CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    NsvdrXnsvdr.exeAdult content dialler
    Norton Service DriverXwsul.exeAdded by the W32/RBOT-ABI WORM!
    NAV Auto ProtectXmsfwe1.exeAdded by a variant of the WIN32.RBOT WORM!
    NVHotkeyUnvHotkey.dllRelated to related to nVIDIA_ForceWare Hotkey Service
    NI.UWFX5TXUWFX5TNetInstaller.exeAdded by the Troj/DownLdr-BO TROJAN! Note: This trojan file is found in the Windows\Downloaded Program Files or Winnt\Downloaded Program Files folder.
    NetmonwXNetmonw.exeAdded by the TROJ/BDOOR-FX TROJAN!
    NVIEWUrundll32.exe,nview.dll, nViewLoadHookThis is a DLL to enable multiple display monitors on a single computer. It can be a cause of numerous problems on some computers
    Nielsen NetRatingsNinsight.exeNielsen NetRatings -  "Provides real-time research and analysis about Internet users, delivering the timely, actionable data you need to make critical business decisions on your competition, your Web site’s audience and your customers". Is it required?
    NAV CfgWiz or NAV Configuration WizardNcfgwiz.exeIntroduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it
    NotebookManager?nbm.exeAssociated with Acer notebook PCs. What does it do and is it required?
    NSCheckXNSCHECK.EXE NetSetter/Marketscore foistware
    ntuserXctfmun.exeAdded by a variant TSPY_AGENT.ACEZ by Trend Micro Note: Located in \%WINDIR%\System32\drivers\ Note: Use SDFix under supervision.
    NVRTNnvrt.exeNVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports
    Norton Personal FirewallYIntroWiz.exePart of Norton Personal Firewall or Norton Internet Security
    Notebook MaximizerUmaximizer_startup.exeToshiba Notebook Maximizer software; adjust settings to save battery power and increase efficiency
    Newsgroup ml097eXnewsgroup.exe RapidBlaster Variant
    Nod32CCUnod32cc.exeControl Center part of Eset's NOD32 virus-scanner. Leave this enabled if you want to update your virus data files via the click of a button
    News Service?ispnews.exe F-Secure antivirus related. However, is this particular item required??
    ntsmodXntsmod.exeadware downloader/installer, probably VX2/Look2Me related - also detected as the WIN32.VB.RL TROJAN!
    NeroCheckXregedit.exeAdded by the DOOMJUICE.B VIRUS! Note - this is not the valid Ahead Nero CD burning program. Also it is not the valid Windows registry editor which resides in C:\Windows or C:\Winnt wheras this version resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP)
    NewtonKnowsUpdXNewtKnow.exe,...NewtnUpd.dll, runkeyNewtonKnow hijacker
    NetTimeUNETTIME.EXEFrom a visitor - "This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols, e.g. NTP."
    nvscv32Xnvscv32.exeAdded by a variant of the W32/SDBOT WORM! Note: Located in C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K)
    Norton Auto-ProtectXSERVICES.exeAdded by the W32.Ahker.B WORM!
    ntx32Xntx32.exeAdded by an unidentified Trojan/Backdoor TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    NtcheckXmapserver.exeAdded by the TROJ/TOMPAI-B WORM!
    NOD32 FiX.lnkXregedt32.exe NodFix is a is a potentially unwanted application. This application was given an (X) status because CastleCops does not and will not support Cracks or Warez. Do not delete the regedt32.exe as it is the legitimate Windows application. NodFix interferes with the default settings of the NOD32 AV application allowing to bypass its free using period as well as changes the default update server to that eval signatures thus allowing to update NOD32 without password. Note: To avoid interfering with the NOD32 application original settings no full cleanup can be provided.
    nVidia Display Drivers (x86)Xnvsys86.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Norton UpdateXccUpdate.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    NvCplXrundl32.exeAdded by the W32/Agobot-TO WORM! Note: This (rundl32.exe) is not the legitimate Windows process rundll32.exe (Notice the difference in the spelling.) This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Network Security GuardX**********.exe,(* = random,char) CoolWebSearch parasite related.
    Nortons AVS SystemsXarse.exeAdded by the RBOT.AWY WORM!
    NiroFile UpdatedXNiroFile.exeAdded by a variant of the BACKDOOR.IRC.BOT Note: This trojan is located in \%WINDIR%\System32\ Read the link, allows remote access
    Nvidia32Xnvidia32.exe CoolWebSearch parasite related.
    Net AcceleratorUNetAccelerator.exeRizal NetAccelerator - "Optimizing Dial-Up, Lan, Cable, DSL, and Satellite connections do you want to speed up your Internet access up to 200% - 300% ???". Only required if you find it helps improve your performance
    netupdate32Xnetupdate32.exeAdded by the W32/Rbot-GQZ Worm
    Norton Crashguard MonitorNcgmenu.exeTroublesome program that doesn't actually work with WinME so Norton removed it from SystemWorks 2001
    NADaemonNNADAEMON.EXEProgram by NetActive which appears to be piggybacked onto some Nvidia graphics cards software. They seem to look after "digital rights management". One user reports disabling it has no detrimental affect - not required
    ntldrXntldr.exeBrowser hijacker to search-control.com (TrojanDropper.Win32.Small.ig). In addition to Registry changes found by HijackThis, also creates the following system files: * Creates file C:\WINDOWS\SYSTEM\ntldr.exe. * Creates file C:\m.exe. * Creates file C:\WINDOWS\Search-For-You.url. * Creates file C:\n.bat. * Deletes file c:\q.exe. * Creates file C:\q.exe. * Creates file C:\r.bat
    NVIDIA Video driversXvideo_32D.exeAdded by the AGOBOT.KV WORM!
    nvchostXwinlogon.exeAdded by the Troj/Klone-J TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ folder
    Network Protocol ServiceXwuamgrd.exe WORM_RBOT.EA
    Norton AntiVirus SysXNAVsys32.exeAdded by a variant of the W32/WOOTBOT WORM!
    NOTEPADXNOTEPAD.exeAdded as the result of the RUSTY VIRUS! Note - not to be confused with the valid Windows "NOTEPAD" text editor! - This malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
    Norton Program Scheduler Event Checker?npscheck.exePart of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as NPS Event Checker
    Norton System DoctorNSysdoc32.exeNorton Disk Doctor from Norton Utilities. Automatically runs at start-up, major resource hog and best started manually form Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well
    NB Start MenuNSTARTM.EXEPart of McAfee Nuts & Bolts. Provides the same control as MSCONFIG and can be used instead if you have N&B
    Network Host ControllerX(path to,trojan)Added by the WHISPER VIRUS!
    NotnXEber.exe PurityScan/Clickspring Adware
    NDSTray.exeNNDSTray.exeRelated to ConfigFree_Traybar utility on Toshiba laptops. It allows you switch between network devices by clicking on the traybar icon. Note: Located in C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    NodeMnger?Nodemngr.exePart of the Dell OpenManage Client installation - to allow Dell representatives to remote logon?
    NetShow Powerpoint HelperUNSPPTHLP.EXEIf disabled, user created fonts can no longer be seen by other programs
    NTdhcpXNTdhcp.exeAdded by the Troj/QQRob-O or Troj/QQRob-K TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder
    NBJUNBJ.exeAhead Nero BackItUp backup program. Only required for if you have scheduled back-ups
    NTSF MICROSOFT SYSTEMXsysman.exeAdded by the WORM_RBOT.EDP WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) steal information and terminate anti-virus applications

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer