CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    ntddetectXntddetect.exeAdded by the TROJ/AGENT-CU or BDOOR-ZAU TROJANS!
    NfoXnfomon.exeAdded by the Adware.W32.DelFin Note: Located in C:\Windows\System\nfomon\ (Win9x/Me), C:\%WINDIR%\System32\nfomon\ (XP/WinNT/2K) More: here
    Norman ZANDAUZLH.EXESystem Tray icon for Norman Antivirus
    nsvcinXn20050308.exeAdware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!
    netsv32Xnetsv32.exeAdded by a W32/Sdbot-PX worm infection
    NSRKeyUNSRTray.exeRelated to Save_and_Restore Symantec Corporation products. Note: Located in C:\Program Files\NORTON~1\NSR\Agent\
    NOMAD DetectorUctmnrun.exeDetects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
    norten Software IntrenetXnorten.pifAdded by W32/Rbot-AWA WORM!
    nsys32Xnsys32.exeAdded by the W32/Agobot-SU Worm!
    NoWayVirusXpgs.exeAdded by AVSystemCare ROGUE! An application reports false detections for a number of Trojan horses. Note: Located in \%Program Files%\NoWayVirus\
    NovaBackup * Tray ControlUNbkCtrl.exeScheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see http://www.no-panic.com/backup/tech_supt/nbackup7_commandline.html * represents the version number
    Norton UpdaterXNortonUpdate.exeAdded by an unidentified WORM or TROJAN!
    Nitro PDF Printer MonitorUNitroPDFPrinterMonitor.exeRelated to Nitro_PDF Printer Monitor from Nitro PDF, Inc., PDF program. Note: Located in \%Program Files%\Nitro PDF\Professional\
    NeroCheckXregedit.exeAdded by the DOOMJUICE.B VIRUS! Note - this is not the valid Ahead Nero CD burning program. Also it is not the valid Windows registry editor which resides in C:\Windows or C:\Winnt wheras this version resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP)
    nvcoiXnvcoi.exeDetected as Downloader-BCF by McAfee. Note: Located in %programfiles%\nvcoi
    Nod29 ServiceXnodwr.exeAdded by a variant of the Rbot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    netservicesXsvchostn.exeAdded by the SDBOT.GI WORM!
    NBInstallXMBDownloader_*****.exeAdded by the Mirar_D a variant of the ADSPY/NetNucleus adware! The *s stand for random characters. Note: Located in \%Temp%\
    NCS_SSNCsinsm32.exeSame as CleanSweep Smart Sweep-Internet Sweep
    Norton UpdaterXccUpdate.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    NetXWINREG.EXEAdded by the ASSASIN.D VIRUS!
    NarratorX******.exe (* =,random char)Added by the QOOLOGIC TROJAN!
    NetlimiterUNetlimiter.exeNetlimiter - "An internet traffic control tool to monitor applications which access the internet and actively control their internet traffic. Use it o set (download/upload) speed limits for applications or even single connection. NetLimiter also allows you to share your internet connection bandwidth among all applications running on your PC."
    NvInitializeNrundll32.exe,NvQtwk.dll, NvXTInitThought to enable the clock frequency option on nVidia control panels. You can overclock without leaving this enabled
    Norton AntivirusXnortonav.exeAdded by the W32/Rbot-AYE TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (NT/2000/XP) folder.
    NInitNNInit.exeNorton Uninstall Deluxe. Monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging - not required
    Notepad ml097eXnotepad.exe RapidBlaster Variant
    Norton Swap CleanerXnortonswap.exeAdded by a W32/Rbot-MH worm infection
    NeroFilterCheckUNeroCheck.exeAssociated with "Nero Burning Rom" CD writing software. Checks for driver issues
    NGServerNngserver.exeSymantec/Norton Ghost Console service
    NI.UWFX5_0001_N57M2112XWinFixerScannerInstall[1].exeThis is WinFixer Malware. Note: This Malware file is located in a Documents and Settings\User name\Local Settings\Temporary Internet Files\Content.IE5 subfolder.
    NCDNncd.exeNorton Change Directory - from the DOS days that allows the user to change directories on their machine without typing the complete path
    neroXnrchk.exePremium rate adult content dialer
    Ntech.patchsX(trojan,filename)Added by the LEMIR.G VIRUS!
    NeroCheck.exeXNeroCheck.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This is NOT related to "Nero Burning Rom" CD writing software. Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    NVRTClk?NVRTClk.exeRelated to a Gigabyte video card; unsure whether required
    NVIDIA Video driversXvideo_32sD.exeAdded by the W32/Rbot-BB WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    NTSF MICROSOFT SYSTEMXmarya.exeAdded by the W32/Rbot-AXY WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    NI.UWFX5LP_0001_0803XUWFX5LP_0001_0803NetInstaller.exeWinFixer web installer - Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
    nTuneUnTune.exenVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards
    NewsUpdNnewsupd.exeFor Creative Soundblaster Live! series soundcards. System tray application for News updates. Available via Start -> Programs. Also spyware - see here.
    NVRTNnvrt.exeNVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports
    Nod32 Free antivirusXnod32krn.exeAdded by the RBOT-AAO WORM! Note - not the popular free NOD32 antivirus software, which shares the same filename
    NvCplDaemon32Xanvshell32.exeAdded by the Troj/VB-XU TROJAN!
    NT securityXrundll32.comAdded by the W32/Rbot-AJC WORM!
    Notebook MaximizerUmaximizer_startup.exeToshiba Notebook Maximizer software; adjust settings to save battery power and increase efficiency
    Notepad++Unotepad++.exeRelated to Notepad , Notepad Plus-Plus is an Opensource program. It has many functions not found in Microsoft's program. Note: Located in \%Program Files%\Notepad \
    NortonAntivirusXLSASS.exeAdded by the W32.Pexmor WORM! Note: This (LSASS.exe) is not the legitimate Windows Process and has nothing to do with NortonAntivirus. The legitimate Windows Process (Lsass.exe) is found in the System32 folder and should not be seen in Msconfig or as a Startup item. This worm file is found in the Windows\Temp or Winnt\Temp folder.
    NvCplScanXwinasp.exeAdded by the FORBOT.BZ WORM!
    NoAdware3UNoAdware3NoAdware Adware/Spyware remover - initially considerered a "rogue" program - see here . Has since apparently mended its ways: see note
    NaviSearchXnls.exeeXact Advertising BargainBuddy/NaviSearch adware
    Norton UpdaterXwinset.exeAdded by a variant of the W32.SPYBOT WORM!
    ntupd32Xntupd32.exe See_Here
    nvscv32Xnvscv32.exeAdded by a variant of the W32/SDBOT WORM! Note: Located in C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K)
    NetscapeUInstallService.exeRelated to Netscape not a critical component. Note: Located in \%Program Files%\Common Files\ISPCOMP\

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer