Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Alert!  Have a problem and would like to ask us for help? To learn how to ask your question Click Here!
Stop!  Do you have popups or other malware infecting your computer? If so, Start Here!
Question?  Are you having trouble using this site? Then you should visit the New User Orientation Center!



A    B    C    D    E    F    G    H    I    J    K    L    M    N    O    P    Q    R    S    T    U    V    W    X    Y    Z    Other   
HJT: F0, F1, F2, F3 · O4 · O20 · O21 · O22 · O23
Rootkit List · Submit a Startup · Top Submitters
 Startup Index · Newest Entries · Mozilla Search Tools · WebMaster Site Tools · Status Key
Startup Database Forum · Computer Help Forums · How to use the Startup Database

Enter the filename or keyword you would like to search for:
Advanced Search

Name Filename Status Description
!!!! new_drv.sys
X
Added by the Troj/NTRootK-BE rootkit Trojan.
(Default) NOTEPAD.exe
X
Added by the RUSTY WORM! Note - not to be confused with the valid Windows "NOTEPAD" text editor ... Read More
(default) ne.exe
X
Added by the Troj/IRCBot-ZL worm and IRC backdoor.
.NET Runtime Optimization Service NETServ.exe
X
Added by the W32/Sdbot-CSA worm and IRC backdoor.

W32/Sdbot-CSA spreads to other network computers by exploiting common buffer overflow ... Read More
/l:eng N/A
N
Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appe ... Read More
17779Proj2002 N/A
?
??
1CmailS NETMAIL.EXE
?
??
4684735485910 netdll32.exe
X
Added by the W32/Sdbot-DEV worm.
4wd!!! Natal!.pif
X
Added by the OPASERV.AI WORM!
<not used> NETLIB32.DLL
X
Added by the Troj/Oscor-G backdoor Trojan.
<not used> nv4_icm3.dll
X
Added by the W32/Stration@MM mass-mailing worm.
<not used> NTDLL32.dll
X
Unidentified malware.
<not used> ntsvc32.dll
X
Identified as the Trojan-Notifier.Win32.Small.i malware.
<Unknown> nuclab.sys
X
Added by a variant of the Goldun.Fam rootkit.
Access Protocol nixfver.exe
X
Added by the BKDR_PPDOOR.AS backdoor.
ActiveScript32 nod.exe
X
Added by the W32/Sohana-AJ worm.
AdobeReaderPro ntkernell32.exe
X
Added by the W32/Rbot-ATY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
anbv32 nabv32.exe
X
Added by the TITOG.C WORM!
Application Explorer Naldesk.exe
U
Novell Zenworks Application Explorer Executable. "For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) ... Read More
Application Window NALWIN32.EXE
Y
Part of Novell's Zenworks. Found in the C:\Program Files\Novell\ZENworks folder. ... Read More
ARCSolo Recovery N/A
N
Backup software by Computer Associates - no longer supported
arsch nets.exe
X
Added by the W32/Forbot-EL, it's displayname is "Indexing Provider".
ASDPLUGIN Netherlands.exe
X
AsdPlug premium rate adult content dialer variant
autoprotectu navapq32.exe
X
Added by an unidentified WORM or TROJAN!
AVSTRT navpsrvc.exe
X
Added by the W32/Forbot-EF worm. When started this infection connects to a remote IRC server where it waits for commands to execute. These infection ... Read More
Batchreg1 N/A
N
Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during ... Read More
benzaldoxime nczupfw.dll
X
Added by a Zlob Trojan which installs AntiVirgear 3.8 and display fake security alerts in your Windows taskbar. ... Read More
bgmonitor_{79662e04-7c6c-4d9f-84c7-88d8a56b10aa} NMBgMonitor.exe
U
Related to Nero_Home
boby netburn.scr
X
Added by the Troj/Bancban-OX banking Trojan. If you are infected with this Trojan it is advised that you immediately change all the passwords for you ... Read More
Boot Manager Njgal.exe
X
Added by the KILO TROJAN!
bpk nvsr32.exe
U
Blazing Tools Perfect Keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't ... Read More
Bron-Spizaetus norBtok.exe
X
Added by the W32.Rontokbro.B@mm mass-mailing worm.
C:\Program Files\NetMeter\NetMeter.exe NetMeter.exe
N
Added by the NetMeter bandwidth meter.

"NetMeter is a small, customizable network bandwidth monitoring program for Windows 95/98/98SE/M ... Read More
caribi ncrjf.dll
X
Zlob Trojan which installs the VirusProtect 3.8 rogue anti-spyware program. This program displays fake security alerts stating that your compute ... Read More
Chckup Netverchk.exe
X
Identified by AntiVir as TR/Dldr.Age.66267.A.
