotswap bay management?
TWBbtn N/A ? Found on a Toshiba laptop
UTILsInst N/A Y For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
Video Multimedia Driver ndrives32.exe X Added by the RBOT-DK WORM!
Video Process netsvcs.exe X Added by the AGOBOT.LH WORM!
WaveTop Receiver 1 N/A N WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
WaveTop Receiver 2 N/A N WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
WaveTop Upload Manager N/A N WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
Win Patch ntldr.exe X Added by the SDBOT-GS WORM!
Windows Media Powerpoint Helper NSPPTHLP.EXE N German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
Windows NT 32 ntlogin32.exe X Added by the RANDEX.BRD WORM!
Windows NT Login ntlogin32.exe X Added by the SDBOT.WG WORM!
Windows Print Spooler NavAgent32.exe X Added by an unidentified VIRUS, WORM or TROJAN!
Windows Update.exe N/A X Homepage hijacker, see here
Winlogon.exe N/A X CoolWebSearch parasite related - resets home page to an adult material site
WinSig NetXP.exe X Added by the BANKER-FN TROJAN!
winsock2 netsvr.exe X Added by the AGOBOT.LY WORM!
WinSocketComponent nthost.exe X Added by an unidentified VIRUS, WORM or TROJAN!
WMBoot N/A N Associated with Logitech Wingman game controllers. Not required but what does it do?
Wxp4 Norton Update.exe X Added by the ERKEZ.D WORM!
xload32 netdd.exe X Added by the NETSPY TROJAN!
XTNDConnect PC - LtNts4 NtsAgnt.exe U Component of EasySync Pro
ntfsmonitorpro ntfs64.exe X W32/Forbot-EB is a network worm with backdoor Trojan functionality. Located in the Windows system directory.
ntechin n20050308.exe X adware, probably VX2/Look2Me related
Netbios Helper nbthelp.exe X Added by the W32/Codbot-D WORM! This infection is installed as a service which is started even in safe mode. The file is found in the Windows system folder.
Norton Personal Firewall npmsysnt.exe X Added by the W32/Rbot-TY WORM! File is found in the Windows system folder.
Help Temp Files netreg.exe X Added by a network worm with backdoor functionality, W32/Forbot-EJ copies itself to the Windows system folder as netreg.exe and sets registry entries.
Application Window NALWIN32.EXE Y Part of Novell's Zenworks. Found in the C:\Program Files\Novell\ZENworks folder.
Novell Application Launcher nalntsrv.exe Y Part of the Novell client for Windows. Found in the C:\Program Files\Novell\ZENworks folder.
nviload32 nviload32.exe X Added by W32/Sdbot-VT, a WORM/backdoor. The IRC network is used for unauthorized remote access.
Norton Protect npprotect.exe X The WORM/backdoor W32/Rbot-WW will add this to the Windows system folder.
Microsoft Office Nxcxtpr.exe X This is a SDBot variant infection. When run this infection connects to an IRC server, hoeee.routing.vu, and join channel #kloni with password 1q2wxc where it waits for commands from a remote user allowing this remote user to access your computer. It will also remove the administrative shares from your computer so that another infection will not be able to take over your computer as well.
NTSF MICROSOFT SYSTEM ntsf.exe X An Rbot variant. This infection connects to an IRC server where it will await commands from a remote user.
nvidll32 nvidll32.exe X W32/Rbot-XK uses this file to run automatically at logon, providing a backdoor for exploitation by a remote attacker using an IRC channel.
Microsoft Neser Experience nese.exe X Added by an Rbot WORM variant!
supernews12 newsd32.exe X A TROJAN/downloader variant adds the file.
Notmad Manager notmgr.exe U Notmad Manager is used to integrate your Creative Labs Nomad MP3 player into Windows Explorer and other applications.
Norton AntiVirus Auto Protect Service navapsvc.exe Y This service is used by Norton Antivirus to run in the background and detect when any files that are infected with malware are stopped from running. This is an essential service and should not be stopped.
NavLogon NavLogon.dll Y Part of the Norton Antivirus product.
ntsmod ntsmod.exe X Unknown Adware!
dxdll32 ntxdll.exe X Added by the GAOBOT.CPX worm which has keylogging, DOS, and backdoor capabilities.
NAP32 NAP32.exe X Premium rate adult content dialer
NAV Auto Protect navprotect.exe X Added by a variant of the RBOT WORM!
nTune nTune.exe U nVidia nTune - mot
herboard monitoring and overclocking utility for nVidia nForce chipset based motherboards
NVRaidService nvraidservice.exe Y Vidia NVRaid - hard disk striping/mirroring utility for increased performance and reliability. Required if you have a RAID setup
nTrayFw nTrayFw.exe ? System tray icon for the Nvidia Firewall. Is this necessary to run at startup?
Remove me nmzbxdnzjsa.exe X Added by the Troj/Sdbot-SZ TROJAN/IRC backdoor to allow malicious access & control of the computer.
MsCplScan nvsv32.exe X A new service added by the W32/Forbot-DI WORM/IRC backdoor Trojan, with a displayname of nvsv32.exe.
nMTaskBarService nMtsk.exe ? Taskbar control for ISDN NetMod modem. Sorry, I dont know whether or not it is required. Unknown if this is a required item for startup.
FastStart ntnut32.exe X Added by the StartPage.L TROJAN!
win-xp nvsc32.exe X Added by the W32.Bropia.N WORM!
Nsv nsvsvc.exe X Unidentified adware
NETMONW NETMONW.EXE X The Troj/Bdoor-FX TROJAN adds this, then automatically contacts a particular URL in order to download an additional file with further commands.
OfficeScanNT RealTime Scan ntrtscan.exe Y Part of the Trend Micro OfficeScan product. Should not be disabled.
Microsoft Office Nxcao.exe X Added by the W32/Rbot-ZE WORM/IRC backdoor Trojan!
ntddetect ntddetect.exe X Added by the Troj/Agent-CU TROJAN/backdoor!
nsvcin n20050308.exe X adware, probably VX2/Look2Me related
Ner0 Check ner0check.exe X Added by a variant of the RBOT WORM!
Compuware Distributed Analyzer Service NCS.exe Y Added as part of the Compuware DevPartner Studio.
NettGain2000 Verifier NettGain2000 Verifier.exe Y Part of the Starband satellite client that attempts to optimize your satellite connection to increase speed.
WinIgon netlogon.exe X Added by the Backdoor.Armageddon backdoor.
[not used] Notify.exe X Added by Backdoor.Armageddon.B
System Server Manager Ntsrvc.exe X Added by Backdoor.DarkSky.B. This infection listens on ports 5418 and 5419 awaiting commands.
nbsession nbsystem.exe X Added by Backdoor.DTR. This infection listens on port 10001 awaiting remote commands.
Nortan Anti Virus nava32.exe X Added by Backdoor.FTP_Ana.C. This infections listens on TCP port 666.
NTdhcp NTdhcp.exe X Added by the Troj/QQRob-A. It will kill processes and disable services.
arsch nets.exe X Added by the W32/Forbot-EL, it's displayname is "Indexing Provider".
NT Service NTOKSRNL.EXE X Added by the W32/Rbot-AAG WORM/IRC backdoor Trojan.
_Cat1 nmmst.exe X Added by the TROJ_SMALL.SD trojan!
Netropa NHK Server Nhksrv.exe N This program is installed by certain Dell and Compaq computers. It is used to disable any configured hotkeys while the screensaver is running.
Nod32 Free antivirus nod32krn.exe X Added by the W32/Rbot-AAO WORM/IRC backdoor trogan!
NAV_Update NAV_Update.exe X Unidentified WORM or TROJAN!
NAV Auto Updates navupdaters.exe X Added by the W32/RBOT-UN WORM!
MSNPluginSrIvcs n3vasap23.exe X Added by a variant of the WIN32.RBOT WORM!
NAV Auto Updates navupdaterx.exe X Added by a variant of the WIN32.RBOT WORM!
Norton Personal Firewall npfw32.exe X Added by the W32/RBOT-UQ WORM!
MONPluginSrIvcs n3monap23.exe X Added by a variant of the WIN32.RBOT WORM!
FireWire Service nvscv32.exe X Added by a variant of the W32/SDBOT WORM!
Norton Updater NortonUpdate.exe X Added by an unidentified WORM or TROJAN!
XPnet NTXp.exe X Added by the Troj/Banker-AS TROJAN!
Norton Personal Firewall npmsys.exe X Added by the W32/Rbot-ALO trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection also attempts to terminate known AV software so that it remains undetected.
securw Nctrup.exe X Added by the W32/Nopir-B WORM, which will delete all COM and MP3 files from the computer, and disable taskmanager, registry tools, and access to the control panel. It will be found in a Program FilesProjects Visual Studio.NET folder.
notes notes.exe X Added by a variant of the Rbot worm. This worm, when started, connects to IRC servers where it sits in a desginated channel waiting for commands from a remote user.
[not used] Nail.exe X This infection is a Abetterinternet adware variant. It is notoriously difficult to remove and is usually bundled with other malware that are hard to remove as well. One method that we have found that is able to remove this infection and the other malware that are bundled with it is the ewido security suite which you can download and try for free.
Microsoft Update Machine ntce.exe X Added by the W32/Rbot-FA trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
NT Video API32 NTAPI32.exe X Added by the W32/Rbot-FW trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection also attempts to find cd keys for popular games and applications.
Nfpt Microsoft Config nfdtrknm.exe X Added by Rbot variant. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Norton Swap Cleaner nortonswap.exe X Added by the W32/Rbot-MH trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Intelli2k netbug.vbs X Added by the VBS/VBuggy-A networm worm.
Win32 nvc nvcva.exe X Added by the W32/Rbot-ABF. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers.
nvsv32.exe nvsv33.exe X Added by the W32/Forbot-DS network worm. When this infection starts it connects to a remote IRC server where it waits for remote commands to execute.
Norton Personal Firewall npfw.exe X Added by the W32/Rbot-UI worm. This infection also has backdoor capabilities via IRC servers, keystroke logging, and cd key harvesting.
Network Monitoring Service NETMON.EXE X Added by the W32/Codbot-A backdoor.
ujm nm32.exe X Added by the Troj/Iyus-K password stealing trojan. This infection steals usernames and passwords and sends them to the creator. If you have this infection you should change all your passwords. Current incarnations of this infection use the Exploit-CreateTxtRng trojan exploit.
Norton AutoProtect navprot32.exe X Added by the W32/Rbot-UX worm. When connected this infections connects to an IRC server where it waits for remote commands to execute.
NvagNT nvagNT.exe X Added by the W32/Agobot-RV trojan. When started this infection connects to a remote IRC server where it waits for commands to execute. This infection will add entries to your HOSTS file, so the hosts file should be restored after cleaning this infection.
norton norton.exe X Added by the W32/Ahker-D mass-mailing worm.
AVSTRT navpsrvc.exe X Added by the W32/Forbot-EF worm. When started this infection connects to a remote IRC server where it waits for commands to execute. These infections also log keystrokes, so if you are infected you should change all your passwords.
[not used] Navw32.exe X Added by the Troj/Agent-CG backdoor.
Nod3d2 Free antivirus N0D32KRN.EXE X Added by the W32/Rbot-ABQ worm.
[random name] n?lookup.exe X PurityScan/Clickspring adware
nero nrchk.exe X Premium rate adult content dialer
ASDPLUGIN Netherlands.exe X AsdPlug premium rate adult content dialer variant
bpk nvsr32.exe U Blazing Tools Perfect Keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove
microsoft system checkup netapi32.exe X Added by the W32/DONK-E WORM!
microsoft updating navguard.exe X Added by the RBOT.HW WORM!
mojnpluginsrivcs neomonap23.exe X Added by a variant of the W32/SDBOT WORM!
nav auto prot navprot1.exe X Added by the RBOT.ZAC WORM!
navregreminder NavLoad.ini N Corel, HP or ScanSoft registration reminder; not required
netapi32 netapi32.exe X Added by an unidentified TROJAN!
ngpw36 ngpw36.exe X AdBlaster adware variant
nsdcmd services nsdcmdav.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
nsdcmd vid process nsdcmdwin.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
nvcpldaemon NvStartup U Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
nvidia control daemon nksvc32.exe X Added by the W32/AGOBOT-OV WORM!
nvidia remote control panel Nvarem.exe ? NVIDIA graphics card related - what does it do and is it required?
nvirundll nvirundll.exe X Added by the W32.SPYBOT.NPS WORM!
nvsvca32 nvsvca32.exe X Adware - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.is
nvupdater nwiz32.exe X Added by a variant of the WIN32.RBOT WORM!
protection Norton Internet Security.exe X Added by the W32.ELITPER.E WORM!
rsync netsync.exe X Pops-stop.com parasite, a IEPageHelper/SafeSurfing adware variant
windows autostart loader notepad32.exe X Added by a variant of the WIN32.RBOT WORM!
_cat2 nmstt.exe X Added by the TROJ/SMALL-DT downloader TROJAN!
NVCOM NVCOM.exe X Added by the W32/Agobot-SB worm.
NAVSCAN64.EXE /s NAVSCAN64.EXE X Added by the W32/Rbot-T worm. This infection connects to an IRC server where it waits for remote commands.
NAVtask NAVtask.exe X Added by the W32/Rembot-A backdoor/worm. This infection connects to an IRC server and waits for commands to execute.
compaq service drivers navapqwa.exe X Added by a variant of the W32/SDBOT WORM!
ms unix binary Norton2005Update.exe X Added by a variant of the WIN32.RBOT WORM!
autoprotectu navapq32.exe X Added by an unidentified WORM or TROJAN!
ms unix binary Norton2005Update.exe X Added by a variant of the WIN32.RBOT WORM!
nvidia system utility NVSystemUtility.exe U The NVidia_System_Utility lets you adjust bus speeds, hardware voltages, memory controller timings, and fan speed as well as additional settings to increase performance aggressiveness and hardware voltages. Will also display a dynamic graph of CPU and system temperatures, hardware voltages, and memory bus speeds.
firewire services nvcsv32.exe X Added by a variant of the W32.SPYBOT WORM!
Explorer navawp32.exe X Added by the Troj/Ronoper-B backdoor trojan.
Microsoft Network Daemon for Win32 ntd32.exe X Added by the W32/Randex-G worm. When started, this infection connects to an IRC server where it waits for remote commands to execute.
NAVSCAN32.EXE NAVSCAN32.exe X Added by the W32/Sdbot-DO worm. When started, this infection connects to an IRC server where it waits for remote commands to execute.
nldr32 NonYou.exe X Added by the W32/Saros-A P2P worm.
nvpatch napatch.exe X Added by the W32/Sasser-F worm.
windows services NetworkDriver32.exe X Added by an unidentified WORM!
microsoft notepad notepad.exe X Added by a variant of the WIN32.RBOT WORM!
msdn nese.exe X Added by the SDBOT.AHY WORM!
nvidia ntune nTune.exe U nVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards
qtime nrchk.exe X Premium rate adult content dialer
scheduie nrchk.exe X Premium rate adult content dialer
schedulermgr navchk.exe X Premium rate adult material dialer
tsvcin n20050308.EXE X adware, probably VX2/Look2Me related
popuppers newpop63.exe X Popuppers adware variant
nsys nsys.exe U NetSpy keystroke logger/monitoring program - remove unless you installed it yourself!
system23 notPad.exe X Added by the ESTEEMS.D TROJAN!
systemservice nsserver.exe U NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!
Postfix patch ngfqes.exe X Added by the Troj/Sdbot-BX backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
IE Processes nosc32.exe X Added by the W32/SdBot-CN backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Configuration Loader NOTEPADE.EXE X Added by the W32/SdBot-GD worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
[unknown] NTSRVCS.EXE X Added by the W32/SdBot-GJ worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Microsoft System Checkup netlogin32.exe X Added by the W32/SdBot-GN worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
ntvdmd ntvdmd.exe X Adware downloader - also detected as the TROJ/DLOADER-YP TROJAN!
Dll Injection NXCM.EXE X Added by the W32/Sdbot-IT worm. When started this infection connects to an IRC server where it waits for remote commands.
Windows driver update nmsmtp32.exe X Added by the W32/Sdbot-JT worm. When started this infection connects to an IRC server where it waits for remote commands.
Windows Services NetworkDrivers.exe X Added by the W32/Sdbot-YO worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
nvc Win32 nvcvc.exe X Added by the W32/Rbot-ADD worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
windows system nec.exe X Added by the W32/Mytob-L
Windows .Net Manager netsvc.exe X Added by the Troj/Dloader-NY trojan.
nsys32 nsys32.exe X Added by the W32/Agobot-SU worm. When started this infection connects to an IRC server where it waits for remote commands.
Configuration ntsys32.exe X Added by the W32/Sdbot-LH worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Configuration ntsyst32.exe X Added by the W32/Sdbot-LT worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
VxD Driver Initialization ntsvxd.exe X Added by the W32/Sdbot-LW worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Threaded ntsys32.exe X Added by the W32/Sdbot-MR worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft System Checkup NTSYSMGR.EXE X Added by the W32/Sdbot-OC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
NortE Antivirus norten.exe X Added by the W32/Rbot-AFFworm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
NortE Antivirus norte.exe X Added by the W32/Rbot-AFE worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
WINDOWS SYSTEM ninfoie.exe X Added by the W32.Mytob.EE@mm mass-mailing worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Messenger ntsubsys.exe X Added by the WORM_SDBOT.BGE trojan.
nawadll32 nawadll32.exe X Added by the W32/Sdbot-ZI worm. When started, this infection will connect to a remote IRC server and wait for commands to execute.
WinNite niteaim.exe X Added by the W32.Opanki.B backdoor/worm.
nawdll32 nawdll32.exe X Added by the W32/Sdbot-Z worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Network DDE Client netddeclnt.exe X Added by the W32/Codbot-M worm and IRC backdoor trojan.
ntupd32 ntupd32.exe X See_Here
Windows System nibie.exe X Added by the W32.Mytob.FO@mm worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
MS taskbar nts.exe X Added by the W32/Rbot-AGB worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
Microsoft Windows DLL Services Configuration newdll.exe X Added by the W32/Sdbot-ZR worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
NvCplDeamon nvdisp.exe X Added by the Troj/PeepVie-I trojan.
NET Bios Stats ntbstats.exe X Added by the W32/Sdbot-ZX worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Net Functions Library netlib.exe X Added by the Troj/Crater-A backdoor trojan.
Microsoft Windows DLL Services Configuration newdll2.exe X Added by the W32/Sdbot-ABD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
kernal fault check ntosrkl.exe X Added by a variant of the W32/SDBOT WORM!
notes notepaad.exe X Added by the RBOT.BME WORM!
npf value NPFMONTR.exe X Added by a variant of the W32.SPYBOT WORM!
ms unix navupdate64.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft network Networksystem.exe X Added by a variant of the W32/SDBOT WORM!
microsoft xpsp2 Networksystem.exe X Added by a variant of the W32/SDBOT WORM!
NT-Virtual Device Manager ntvdmn.exe X Added by the W32/Sdbot-AAA worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
GLF Network Lan Monitor NPFMNTOR.exe X Added by the W32/Rbot-AGY worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
NITE niteaim.exe X Added by the W32.Opanki.C AIM worm and IRC downloader.
nnmgr nnmgr.exe X Added by the Adware.FFToolBar adware toolbar.
COM Message Transfer Ntmssvcs.dll X Added by the Troj/Dbit-A trojan.
nvjxue nvjxue.exe X Added by the W32/Eyeveg-J worm.
shell32 ntldrt.exe X Added by the W32/Jlok-A Microsoft Word document virus.
Messenger Service nvhost.exe X Added by the W32.Mytob.HM@mm worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
microsoft update 23 NtKernelSystem.exe X Added by a variant of the WIN32.RBOT WORM!
netbios helper nbthlp.exe X Added by the PWS-BANKER.Y password stealing TROJAN!
nt microsoft svcd ntvsvcd.exe X Added by a variant of the WIN32.RBOT WORM!
ntsf microsoft system ntssf.exe X Added by a variant of the WIN32.RBOT WORM!
pcmcia resource monitor nvp2pmon.exe ? NVIDIA nForce P2P Driver - what does it do and is it required?
sheduler nerocheck.exe X Added by the WIN32.TACTSLAY.B TROJAN!
sysclx ntldrt.exe X Added by the W32/Jlok-A
Windows Networks netcog.exe X Added by the W32.Mytob.IA@mm worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
ntmsevt ntmsevt.exe X Added by the Troj/Stoped-B downloading Trojan.
spc_w nzspc.exe N NetZero Search Enhancement related
netmanageimport nmcpdata.exe U NetManage business software related
Windows Xp nortonguard.exe X Added by the W32/Mytob-DZ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Net Functions Monitoring Netmon.exe X Added by the W32/Codbot-R worm and IRC backdoor.
Ehch nbme.exe X PurityScan delivers advertisements to your computer.
NetLogon netlogin.dll X Added by the Backdoor.Fuwudoor backdoor.
ntmssvc ntms.dll X Added by the Backdoor.Fuwudoor backdoor.
NetService ntsvc.exe X Added by the Troj/QQPass-DU password-stealing Trojan.
nwiz32 nwiz32.exe X Added by the Troj/Sinbank-A Troja.
Messenger Protocol netsender.exe X Added by the W32/Sdbot-ACC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
NeroLoader NeroLoader.exe X Added by the Troj/Bancban-EJ password-stealing Trojan of banking websites.
NETINFO netinfo.exe X Added by the W32/Tilebot-J worm.
NVIDIA driver Helper Service nvsvc32.exe Y Part of the display driver for Nvidia cards.
Network Client netclnt.exe X Added by the Trojan.Boxed.A Trojan.
noadware3 NoAdware3.exe U NoAdware Adware/Spyware remover - initially considerered a "rogue" program - see here. Has since apparently mended its ways: see note
helloworld nb32ext3.exe X Added by the MYTOB.JT WORM!
SERV PacK2 nerx.exe X Added by the W32/Sdbot-ACP backdoor and IRC worm.
XmLdrLocation nvrcr32.dll X Added by the Spyware.Eblaster spyware. It also installs a file into %System%rmashlex.dll.
nisvcloc niSvcLoc.exe U Related to National Instruments Corp. LabView
Microsft Update 32 neta.exe X Added by the W32/Rbot-AMI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
nvmsgdwn NVMSGDWN.EXE X Added by the Troj/Graber-D downloader Trojan.
NetDDE Server netddesrv.exe X Added by the W32/Codbot-Y worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
graphic loader ntvdm32.exe X Added by a variant of the WIN32.RBOT WORM!
microsof value nmatt.exe X Added by a variant of the WIN32.RBOT WORM!
windows update 64 nbupd64.exe X Added by a variant of the W32/FORBOT WORM!
Windows System Configuration nether.exe X Added by the W32/Opanki-AB worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Bron-Spizaetus norBtok.exe X Added by the W32.Rontokbro.B@mm mass-mailing worm.
Microsoft Update 32 network.exe X Added by the W32/Rbot-AQE worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
ntcommlib3 NTCommLib3.exe X Admess adware variant
rnaomflt naomf.exe U Naomi internet filtering software
NetBIOS Helper nbthlp.exe X Added by the W32.Toxbot.AL worm and IRC backdoor.
Microsoft Update 32 network.exe X Added by the W32/Rbot-ARZ worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
nbustrce1d nbustrce1D.exe ? Device driver, possibly CD-ROM/DVD-ROM related - what exactly is it and is it required in startup?
NTAuth ntsvc.ocx X Added by the Troj/Taladra-F backdoor Trojan.
nnqcouu nnqcouu.exe X The Abi Network adware
NetworkKey netkey.exe X Added by the Troj/IRCBot-AJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
irfk NITEAIM.EXE X Added by the W32/Sdbot-AEJ worm and IRC backdoor.
norten Software Intrenet norten.pif X Added by the W32/Rbot-AWA worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
nwprovau nwprovau.dll Y Client Service for NetWare
AdobeReaderPro ntkernell32.exe X Added by the W32/Rbot-ATY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
operations typhoon rising registration NOVG.EXE N Joint_Operations registration reminder
NAMEDPIPE SYSTEM namedpipe.exe X Added by the W32/Mytob-FH worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Nero Checker nerocheck.exe X Added by the Troj/Proxy-X Trojan.
Compaq Service Drivers ntdat32.exe X Added by the W32/Sdbot-CNW worm. When started, this infection connects to a remote IRC server where it waits for commands to execute
NetFxUpdate_v1.1.4322 netfxupdate.exe ? Part of the Microsoft .Net Framework. Unsure if its required to run.
NLS Monitor nlsmon.exe X Added by the W32/Rbot-AXJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Nvidia Graphic Displacement nvideogui.exe X Added by the W32/Sdbot.worm.gen.w!64512 worm and IRC backdoor. This infection will also create a new service in order to load the rootkit file c:\windows\REMON.SYS.
nvctrl.exe nvctrl.exe X Added by the Troj/Zlob-BC downloader Trojan. This infection installs the following files:

mscornet.exe (detected as Troj/Zlob-BC)
mssearch.exe (detected as Troj/Zlob-BC)
ld????.tmp (detected as Troj/Zlob-BC)
ncompat.tlb (may be safely deleted)
msvol.tlb (may be safely deleted)
hp????.tmp (may be safely deleted) where ??? are random characters.
Microsoft PCHealth32 NDDENB.exe X Added by the Troj/PWSYahoo-A password-stealing Trojan for the Yahoo Messaging Service.
netconf32 netconf32.exe X Added by the W32/Tilebot-BN worm and IRC backdoor.
Norton Antivirus nortonav.exe X Added by the W32/Rbot-AYE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
MSN Service Utilities nkn.exe X Added by the W32/Kelvir-BC MSN Messenger worm.
nvsvc nvsvc.exe X Added by the Troj/Banker-HQ Trojan.
nVidia Drivers nVidiaDrvers.exe X Added by the W32/Sdbot-AFX worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
nuclabdll nuclabdll.dll X Identified as Trojan.PWS.Egold.
netmeter NielsenOnline.exe X This is software that monitors your Internet usage and offers surveys that are based on users online habits. The data that is monitored is supposedly reported anonymously. Though this software is not considered malware or malicious, since this software can be bundled with adware and performs constant monitoring of your activity, it is the site's opinion that you disable it.
NetSendServer NetSend.exe X Added by the Troj/Hupigon-DQ backdoor Trojan.
Internet Services Netsvc.exe X Added by the WORM_MYTOB.NH worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
NPF Value NPFMONTR32.exe X Added by the W32/Rbot-BBC worm and IRC backdoor.
Microsoft Update ntsf.exe X Added by the W32/Rbot-BBP worm and IRC backdoor.
GoOutside nakedx.exe X Added by the W32/Sdbot-AGK worm and IRC backdoor.
Network DRV netdrvr.exe X Added by the W32/Tilebot-CO worm and IRC backdoor.
Ntsysv ntsysv.exe X Added by the Troj/Mifeng-E Trojan.
PixelModule nvidcgui.exe X Added by the W32/Tilebot-GS worm and IRC backdoor. This infection also installs the rootkit file remon.sys.
System nav32.exe X Added by the W32/Rbot-BHV worm and IRC backdoor.
NetSTrSvc netsvcs.sys X Added by the Troj/HacDef-AM rootkit.
Nevwoek conectin Nevwoek.exe X Added by the Troj/GrayBrd-V Trojan.
NIW NIW.exe X Added by the Troj/Lewor-U Trojan.
{C1A2FDA2-1A5B-2A8F-F3A2-B22DA1A3C41D} netwrap.dll X Added by a rogue antispyware program who's affiliates install files that replaces the Windows wallpaper with a fake virus alert message and issues fake virus alerts.
nwisse nwisse.exe X Added by the Troj/Fusion-B keylogging backdoor Trojan.
Windows Internet Server ntdlr.exe X Added by the Troj/Feutel-CH Trojan. This infection also creates the files C:\Windows\ntdlr.dll and C:\Windows\ntdlr_Hook.DLL.
NetBIOS Protection netpt.sys X Identified as not-a-virus:Monitor.Win32.NetMon.a by Kapersky.
[Various Names] newbreed.exe X Part of the Wareout infection as described here.
[Various Names] NsCplTray.exe X Part of the Wareout infection as described here.
[Various Names] new32.exe X Part of the Wareout infection as described here.
[Various Names] NSYSCPLSTR.exe X Part of the Wareout infection as described here.
[Various Names] NopeZ.exe X Part of the Wareout infection as described here.
[Various Names] nmdllw.exe X Part of the Wareout infection as described here.
[Various Names] NukeSpan.exe X Part of the Wareout infection as described here.
Microsoft CSRSS Service nsmscrs.exe X Added by the W32/Rbot-BPT worm and IRC backdoor.
bgmonitor_{79662e04-7c6c-4d9f-84c7-88d8a56b10aa} NMBgMonitor.exe U Related to Nero_Home
compaq services drivers ndt32.exe X Added by the RBOT.CQZ
Ya Salam NancyAjram.exe X Added by the W32.Jalabed@mm mass-mailing worm.
NTSF MICROSOFT SYSTEM ntsfd.exe X Added by the W32/Rbot-BAP worm and IRC backdoor.
nvidGUIv2 nvidGUIv.exe X Added by the W32/Tilebot-DK worm and IRC backdoor. This infection will also create a new service in order to load the rootkit file c:\windows\REMON.SYS.
Kernel Fault Check ntvbm.exe X Added by the W32/Rbot-CKP worm and IRC backdoor.
[not used] netsrv16.dll X Added by the Troj/Riler-O backdoor Trojan.
SynUSB Manager netsrv16.dll X Added by the Troj/Riler-O backdoor Trojan.
noadware4 NoAdware4.exe U NoAdware Adware/Spyware remover - initially considerered a "rogue" program - see here . Has since apparently mended its ways: see note
ntxp2 ntxp2.exe X Added by the Troj/VB-API Trojan.
Access Protocol nixfver.exe X Added by the BKDR_PPDOOR.AS backdoor.
newname newname2.exe X Added by the Troj/Drsmartl-V Trojan.
newname newname2.exe X Added by the Troj/Drsmartl-V Trojan.
newname newname4.exe X Added by the Troj/Drsmartl-V Trojan.
stubpath nerodll.exe X Added by the Troj/Bifrose-HY Trojan.
Microsoft Name Server nssrv.exe X Added by the W32/Tilebot-EK worm and IRC backdoor. This infection utilizes the rootkit rofl.sys.
Windows Log nvsvcd.exe X Added by the Troj/Polbot-D backdoor Trojan.
Network Trafic Monitoring nmntrng.exe X Added by the W32/Nanpy-O worm.
NetBTD(ntbtd) netbtd.exe X Added by the W32/Sdbot-BLW worm and IRC backdoor.
Notification Utility notify.exe X Added by the Trojan.Muvipaz Trojan.
[not used] ntndis.exe X Added by the W32/Rbot-DPG worm and IRC backdoor.
NK45 file system driver nkcfg.sys X Added by the TSPY_HAXSPY.AD rootkit.
nkunpack nkunpack.dll X Added by the TSPY_HAXSPY.AD Trojan. This infection utilizes the nkcfg.sys rootkit in order to hide its components.
boby netburn.scr X Added by the Troj/Bancban-OX banking Trojan. If you are infected with this Trojan it is advised that you immediately change all the passwords for your online banking accounts.
nvcpll nvcpll.exe X Added by the Troj/Bancban-PF password-stealing Trojan for online banks. If you are infected with this Trojan you should immediately change all your online banking information.
NOD AV service nodantivir.sys X Added by a variant of the Troj/Haxdor-Gen rootkit.
nnll nnll.exe U Net Nanny internet filter
scanner file utility NsCatCom.exe Y Kycocera network copier/printer/scanner process to dump scanned documents onto a workstation.
svtcin n20050308.a.Stub.EXE X Added by Trojan.N20050308.Process TROJAN! Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
win32.trojan.downloader netstat2.exe X Added by the Trojan.RealSearch TROJAN! Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
<not used> NETLIB32.DLL X Added by the Troj/Oscor-G backdoor Trojan.
[not used] nmst.exe U Added by the Spyware.NetMama surveillance software. This program should be uninstalled if it was not installed by yourself.
[Unknown] nclaby.sys X A variant of the Haxdoor rootkit.
nclabydll nclabydll.dll X Added by a variant of the Haxdoor Trojan. This infection utilizes the nclaby.sys rootkit.
<Unknown> nuclab.sys X Added by a variant of the Goldun.Fam rootkit.
nuclabdll nuclabdll.dll X Added by a variant of the Goldun.Fam Trojan. This infection utilizes the nuclab.sys rootkit.
gdwxp3 nuclabdll.dll X Added by a variant of the Goldun.Fam Trojan.
Novell WebClient Service nvicli.exe X Added by the Troj/Bckdr-LEM backdoor Trojan.
FASTTRACKNETVISION NETVISION.exe X Added by the Dial/DialCar-Z premium rate dialer..
Microsoft (R) Windows Vista/NT Runtime Compatibility Service nrcs.exe X Added by the Backdoor.Ranky.X backdoor Trojan. This infection also creates a Windows service using the same name and filename.
{29123221-3AF8-488c-85DE-6B3EC59E8074} netmedia.exe X Added by the Adware.NetMedia adware. Adware.NetMedia is a security risk that displays advertisements while a user browses the Internet.
NSpackk nSpackk.exe X Added by the Troj/Bancos-AVO Trojan. This Trojan attempts to steal banking information.
Microsoft Net API ntps.exe X Added by the W32/Tilebot-HA worm and IRC backdoor.
ntq ntq.exe X Added by the W32/Stration-AC worm.
Remote Protection File System NewName.BAT X Added by the W32/WinLose-A worm.
Microsoft Update ntservice.exe X Added by the Troj/Agent-DIS Trojan.
netchecker netcheck.exe X Added by the Troj/Daemoni-AP Trojan.
Microsoft Windows Internet Connections Manager net32b.exe X Added by the W32/Cuebot-N worm and IRC backdoor.

W32/Cuebot-N can spread to computers vulnerable to the Server Service exploit.

The following patch for the operating system vulnerability exploited by W32/Cuebot-N can be obtained from the Microsoft website:

MS06-040
.NET Runtime Optimization Service NETServ.exe X Added by the W32/Sdbot-CSA worm and IRC backdoor.

W32/Sdbot-CSA spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: SRVSVC (MS06-040), RPC-DCOM (MS04-012), WKS (MS03-049) (CAN-2003-0812) and ASN.1 (MS04-007).
NetMeeting Remote Desktop Agent Nwsapagent.dll X Added by the Trojan.Linkmediac Trojan.

Trojan.Linkmediac is a Trojan horse that displays popup advertisements and sends information about the compromised computer to a specific Web site.
Renova Nova.exe X Added by the W32/Levona-A worm. W32/Levona-A spreads to network shares and removable drives.
RPCall_REPCLIENT numlock.exe X Added by the Troj/Hasik-A Trojan.
Nas nas.exe X Added by the Adware.ClearX adware program. Adware.ClearX is a program that attempts to modify settings in Internet Explorer. It redirects both the home page and search page.
NTFS File Location Service ntfsloc.exe X Added by the W32/Sdbot-CSG worm and IRC backdoor. W32/Sdbot-CSG spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: SRVSVC (MS06-040), RPC-DCOM (MS04-012), WKS (MS03-049) (CAN-2003-0812), and ASN.1 (MS04-007). The worm may also spreads via network shares protected by weak passwords.
NdisFilter ndisfilter.sys X Added by the Troj/NetAtk-F rootkit.
nDaemon ndaemon.exe Y Unsupported and discontinued News server for windows by Alt-N.
{F3D0D422-CE6D-47B3-9CE6-C54DD63F1ADB} new123.sys X Added by the Troj/QQPass-AIT Trojan.
NvVideoCenter NvVid.exe X Added by the W32.Ovagur virus. W32.Ovagur is a virus that infects .exe files in removable disks and network mapped drives.
NvVideoCenter NvVid.sys X Added by the W32.Ovagur virus. This file acts a rootkit to hide the rest of the infection's files.
nmapp nmapp.exe N This is the main executable for Network Magic. Network magic helps home network users quickly solve network related problems as well as configure network related services.
Network Magic nmsrvc.exe U Part of Network Magic. Network magic helps home network users quickly solve network related problems as well as configure network related services.
Pure Networks Network Magic Service nmsrvc.exe U Part of Network Magic. Network magic helps home network users quickly solve network related problems as well as configure network related services.
Pure Networks Net2Go Service nmraapache.exe U Part of Network Magic's Net2Go service.

"Net2Go service gives users remote access to the shared files on all PCs in their home from any web browser, no matter where they are. Users get an encrypted password and can also upload to their home networks. In addition, users can remotely view the online status of all the PCs in their home network. With its dynamic DNS service, Net2Go also acts as a personal home web server. It provides a fast and easy way to share photos and files with friends and family via a personal web site without having to upload to a 3rd party website or constantly e-mailing them. Users can view the photos individually as thumbnails or as a slideshow and can download source files for easy printing."
C:\Program Files\NetMeter\NetMeter.exe NetMeter.exe N Added by the NetMeter bandwidth meter.

"NetMeter is a small, customizable network bandwidth monitoring program for Windows 95/98/98SE/ME/NT4/2000/XP. NetMeter is and will always stay freeware. The program has been tested extensively on Windows 2000 and XP, but it should work just as well on all other Win32 operating systems."
nservice nservice.exe X Added by the W32/Agobot-AHR worm and IRC backdoor.
NetService NetService.exe X Added by the W32/Silly-F worm.
ninsvc ninsvc.exe X Added by the W32/Akbot-AL worm and backdoor.
hdlpscom netilxgn.exe X Added by the W32/Rbot-FXD worm and IRC backdoor. W32/Rbot-FXD may spread using a variety of techniques including exploiting weak passwords on computers and SQL servers, exploiting operating system vulnerabilities (including RPC-DCOM, LSASS, WKS and ASN.1) and using backdoors opened by other worms or Trojans.
Nord NORDSYS.EXE X Added by the WORM_NUWAR.PO worm.
Network Performance Alerts netlog32.exe X Added by the W32/Mofei-T worm and backdoor. W32/Mofei-T may attempt to spread via network shares protected by weak passwords.
Windows Server Management Service netsvc.exe X Added by the W32/Tilebot-IF worm and IRC backdoor.
www.ppandora.com nsvc.exe X Added by the Troj/DDos-P flooding Trojan.
Windows Netlib Service netlib32.exe X Added by the W32/Tilebot-IG worm and IRC backdoor.
Net Service Monitor netsvc.exe X Added by the W32/Rbot-FZD worm.
www.ppandora.com nsvc32.exe X Added by the Trojan.Panddos Trojan. Trojan.Panddos is a Trojan horse that performs Denial of Service attacks.
Microsoft Internet new.exe X Added by the Troj/Banker-DSL Trojan.
Windows Logon Service napi32.exe X Added by the W32.Spybot.ANDM worm. W32.Spybot.ANDM is a worm that spreads through mIRC and to network shares protected by weak passwords. It also spreads by exploiting system vulnerabilities.
NTFS Crypto Technology ntfscrypt.exe X Added by the W32/Spybot-NC worm and IRC backdoor.
Media Sariel Number Services notaped.exe X Added by the Troj/DwnLdr-FYA Trojan.
{fa19bd7e-50bc-4203-80ac-c4edc81ca9a3} nbbrhbd.dll X A Trojan used by the rogue anti-spyware program AntiVermins. This Trojan, when installed, will display fake security alerts on your taskbar and install the AntiVermins program on your computer. This infection also loads under the hirtellous value in the ShellServiceObjectDelayLoad registry key.
svcshare nvscv32.exe X Added by the W32/Fujacks-J prepending virus. W32/Fujacks-J searches for files with HTML and ASP extensions and append code to them. These files are detected as Troj/Fujif-A.
Network Bridge netadp.exe X Added by the W32/IRCBot-TO worm.
Windows Server Management Services navsvc.exe X Added by the W32/Rbot-GCH worm and IRC backdoor.
nvscv32 ncscv32.exe X Added by the W32/Fujacks-L backdoor virus.
NetGroup Packet Filter Driver npf.sys Y Part of the WinPcap packet capture library. This file can be installed by malware but is not considered harmful to your computer.
!!!! new_drv.sys X Added by the Troj/NTRootK-BE rootkit Trojan.
NJIL njil.exe X Added by the Troj/Delf-ELF Trojan.
Internet nteusodp.exe X Added by the W32/Rbot-GFJ worm and IRC backdoor. W32/Rbot-GFJ spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: RPC-DCOM (MS04-012), ASN.1 (MS04-007) and Symantec (SYM06-010).
Windows Server Management Services navapsvc.exe X Added by the Troj/Rbot-GGW worm and IRC backdoor.
Norton Antiviral Scanner navscnr.exe X Added by the W32/Delbot-K worm and IRC backdoor.
<not used> nv4_icm3.dll X Added by the W32/Stration@MM mass-mailing worm.
ntiMUI ntiMUI.exe ? Related to NTI CD & DVD Maker 7.
NPROTECT NPROTECT.exe X Added by the Trojan.Syginre Trojan. Trojan.Syginre is a Trojan horse that disables the Windows Firewall and may delete some files from the compromised computer.
Netbeans netbeans.exe X Added by the W32/Delbot-R worm and IRC backdoor. W32/Delbot-R spreads to other network computers by scanning network shares for weak passwords and by exploiting common buffer overflow vulnerabilities, including Symantec (SYM06-010).
Norton Antivirus Updater nortonav.exe X Added by the W32/Delbot-T worm and IRC backdoor. W32/Delbot-T spreads to other network computers by scanning network shares for weak passwords and by exploiting common buffer overflow vulnerabilities, including Symantec (SYM06-010).
Wkyo86 Nitip.exe X Added by the W32/Pitin-A networm worm.
Windows Media Upgrade NeUpgrade.exe X Identified as Backdoor.Win32.Rbot.bmf. This infection is a worm and IRC backdoor.
Server Network Debug NetDebug.exe X Added by the W32/VB-DOS worm.
userinit ntos.exe X Added by the Troj/Dloadr-AWJ downloader Trojan.
NOFIIN.EXE NOFIIN.EXE X Added by the Troj/Haxdoor-DP Trojan.
Netintelligence Home Edition Web Filter NINDFltr.exe Y Added by the Netintelligence parental controls product.
KSD2Service notaped.exe X Added by the Troj/DownLd-ABB Trojan.
{A6011F8F-A7F8-49AA-9ADA-49127D43138F} NewInfo.dll X Added by the Troj/QQPass-AOL Trojan.
nortonp nortonp.exe X Added by the Troj/JD-A password-stealing Trojan.
nvidia: nvidia.exe X Added by the W32.Kueight worm. W32.Kueight is a worm that spreads by copying itself to removable drives and downloads other malicious files on to the compromised computer.
NVIDIA Display Driver Service nvsvc32.exe Y Part of the display driver for Nvidia cards.
ForceWare Intelligent Application Manager nSvcAppFlt.exe Y Related to the NVIDIA firewall used on certain motherboards that have the NVIDIA forceware chipset.
Forceware Web Interface nSvcAppFlt.exe U Web interface for configuring and managing the NVIDIA firewall used on certain motherboards. Not needed if you do not use this Firewall.
ForceWare IP service nSvcIp.exe U Related to the NVIDIA Firewall used on certain motherboards with nForce chipsets. Not needed if you do not use this Firewall.
ForceWare user log service nSvcLog.exe U Related to the NVIDIA Firewall used on certain motherboards with nForce chipsets. Not needed if you do not use this Firewall.
Norton Unerase Protection NPROTECT.EXE Y Related to Symantec's file protection program. This program allows you to restore deleted files at a later date.
Speed Disk service NOPDB.EXE Y Disk defragmenter bundled with Norton System Works.
NeroHomeFirstStart NMFirstStart.exe U A media indexing program installed with Nero products. More information about it can be found here.
Chckup Netverchk.exe X Identified by AntiVir as TR/Dldr.Age.66267.A.
Input and output operations ntio256.sys X Added by the Troj/Bckdr-QHO Trojan.
Microsoft Svchost local services nzm23.exe X Added by the W32/Rbot-GMC worm and IRC backdoor.
Notepad ntoepad.exe X Added by the W32/Delbot-AK worm and IRC backdoor.
Microsoft Installshield nundll32.exe X Added by the W32/Agobot-AHZ worm and IRC backdoor.
Netman Netserv.dll X Added by the Troj/Protux-E Trojan.
{30EBEA2E-8618-979F-0807-050701070107} ntdvll.exe X Added by the Troj/Poison-J keylogging Trojan.
Nod23 Service nod23.exe X Added by the W32/Rbot-GMK worm and IRC backdoor.
Msn Messenger nkbf.exe X Added by the W32/Rbot-GMQ worm and IRC backdoor.
Network System NetSystem.exe X Added by the Troj/QQRob-ADE password-stealing Trojan.
vtmesys netlprto.exe X Added by the W32/Rbot-GNA worm and IRC backdoor.
Microsoft netsrv.exe X Added by the W32/Rbot-GOS worm and IRC backdoor.
{DEC39E0E-F1F2-41E5-80B8-592A67AB0AA5} NewInfo.rxk X Added by the Troj/QQPass-AOQ Trojan.
WindowsUpdate Nzil.exe X Added by the W32/Culler-C worm that spreads via MSN Messenger.
SystemUpdate Negdo.exe X Added by the W32/Culler-C worm that spreads via MSN Messenger.
RunDll.exe navupdt2.exe X Added by the Troj/Banloa-BJN downloading Trojan.
4684735485910 netdll32.exe X Added by the W32/Sdbot-DEV worm.
Java Update nod.exe X IRCBot variant.
NAVENG naveng.sys Y Driver used by Symantec Antivirus.
NAVEX15 navex15.sys Y Driver related to the virus definitions of Symantec Antivirus.
TCP/IP Network Throttle netthrot.exe X Added by the W32/Tilebot-JO worm and IRC backdoor.
numlock.vbs numlock.vbs U Code example from Microsoft that allows you set the state of the Number Lock key on your keyboard when Windows starts. This startup uses no resources as it runs once and then unloads.
NapsterShell napster.exe N Windows system tray icon for the music download service, Napster.
Driver nso12k.sys X Added by the Troj/Knockit-A backdoor Trojan.
Nex nex.exe X Added by the Troj/Agent-FPQ Trojan.
Microsoft netfix32.exe X A variant of the RBot family of worms and IRC backdoor Trojans.
Nvidia Driver Help nvsvc32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
NVIDIA Compatible Windows Miniport Driver nvmini.sys X Added by the PE_CORELINK.C-O rootkit.
MagicSet.exe nkruls.exe X Added by the W32.Slurk.A worm. This infection will also configure itself as debuggers for many other security related programs.
netupdate32 netupdate32.exe X Added by the worm and IRC backdoor.
EYORE Notepad.scr X Added by the W32/Gimlet-A worm.
{0EA66AD2-CF26-2E23-532B-B292E22F3266} NewTemp.dll X Added by the Troj/QQPass-AOU password-stealing Trojan.
{5FF01121-F04D-30cf-64CD-74FF5FE1CF1C} nwizdh.exe X Added by the Troj/OnLineG-A Trojan.
netsup netsup.dll X Identified as the Adware.Agent Trojan.
sittachasnahalbasya ntoskernel.exe X Added by the W32/Hansah-A worm.
Network Security NSecurity.exe X Added by the Troj/IRCBot-WN IRC backdoor Trojan.
ntldr.sys ntldr.sys X Added by the Troj/SpamToo-AQ Trojan.
Microsoft Internet novo.exe X Identified by Panda Antivirus as Trj/Banker.HYW. If you are infected with this file then you should immediately change your online banking passwords and notify your banks.
{076200C7-8302-FDAA-0404-070602000300} nvfw96.exe X Added by the Troj/Agent-FWO Trojan.
NotebookHardwareControl nhc.exe U Added by the Notebook Hardware Control hardware management software for various notebooks.
novsvida.exe novsvida.exe X Identified by Panda antivirus as the Trj/Agent.FOB Trojan.
<not used> NTDLL32.dll X Unidentified malware.
Microsoft Autorun1 nwizdh.exe X Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on to the compromised computer.
Microsoft Autorun7 nwiztlbu.exe X Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on to the compromised computer.
Microsoft Autorun12 nwizzhuxians.exe X Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on to the compromised computer.
Microsoft Autorun13 nwizwlwzs.exe X Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on to the compromised computer.
Microsoft Autorun20 nwizfy.exe X Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on to the compromised computer.
Microsoft Autorun3 nwizhx2.exe X Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on to the compromised computer.
Microsoft Autorun10 nwizwmgjs.exe X Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on to the compromised computer.
Network Location Awareness Network.exe X Added by the Troj/Dloadr-BBE Trojan.
UPSI_1.exe New_Folder(1).exe X Added by the W32/SillyFD-C worm that spreads to removeable storage devices.
Shell2 New_Folder(1).exe X Added by the W32/SillyFD-C worm that spreads to removeable storage devices.
nMtskBar Service nMtsk.exe ? Taskbar control for ISDN NetMod modem. Sorry, I dont know whether or not it is required. Unknown if this is a required item for startup.
Windows Services Ts nwdpqqoiwm.exe X Added by the W32/Rbot-GRV worm and IRC backdoor.
Microsoft Nvpss.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
OfficeScanNT RealTime Scan ntrtscan.exe Y Real time scanner for Trend Micro's OfficeScan security suite.
{94524218-9af3-4643-9687-cbc2880e54da} nuqjici.dll X Zlob Trojan that installs VirusProtectPro 3.3 and shows fake security alerts from your Windows taskbar.
Network Password Manager npmsvc.exe U Added by the Network Password Manager password management system.
Nod32 Service nod32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Nod32 Service nod64.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Vista Updater System nvcsc23.exe X A variant of the IRCBot family of worms and IRC backdoor Trojan
Microsoft (R) Windows Network Latency Controller nlc.exe X Added by the Backdoor.Ranky backdoor Trojan. This infection also installs a Windows service of the same name and filename.
Microsoft (R) Windows Network Security Management Service nsms.exe X Added by the Backdoor.Ranky backdoor Trojan.
NTVDM ntvdm.exe X Added by the W32/Sdbot-DFQ worm and IRC backdoor. This infection should not be confused with the legitimate C:\Windows\System32\ntvdm.exe file.
NiroFile Updated NiroFile.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
ScanReg NPFMONTR.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
navapsvc navapsvc.exe X A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Windows Desktop Multimedia ntkrnl.exe X Unknown malware.
Win Net Wks32 netwks32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows NZDB Service nzbd.exe X Added by the W32/Sdbot-DGJ worm and IRC backdoor.
printers notiffy.dll X Added by the W32.Mubla.B worm.
NAVWatch NAVWatcher.exe X Identified by Sunbelt Software as a variant of the VX2.Transponder Trojan.
TA_Start nqdsregp.exe X Added by a variant of the Zenosearch adware. Adware.ZenoSearch is an adware that displays pop-up ads based on searches the user performs on popular web search engines.
NvCCCpl NvCCCpl.exe X Added by the Troj/Nogata-A backdoor Trojan.
Net Command Senter nvscvse.exe X Identified as a variant of the Backdoor.Win32.Agent.aox backdoor.
modems notice.dll X A variant of the IRCBot family of worms and IRC backdoor Trojans.
tpfnf2 notifyf2.dll ? Installed with IBM Thinkpad and Lenovo laptops.
Windows noper.exe X Unknown malware.
Rsystem nod32kul.exe X Unknown malware.
Remote Help Session Manager ntsokele.exe X Added by the W32/Fujacks-AP worm.
{eb86b46a-d6db-4478-8f5f-06cb2ebc1b35} nexpegp.dll X Zlob Trojan that installs VirusProtectPro 3.6 and shows fake security alerts from your Windows taskbar.
DDMP netservice.exe X Added by the Troj/Delf-EXQ Trojan.
startkey navsys.exe X Identified as a variant of the Backdoor.Bifrose malware.
SystemX nzm.exe X A variant of the RBot family of worms and IRC backdoor Trojans.
<not used> ntsvc32.dll X Identified as the Trojan-Notifier.Win32.Small.i malware.
prodigy1 newsystem25.dll X Added by the W32/IRCBot-XL worm and IRC backdoor.
NeroFilterCheck NeroChek.exe X Added by the TSPY_AGENT.AAVG spyware Trojan.
Network Source Engine nsecvc.exe X Identified by Bitdefender as Trojan.Peed.Gen.
ActiveScript32 nod.exe X Added by the W32/Sohana-AJ worm.
Microsoft Internel Corporat netvhost.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft NT Drivers ntdrv.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Nvidia Video nvidia.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
NVidia TLayer gateway A2 nvmapi.sys X Added by a variant of the Goldun.Fam rootkit.
RunNarrator Narrator.exe U Microsoft's Narrator program which is an accessibility program that reads the text on your screen to you via your speakers.
NET protection system netst.exe X Identified as the Backdoor.Rizo.A malware.
Microsoft Agent nsch0st.exe X Identified as a variant of the Win32/Duiskbot.AG malware.
Microsoft netshield.exe X Identified as the Backdoor.Win32.Agent.aqb malware.
Network System Logon netmsvc.exe X A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
PPA Virtial rendering nvsystl3.sys X Added by a variant of the Goldun.Fam rootkit.
nvsystl0 nvsystl0.dll X Added by a variant of the Goldun.Fam Trojan. This infection utilizes the nvsystl3.sys rootkit to hide itself.
Oddysee ntoskrnl.exe:kernel X Added by the W32.Focelto.A rootkit. This rootkit is a Alternate Data Stream file which requires certain tools to remove it. The ntoskrnl.exe it is attached to is a legitimate Microsoft file and should not be removed.
NOTEPAD NOTEPAD.exe X Added by the W32/Sdbot-DHU worm and IRC backdoor.
Network ODBC NetODBC.exe X Added by the W32.Snaban worm. W32.Snaban is a worm that spreads by copying itself to removable drives and network drives on the compromised computer. It also steals confidential information by logging keystrokes.
Network Translation System Service ntss.exe X Added by the Backdoor.Unpdoor backdoor Trojan. Backdoor.Unpdoor is a Trojan horse that opens a random port and connects to a remote Web site.
Microsoft Network Service netsvc.exe X A variant of the Backdoor.Win32.Rbot.eac family of worms and IRC backdoor Trojans.
Nod29 Service nodwr.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Norton GProtect ngrfn.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Win32 Notepad Services notepad32.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Yahoo! Messengger neo32.exe X Added by the W32/Sohana-AK removable media worm.
Windows Automatic Updater ntapi.exe X Added by the W32/Rbot-GTT worm and IRC backdoor.
Nakido nakido.exe U Added by the Nakido file sharing software. This software allows you to share files with other people on the Nakido network.
Microsoft Update nbdos.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
test netservice.exe X Added by the Troj/Bckdr-QJQ backdoor Trojan.
Network Security XP nvsvc86.exe X Added by the W32/Rbot-GUI worm and IRC backdoor.
NBService NBService.exe U Service used to run backups using Nero BackItUp.
nVidia Display Driver nvsvc64.exe X Added by the W32/IRCBot-YK worm and IRC backdoor.
benzaldoxime nczupfw.dll X Added by a Zlob Trojan which installs AntiVirgear 3.8 and display fake security alerts in your Windows taskbar.
Windows NB Service nbsrv.exe X Added by the W32/Tilebot-KK worm and IRC backdoor.
NeroFil NeroFil.EXE X A variant of the IRCBot family of worms and IRC backdoor Trojans.
NiroFilter Updated NiroFilter.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Network Security Monitor nsmon.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Nod32 Service n0m.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Nod3g2 Service nod6dr4.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Nokia Check nokiacheck.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
nton.exe nton.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
NMIndexingService NMIndexingService.exe U Service used by Ahead Nero to index the media files on your computer into an internal database. This index can then be used to quickly find your media.
NvCCpl NvCCpl.exe X Added by the W32/Chilin-A worm.
NdisWon NdisWon.sys X Identified as a variant of the Ascesso rootkit.
Microsoft Update Machine nlczty.exe X Added by the W32/Rbot-GUR worm and IRC backdoor.
noskrnl noskrnl.exe X Added by the Trojan.Peacomm.D Trojan. Trojan.Peacomm.D is a Trojan horse that gathers system information and email addresses from the compromised computer.
noskrnl noskrnl.sys X Added by the Trojan.Peacomm.D rootkit. Trojan.Peacomm.D is a Trojan horse that gathers system information and email addresses from the compromised computer.
ComService Netlogon.vbs X Added by the VBS/Edibara@M virus.
Paradyne ADSL Network Driver V2.3 netcfgx32.exe X Added by the Troj/Delf-EYS Trojan.
neobus neobus.dll X Added by a variant of the MyGeek/CPVFeed adware.
Nt System Protocol ntsystem.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
NTSpool NTSpool.exe X Identified as a variant of the Backdoor.Bifrose backdoor.
Nod32 Service NZ.exe X Added by the Troj/Rbot-GUK worm and IRC backdoor.
System Manager ncvs32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows File System Frame ntframe.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
NamedSvc named.exe X Identified by Kaspersky Antivirus as Backdoor.Win32.IRCBot.anp.
nopctrl nopctrl.dll X Added by a variant of the MyGeek/CPVFeed adware.
NcpBudget ncpbudgt.exe Y Related to the FEC Secure IPSec VPN client.
SystemSv12 newmaxxsv234.exe X Added by the Troj/Tibs-TS Trojan.
ntosnh.sys ntosnh.sys X Added by the Troj/Dload-Z Trojan.
ntoss.sys ntoss.sys X Added by the Troj/Dload-Z Trojan.
caribi ncrjf.dll X Zlob Trojan which installs the VirusProtect 3.8 rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install VirusProtect onto your computer without permissions. This Trojan pretends to be a fake video codec required to watch videos online.
(default) ne.exe X Added by the Troj/IRCBot-ZL worm and IRC backdoor.
nopzet nopzet.dll X Added by a variant of the MyGeek/CPVFeed adware.
NVidia XTLayer gateway nvnati.sys X Added by a variant of the Goldun.Fam rootkit.
Nvdia Native Rendering nvnatv.sys X Added by a variant of the Goldun.Fam rootkit.
Distributed Link Tracking ntlsrv.exe X Added by the W32/Tilebot-KP worm and IRC backdoor.
Intec Service Drivers ntservice.exe X A variant of the Win32/Rbot.IKK family of worms and IRC backdoor Trojans.
Network IPv6 network.exe X Added by the W32/VB-DYF worm.
Kernel TCP Filtering protocol necsort.sys X A variant of the Troj/Haxdor-Gen rootkit.
ntfyapp ntfyapp.exe X Added by the Storm worm. The Storm worm is a network-aware worm that attempts to replicate across the existing network(s)
Microsoft Network Neighbourhood networknbh.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
nisdisa nisdisa.exe X Added by the Email-Worm.Zhelatin worm. Email-Worm.Zhelatin normally received as an email attachment; may consist of a rootkit, a peer-to-peer client, and a mass-mailing worm component. Its code may be injected and run from the legitimate services.exe process in order to bypass firewalls.
Network Monitor netmon.exe X Added by the Adware.Network_Monitor adware.
Win32 LanMgr netspool.exe X Added by the W32/Perin-A worm and IRC backdoor.
ntload v0.1 ntload.sys X Identified as a variant of the Trojan.Ntrootkit.AL rootkit.
MSN ntmngr.exe X Added by the Troj/Delbot-AR Trojan.
ntuser ntuser.exe X Identified as a variant of the Trojan-Downloader.Win32.Small.hpb malware.
IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} NMIndexStoreSvr.exe U Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications.
nmctxth nmctxth.exe U Part of Network Magic. Network magic helps home network users quickly solve network related problems as well as configure network related services.
ndisaluo ndisaluo.sys X Identified as a variant of the TR/Rootkit.Gen rootkit.
ntio922 ntio922.sys X Identified as a variant of the RKIT/Agent.EZ rootkit.
uptolate nucle.exe X Identified as a variant of the Backdoor.Win32.Nucleroot.a malware.
ntndis ntndis.sys X Added by the Troj/RKProc-F rootkit.
USB2_04 nkv2.sys X Identified as a variant of the Rootkit.Win32.Agent.tj rootkit.
Windows Audio Panel nppsvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Audio System nndsvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
nax12 nax12.sys X Identified as a variant of the Backdoor:Win32/Rustock.gen rootkit.
nested nested.sys X Identified as a variant of the Backdoor:Win32/Rustock.gen rootkit.
Windows Audio Components nncsvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
SystemSv121 n2ewma1xxsv234.exe X Added by the Nuwar/Storm worm.
Logical_Disk netservice.exe X Identified by Trend Micro as the BKDR_HUPIGON.EVG backdoor Trojan.
ctfmon netservice.exe X Identified by Trend Micro as the BKDR_HUPIGON.EVG backdoor Trojan.
IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] NMIndexStoreSvr.exe U Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications.
{Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E666} nusrmgr.exe X Added by the Trojan-Downloader.CashDeluxe adware.
Network Translation Service nts.exe X Added by the TROJ_XPACK.TZ Trojan.
{5738E8A8-69D9-4DA9-166B-7ADD24D1B74B} ntmon.exe X Identified as a variant of the Backdoor.Bifrose backdoor.
Windows Network Logon npesvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
iluqcwr nqyltsy.exe X Added by the W32/SillyFDC-BX removable media worm.
Microsoft Notepad Manager notepad.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
NSUService NSUService.exe Y A network utility for Sony laptops.
NoDNS NoDNS.exe X Identified as a variant of the Trojan.Agent.AHBF malware.
Windows Zero Spooler nmvcs.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Norton Antivirus norton.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
nvcoi nvcoi.exe X Identified as a variant of the Trojan.Downloader.Matcash malware.
nvsvc16 nvsvc16.exe U Added by the Spyware.MySuperSpy surveillance software. If this software is installed without your knowledge, it should be removed.
NUAgentInstallPath NU_Install.exe U Added by the Spyware.ChilyEMon surveillance software. This software should be removed if found on your computer without your knowledge.
NNServ nnrun.exe X Added by the New.net adware.
Disk Panel Setup npcsvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
OS Boot Configuration nspsvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Network Session nspsvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Protected Storage npssvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN netstats.exe X Added by the Worm.IRCBot.UXP worm and IRC backdoor.
Windows Global Init ngpsvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Newss newhost.exe X Added by an unknown Trojan.
ntoskrnl ntoskrnl.exe X Added by the W32/Zaap-A worm.
Scan Fonts New Arial Kotim.exe X Added by the W32/VB-DZA worm.
nqaplwj nqaplwj.sys X Added by the Backdoor.Rustock backdoor rootkit.
Microsoft Net Driver NETSVC.exe X Added by the W32.Momib.A worm.
Network netwin.exe X Added by the W32/SillyFDC-CG removable media worm.
NGTray ngtray.exe Y Added by the Symantec Ghost. If you are running the ghost console on a server on your network then this process will have been installed as part of the client process deployment. If you want to remove the icon from the system tray you can do this from the Server Console. Removing this will interfere with communications between the server and client and prevent identification of remote client status. If you don't want this functionality the ghost client can be uninstalled via the server console.
nexkaqf nexkaqf.sys X Added by the Backdoor.Rustock backdoor rootkit.
NetBioy Client netbioy.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
nzqtegh nzqtegh.sys X Added by the Backdoor.Rustock backdoor rootkit.
SoundTap Recorder nchssvad.sys Y Audio driver for audio chipset from Knowles.
Security Accounts ntsasvc.exe X Added by the Troj/Bckdr-QNP backdoor Trojan.
naPrdMgr naPrdMgr.exe X Added by the W32/Tilebot-KX worm and IRC backdoor.
NvidiaDisplayService nvdsc.exe X Added by the W32/Rbot-GWX worm and IRC backdoor.
Norman Worl System Ability nwcss32.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Office Monitor nvsvc86.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows ARP Detectionc nvudlsp.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
netview netview.exe X Added by the Backdoor.Bifrose.L backdoor.
Microsoft Corporation nsvdec.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
narqwe narqwe.sys X Added by the Backdoor.Rustock backdoor rootkit.
NokKernel install Nok_install.exe U Added by the Spyware.NokKernel surveillance software. This software should be uninstalled if found on your computer without your knowledge.
TCP/IP NetBIOS netbios.exe X Identified as a IRC Backdoor.
NPFValue NPFMONTR.exe X Added by the W32/Rbot-GWZ worm and IRC backdoor.
Microsoft ntsvr.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
nVidia Display Drivers (x86) nvsys86.exe X Unknown malware. If infected it will create a lmhosts file on your computer that blocks you from reaching a variety of antimalware and computer help sites, including BleepingComputer.com. To resolve this issue, you can delete the C:\Windows\System32\drivers\etc\lmhosts file.
nVidia System Drivers nvsys32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
nVidia Application Drivers nvidiav32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
NMBgMonitor.exe NMBgMonitor.exe X Added by the Troj/Bravo-G Trojan.
neos neos.exe X Added by the Troj/BdoorB-Fam backdoor.
nobicyt Service Nobicyt.exe X Identified as a variant of the Backdoor:Win32/Refpron.C malware.
New Folder New Folder.exe X Added by the W32/VB-EAS worm.
Nod32 Service nod6.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Update Nod32Av.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows NT Net Service Monitor ntsvc.exe X Added by the W32/SdBot-DKY worm and IRC backdoor.
NVIDIA nTune nTuneCmd.exe U nTune allows a user to tweak the settings of Nvidia based motherboards from within Windows and save these settings as individual profiles that can load on startup. The default settings file that loads with this command is osbootpf.nsu. This command does not need to run on Windows startup unless you use nTune to customize motherboard settings.
Multi-user Cleanup Service ntmulti.exe Y Related to IBM Lotus Notes.
Intelli Mouse Pro Version 2.0B ncsjapi32.exe X Added by the Troj/Buzus-O Trojan.
{9B71D88C-C598-4935-C5D1-43AA4DB90836} nando.exe X A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote server. It then uploads one or more files and runs them on the compromised system.
systemStart Ntfs.exe X Added by the W32/Autorun-JM removable media worm.
NBKeyScan NBKeyScan.exe U Part of the BackItUp backup software bundled with Nero 8 Suite.
neksolda neksolda.dll X Identified as a variant of the VideoAccessCodec.
newupdate newupdate.sys X Added by the Troj/Hupigo-AW Trojan.
ngwstxfd ngwstxfd.dll X Identified as a variant of the VideoAccessCodec adware.
Nano Antivirus nanoav.exe X Added by the Nano Antivirus rogue anti-spyware program.
ArcNet NDIS Protocol Driver Ndisprot.sys X Added by the Trojan.Flush.M Trojan. Trojan.Flush.M is a Trojan horse that impacts network traffic with Address Resolution Protocol (ARP) requests and lowers security settings.
*Intelli Mouse Pro Version 2.0B* ncsjapi32.exe X Added by the W32/Koobface.worm FaceBook and Myspace worm.
<not used> n.vbe X Added by the W32/AutoRun-SH removable media worm.
Norman NJeeves Njeeves.exe Y Part of Norman Antivirus.
Norman Scanner Engine Service NSESVC.EXE Y Part of real-time scanning engine for Norman Antivirus.
Norman Virus Control on-access component nvcoas.exe Y Part of real-time scanning engine for Norman Antivirus.
Norman Virus Control Scheduler Nvcsched.exe Y Scheduling service for for Norman Antivirus.
Norman's Very Own supplY of resources nvoy.exe Y Part of Norman Antivirus.
krn nl.exe X Added by the TSPY_BANKER.GBW information stealing Trojan for online banks.
nwiz nwiz.exe ? Installed with an as yet unspecified NVIDIA graphic/video card
NetDriver netdriver.dll X Added by the Troj/Dloadr-CIB downloader Trojan.
Win32load nscagent.exe X Identified by Avast as a variant of the Win32:Vupa malware.
{6825FAC3-D7D2-4045-97A2-87DF42CB6728} nods32.dll X Added by the W32/AutoRun-AFA removable media worm.
ntvbn ntvbn.exe X Trojan related to rogue software.
gabougool nounina.exe X Added by the Troj/Agent-JVX Trojan.
nah_Shell nah_cord.exe X Added by the Trojan.Hanambot Trojan. Trojan.Hanambot is a Trojan horse that steals financial information and opens a back door on the compromised computer.
NVHotkey nvHotkey.dll U Installed with certain NVIDIA graphics cards, this file allows the user to change graphics settings with hotkeys.
MSDRV NetFilter.exe X Added by the Trojan.Interrupdate Trojan. Trojan.Interrupdate is a Trojan horse that lowers security settings.
NDISRD ndisrd.sys X Added by the Trojan.Interrupdate Trojan. Trojan.Interrupdate is a Trojan horse that lowers security settings.
niu niu.exe X Added by the W32.SillyFDC.BCS removable media worm. W32.SillyFDC.BCS is a worm that spreads by copying itself to removable drives.
neos neos.exe X Added by the Troj/BdoorB-Fam backdoor Trojan.
9UmxQPSiTJMbA NVUKZ.exe X Added by the Troj/Agent-LMN Trojan.
32.exe nvscv32.exe X Added by the Troj/Agent-LOL Trojan.
Ncr3 ncrcore3.exe U