COM Message Transfer Ntmssvcs.dll
X
Added by the Troj/Dbit-A trojan.
compaq service drivers navapqwa.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Compaq Service Drivers ntdat32.exe
X
Added by the W32/Sdbot-CNW worm. When started, this infection connects to a remote IRC server where it waits for commands to execute ... Read More
compaq services drivers ndt32.exe
X
Added by the RBOT.CQZ ... Read More
Compuware Distributed Analyzer Service NCS.exe
Y
Added as part of the Compuware DevPartner Studio.
ComService Netlogon.vbs
X
Added by the VBS/Edibara@M virus.
Configuration ntsys32.exe
X
Added by the W32/Sdbot-LH worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Configuration ntsyst32.exe
X
Added by the W32/Sdbot-LT worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Configuration Loader NOTEPADE.EXE
X
Added by the W32/SdBot-GD worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute. ... Read More
Corel Reminder NAVBROWSER.EXE
N
If you don't want to register Corel products and be reminded about it every 2 weeks disable it ... Read More
CostAware niIPCApp.exe
U
NetInternals CostAware - download quota measuring tool
cpntmgc navpmc.exe
X
MagicControl downloader trojan variant
ctfmon netservice.exe
X
Identified by Trend Micro as the BKDR_HUPIGON.EVG backdoor Trojan.
DashIE N/A
?
Could be related to "Dash Power Shopping" tool bar in IE?
Datechecker N/A
?
Could be related to this?
DDMP netservice.exe
X
Added by the Troj/Delf-EXQ Trojan.
DDT N/A
?
??
directx NTCmd.exe
X
Added by the SDBOT.D TROJAN!
Disable EHCI nousb20.exe
?
??
Disk Panel Setup npcsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Distributed Link Tracking ntlsrv.exe
X
Added by the W32/Tilebot-KP worm and IRC backdoor.
DLHelperEXE.exe N/A
X
Downloader for Microgaming/Casino software - stealth installed
Dll Injection NXCM.EXE
X
Added by the W32/Sdbot-IT worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
Driver nso12k.sys
X
Added by the Troj/Knockit-A backdoor Trojan.
dxdll32 ntxdll.exe
X
Added by the GAOBOT.CPX worm which has keylogging, DOS, and backdoor capabilities. ... Read More
Ehch nbme.exe
X
PurityScan delivers advertisements to your computer.
Explorer navawp32.exe
X
Added by the Troj/Ronoper-B backdoor trojan.
EYORE Notepad.scr
X
Added by the W32/Gimlet-A worm.
Fast start Ntut.exe
X
Added by unidentified adware - recognized by Kaspersky antivirus as Trojan.Win32.Favadd.i ... Read More
FastStart ntnut32.exe
X
Added by the StartPage.L TROJAN!
FASTTRACKNETVISION NETVISION.exe
X
Added by the Dial/DialCar-Z premium rate dialer..
FireWire Service nvscv32.exe
X
Added by a variant of the W32/SDBOT WORM!
firewire services nvcsv32.exe
X
Added by a variant of the W32.SPYBOT WORM! ... Read More
ForceWare Intelligent Application Manager nSvcAppFlt.exe
Y
Related to the NVIDIA firewall used on certain motherboards that have the NVIDIA forceware chipset. ... Read More
ForceWare IP service nSvcIp.exe
U
Related to the NVIDIA Firewall used on certain motherboards with nForce chipsets. Not needed if you do not use this Firewall. ... Read More
ForceWare user log service nSvcLog.exe
U
Related to the NVIDIA Firewall used on certain motherboards with nForce chipsets. Not needed if you do not use this Firewall. ... Read More
Forceware Web Interface nSvcAppFlt.exe
U
Web interface for configuring and managing the NVIDIA firewall used on certain motherboards. Not needed if you do not use this Firewall. ... Read More
gdwxp3 nuclabdll.dll
X
Added by a variant of the Goldun.Fam Trojan.
Generic Host Process for Win32 Services ntspcv.exe
X
Added by the SDBOT.S TROJAN!
GinaDll ntgina.dll
X
Added by the ANIG.A WORM!
GLF Network Lan Monitor NPFMNTOR.exe
X
Added by the W32/Rbot-AGY worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
GoOutside nakedx.exe
X
Added by the W32/Sdbot-AGK worm and IRC backdoor.
graphic loader ntvdm32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
hdlpscom netilxgn.exe
X
Added by the W32/Rbot-FXD worm and IRC backdoor. W32/Rbot-FXD may spread using a variety of techniques including exploiting weak passwords on computer ... Read More
helloworld nb32ext3.exe
X
Added by the MYTOB.JT WORM! ... Read More
Host N/A
X
Added by the POPDIS or STARTPAGE.F TROJANS!
hpoddt01.exe N/A
N
Installed by the "HP Photo and Imaging Director" software. If you ask for the imaging software, this program will be started ... Read More
Hti npdor.exe
U
Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not re ... Read More
HWinst N/A
Y
For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue ... Read More
iCn NAG.EXE
N
iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist ... Read More
IE Processes nosc32.exe
X
Added by the W32/SdBot-CN backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
iluqcwr nqyltsy.exe
X
Added by the W32/SillyFDC-BX removable media worm.
IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} NMIndexStoreSvr.exe
U
Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications ... Read More
IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] NMIndexStoreSvr.exe
U
Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications ... Read More
Inetapi Netapi.exe
X
Added by the NETDEVIL.14 TROJAN!
Input and output operations ntio256.sys
X
Added by the Troj/Bckdr-QHO Trojan.
Intec Service Drivers ntservice.exe
X
A variant of the Win32/Rbot.IKK family of worms and IRC backdoor Trojans.
Intelli Mouse Pro Version 2.0B ncsjapi32.exe
X
Added by the Troj/Buzus-O Trojan.
Intelli2k netbug.vbs
X
Added by the VBS/VBuggy-A networm worm.
Internet nteusodp.exe
X
Added by the W32/Rbot-GFJ worm and IRC backdoor. W32/Rbot-GFJ spreads to other network computers by exploiting common buffer overflow vulnerabilities, ... Read More
Internet Services Netsvc.exe
X
Added by the WORM_MYTOB.NH worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
IPinst N/A
Y
For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue ... Read More
IPv6 STUN Service netstun.exe
X
Added by a variant of the SDBOT WORM!
irfk NITEAIM.EXE
X
Added by the W32/Sdbot-AEJ worm and IRC backdoor.
Iusage netdet.exe
N
Internet Usage Monitor - utility to calculate the cost and time on the internet via dial-up ... Read More
IZE N/A
?
??
Java Update nod.exe
X
IRCBot variant.
kernal fault check ntosrkl.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Kernel Fault Check ntvbm.exe
X
Added by the W32/Rbot-CKP worm and IRC backdoor.
Kernel Loader ntkrnl.exe
X
Added by the CERVIVEC.A WORM!
Kernel TCP Filtering protocol necsort.sys
X
A variant of the Troj/Haxdor-Gen rootkit.
KSD2Service notaped.exe
X
Added by the Troj/DownLd-ABB Trojan.
LASTinst N/A
Y
For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue ... Read More
load32 netda.exe
X
Added by the NIBU.E TROJAN!
Loadout Manager nost_LM.exe
U
Manager for the Belkin Nostromo n50 SpeedPad game controller - see here
Logical_Disk netservice.exe
X
Identified by Trend Micro as the BKDR_HUPIGON.EVG backdoor Trojan.
MagicSet.exe nkruls.exe
X
Added by the W32.Slurk.A worm. This infection will also configure itself as debuggers for many other security related programs. ... Read More
Mcafee Anti Scan NortonScn.exe
X
Added by a variant of the RBOT WORM!
Media Sariel Number Services notaped.exe
X
Added by the Troj/DwnLdr-FYA Trojan.
Messenger ntsubsys.exe
X
Added by the WORM_SDBOT.BGE trojan.
Messenger Protocol netsender.exe
X
Added by the W32/Sdbot-ACC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Messenger Service nvhost.exe
X
Added by the W32.Mytob.HM@mm worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsft Update 32 neta.exe
X
Added by the W32/Rbot-AMI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
microsof value nmatt.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft netsrv.exe
X
Added by the W32/Rbot-GOS worm and IRC backdoor.
Microsoft netfix32.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
Microsoft Nvpss.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft netshield.exe
X
Identified as the Backdoor.Win32.Agent.aqb malware.
Microsoft ntsvr.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft (R) Windows Network Latency Controller nlc.exe
X
Added by the Backdoor.Ranky backdoor Trojan. This infection also installs a Windows service of the same name and filename. ... Read More
Microsoft (R) Windows Network Security Management Service nsms.exe
X
Added by the Backdoor.Ranky backdoor Trojan.
Microsoft (R) Windows Vista/NT Runtime Compatibility Service nrcs.exe
X
Added by the Backdoor.Ranky.X backdoor Trojan. This infection also creates a Windows service using the same name and filename. ... Read More
Microsoft Agent nsch0st.exe
X
Identified as a variant of the Win32/Duiskbot.AG malware.