This file is installed with home or office security software that uses Panasonic Cameras. This file allows you to locally view, record and adjust the camera settings.

calc ntuser.dll X Added by the Opachki.a Trojan. Please note that rundll32.exe is a legitimate program and should not be deleted.
net net.net X Added by the Troj/Mdrop-CIF Trojan.
<not used> ntsvc32.exe X Added by the Troj/Stealth-S Trojan.
dpzProtect n.vbe X Added by the VBS.Runauto.H worm. VBS.Runauto.H is a worm that spreads through removable drives.
*ntfsqueuedns.exe ntfsqueuedns.exe X Added by the Troj/FakeAV-EMN Trojan.
notepad notepad.dll X Identified as a variant of the Trojan:Win32/Opachki.A malware. Please note that c:\Windows\System32\rundll32.exe is a legitimate program and should not be deleted.
notepad ntload.dll X Identified as a variant of the Trojan:Win32/Opachki.A malware. Please note that c:\Windows\System32\rundll32.exe is a legitimate program and should not be deleted.
Server for NFS nfssvc.exe X Added by the Troj/ServU-FZ backdoor FTP program.
<not used> nnfj.tqo X Added by the Bredolab.gen.o password-stealing Trojan. Please note C:\Windows\System32\rundll32.exe is a legitimate program and should not be removed.
<not used> nologon32.exe X Added by the Troj/Zbot-ND Trojan.
nod32 nodqq.exe X Added by the W32/Autorun-BBV removable media worm.
NZ01 NZ01.exe X Added by the Troj/Scar-K Trojan.
NMSAccessU NMSAccessU.exe Y Service used by various CD/DVD Drive vendors and software for interacting with the installed CD/DVD drive.
NVIDIA Display Driver Service nvvsvc.exe Y Provides system and desktop level support to the NVIDIA display driver
NVIDIA Stereoscopic 3D Driver Service nvSCPAPISvr.exe Y Provides system support for NVIDIA Stereoscopic 3D driver.
Netprotocol netprotocol.exe X Added by the Troj/FakeAV-BNY Trojan.
NokiaMServer NokiaMServer.exe N