Microsoft Autorun1 nwizdh.exe
X
Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on ... Read More
Microsoft Autorun10 nwizwmgjs.exe
X
Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on ... Read More
Microsoft Autorun12 nwizzhuxians.exe
X
Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on ... Read More
Microsoft Autorun13 nwizwlwzs.exe
X
Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on ... Read More
Microsoft Autorun20 nwizfy.exe
X
Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on ... Read More
Microsoft Autorun3 nwizhx2.exe
X
Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on ... Read More
Microsoft Autorun7 nwiztlbu.exe
X
Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on ... Read More
Microsoft Corporation nsvdec.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft CSRSS Service nsmscrs.exe
X
Added by the W32/Rbot-BPT worm and IRC backdoor.
Microsoft Installshield nundll32.exe
X
Added by the W32/Agobot-AHZ worm and IRC backdoor.
Microsoft Internel Corporat netvhost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Internet new.exe
X
Added by the Troj/Banker-DSL Trojan.
Microsoft Internet novo.exe
X
Identified by Panda Antivirus as Trj/Banker.HYW. If you are infected with this file then you should immediately change your online banking passwords a ... Read More
Microsoft Name Server nssrv.exe
X
Added by the W32/Tilebot-EK worm and IRC backdoor. This infection utilizes the rootkit rofl.sys. ... Read More
Microsoft Neser Experience nese.exe
X
Added by an Rbot WORM variant!
Microsoft Net API ntps.exe
X
Added by the W32/Tilebot-HA worm and IRC backdoor.
Microsoft Net Driver NETSVC.exe
X
Added by the W32.Momib.A worm.
Microsoft NetMeeting Associates, Inc. NetMeeting.exe
X
Added by a variant of the LOVGATE WORM!
microsoft network Networksystem.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Microsoft Network Daemon for Win32 Netd32.exe
X
Added by the SDBOT.R TROJAN!
Microsoft Network Daemon for Win32 ntd32.exe
X
Added by the W32/Randex-G worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
Microsoft Network Neighbourhood networknbh.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Network Service netsvc.exe
X
A variant of the Backdoor.Win32.Rbot.eac family of worms and IRC backdoor Trojans. ... Read More
Microsoft Newss newhost.exe
X
Added by an unknown Trojan.
Microsoft Norton Antivirus norton.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
microsoft notepad notepad.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Notepad Manager notepad.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft NT Drivers ntdrv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Nvidia Video nvidia.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Office Nxcxtpr.exe
X
This is a SDBot variant infection. When run this infection connects to an IRC server, hoeee.routing.vu, and join channel #kloni with password 1q2wxc ... Read More
Microsoft Office Nxcao.exe
X
Added by the W32/Rbot-ZE WORM/IRC backdoor Trojan!
Microsoft PCHealth32 NDDENB.exe
X
Added by the Troj/PWSYahoo-A password-stealing Trojan for the Yahoo Messaging Service. ... Read More
Microsoft Software Update nmon.exe
X
Added by the RBOT.HZ WORM!
Microsoft Svchost local services nzm23.exe
X
Added by the W32/Rbot-GMC worm and IRC backdoor.
Microsoft Synchronization Manager netscape.exe
X
Added by the RANDEX.AE WORM!
Microsoft System Checkup ntsysmgr.exe
X
Added by the DONK.S WORM!
Microsoft System Checkup ntsysman.exe
X
Added by the SDBOT-QW WORM!
microsoft system checkup netapi32.exe
X
Added by the W32/DONK-E WORM! ... Read More
Microsoft System Checkup netlogin32.exe
X
Added by the W32/SdBot-GN worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute. ... Read More
Microsoft System Checkup NTSYSMGR.EXE
X
Added by the W32/Sdbot-OC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update navmgrd.exe
X
Added by the SDBOT.DP TROJAN!
Microsoft Update NAV.exe
X
Added by the RBOT-IV WORM!
Microsoft Update ntsf.exe
X
Added by the W32/Rbot-BBP worm and IRC backdoor.
Microsoft Update ntservice.exe
X
Added by the Troj/Agent-DIS Trojan.
Microsoft Update nbdos.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
microsoft update 23 NtKernelSystem.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Update 32 network.exe
X
Added by the W32/Rbot-AQE worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update 32 network.exe
X
Added by the W32/Rbot-ARZ worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Microsoft Update Machine ntce.exe
X
Added by the RBOT-FA WORM!
Microsoft Update Machine