This file is installed with OVI Suite, a phone synching software by Nokia, and other OVI applications such as OVI player.  The file also is used in synching the phone, indexing photos, media files, and other tasks.  According to a statement from Nokia dated Sept. 2, 2011, the next major release of OVI Suite will not have this file.  Other OVI applications, however, will.  Many users state that this file is a severe memory hog.  It is suggested that you disable this startup as the applications will start it when you start the program.  Once finished using the program, it appears that the user must manually stop this file from running.

May also have the command:

%programfiles%\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup

NetworkControl nc.exe X Added by the NetworkControl ransomware.
Network Connections netman.dll Y This Windows services manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
Network List Service netprofm.dll Y This Windows identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
Network Location Awareness nlasvc.dll Y This Windows collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
Network Store Interface Service nsisvc.dll Y This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
SecurDisc NBHGui.exe U Installed by the Nero CD/DVD authoring software, SecurDisc allows the user to encrypt, password protect, and content protect CD's, DVD's, and Blu-ray Discs and also utilizes technology to read the disc on the computer regardless of deterioration, scratches, and age.  It also provides advanced warning to the user about disc failure so it can be backed up.
<not used> ntload.exe X Added by the Advanced Security Tool 2010 rogue anti-spyware program.
rundll32 ntload.exe X Added by the Advanced Security Tool 2010 rogue anti-spyware program.
Nokia nsu_ui_client.exe X Added by the Troj/Banker-FAQ information stealing Trojan for online banks.
nodsos nodabc.exe X Added by the Troj/PWS-BLE password-stealing Trojan.
rundll32 ntdevice.exe X Added by the Troj/Agent-OUM Trojan.
NokiaOviSuite2 NokiaOviSuite.exe N Installed with version 2 of Nokia Ovi Suite software, a phone synching program that also indexes photos, videos, and music files and allows the user to share these files.
Nvidia Control Center NvTaskbarInit.exe X Added by the Troj/Hiloti-AY Trojan.
Nikon Monitor NkMonitor.exe U

Bundled with certain Nikon cameras, this program checks to see if the camera has been plugged into a USB port then opens a program to facilitate downloading images or videos from the camera to the computer.
 

NVIDIA driver monitor nvsvc32.exe X Unknown malware.
Ci Servs newbin.exe X Added by the Troj/Rimecud-BC Trojan.
NBCore nbcore.exe U Part of Nero's BackitUp 4, this file will automatically backup specified files and folders to a local location or to Nero Online Backup.  It will also automatically backup changes to those files and any new files in specified folders replacing the old backup with the new one.  To disable this from starting up, go through the tray icon and uncheck "Launch at Startup".
NICCONFIGSVC nicconfigsvc.exe Y Service for various Internal Network Cards made by Dell, Inc. Involved with the power management.
NICCONFIGSVC nicconfigsvc.exe Y Service for various Internal Network Cards made by Dell, Inc. Involved with the power management.
NUSB3MON nusb3mon.exe N Monitors whether or not devices are inserted into the motherboard's USB 3.0 port.
RealActive ntoscore.exe X Identified by Kaspersky Antivirus as a variant of the Virus.Win32.Virut.q malware.
NVIDIA Driver Helper Service nvvsvc.exe Y Part of the display driver for Nvidia cards.
NSLauncher NSLauncher.exe N Added by the Nokia PC Suite software. This program detects when you connect your Nokia devices and then automatically launches the program.
NVHotkey nvHotkey.dll U Installed with certain NVIDIA graphics cards, this file allows the user to change graphics settings with hotkeys.

Please note, C:\Windows\System32\rundll32.exe is a legitimate program and should not be deleted.
nwizs nwizs.exe X Added by the W32.Queshare worm. W32.Queshare is a worm that spreads through removable drives and instant messaging shared folders. It may also download files and steal information from the compromised computer.
CLCKR nvvsvc.exe X Added by the Troj/Agent-TQK Trojan.
NortonOnlineBackup NOBuClient.exe U Provides access to Norton's Online Backup through a tray icon and also provides notifications through that tray icon.
Akamai NetSession Interface netsession_win_b427739.dll U Added by the Akamai NetSession downloader. This is a service launched by the legitimate C:\Windows\System32\svchost.exe program. The actual executable file for the Akamai NetSession Interface service is %ProgramFiles%\common files\akamai\netsession_win_b427739.dll.
Nalpeiron Licensing Service nlssrv32.exe Y Added by the Nalpeiron Licensing Service licensing software.
Akamai NetSession Interface netsession_win.exe U Added by the Akamai NetSession downloader. This is a service launched by the legitimate C:\Windows\System32\svchost.exe program. The actual executable file for the Akamai NetSession Interface service is %ProgramFiles%\common files\akamai\netsession_win_b427739.dll.
RDSound NokiaDriveUpdate.exe X Added by the Troj/Agent-UOU Trojan.
night night.exe X Added by the Mal/VB-PM malware.
NielsenOnline NielsenOnline.exe X This is software that monitors your Internet usage and offers surveys that are based on users online habits. The data that is monitored is supposedly reported anonymously. Though this software is not considered malware or malicious, since this software can be bundled with adware and performs constant monitoring of your activity, it is the site's opinion that you disable it.
Dell DataSafe Online NOBuClient.exe U Provides access to Dell's DataSafe Online through a tray icon and also provides notifications through that tray icon.
Nikon Transfer Monitor NkMonitor.exe U Bundled with certain Nikon cameras, this program checks to see if the camera has been plugged into a USB port then opens a program to facilitate downloading images or videos from the camera to the computer.
NOD32 Kernel Service nod32krn.exe Y Required service for ESET NOD32 antivirus. This file can also be found in the %ProgramFiles%\Eset\nod32krn.exe folder.
AhnLab V3Lite Update Process nusb3mon.exe X Added by the TrojanDownloader:Win32/Navattle.A malware.
PCAlertDriver NTGLM7X.SYS Y Part of MSI's PC Alert. PC Alert detects system temperature, the status of voltage, fans and all other key motherboard components. If any problem occurs, it will alert the user to correct the problem, reducing the risk of system damage.
Microsoft Network Inspection System NisDrvWFP.sys Y A driver related to Microsoft Security Essentials.
Nvtmru nvtmru.exe U Part of the NVIDIA GeForce Experience.
NTIOLib_1_0_2 NTIOLib_X64.sys Y Driver that unlocks CPU cores on certain MSI motherboards.
NisSrv NisSrv.exe Y MSE Network Inspection System driver for Microsoft Security Essentials.
NTRedirect NTRedirect.dll X Added by the Babylon and Delta Search adware programs.
nmjim2z2zhm1bgz nmjim2z2zhm1bgz.sys X Added by the Hades adware. This program is part of the Adware.Salus, which shows intrusive ads on sites you visit.
SushiLeadsUpdaterService NpUpdaterService.exe X Added by the SushiLeads adware. SushiLeads displays advertisements and lead generation forums in search result pages.
Secured Net netsafe.exe X Added by the NetSecure adware.
NetUtils2016 NetUtils2016.sys X Added by the Netutils Adware.
Nerta nerta.exe X Uninstall Programs entry for a Nerta Tech Support Scam Trojan.
Btior New nertacs.exe X Uninstall Programs entry for a Nerta Tech Support Scam Trojan.

Login

Remember Me
Sign in anonymously