| Name | Status | Filename | Description |
|---|
| NAI ePolicy Orchestrator Agent (NAIMAGENT32) | L | naimas32.exe | Related to Network Associates anti-virus protection suite
http://www.liutilities.com/products/wintaskspro/processlibrary/naimas32/ |
| Nakido | L | nakido.exe | Related to Nakido file sharing software. Note: Located in \%Program Files%\Nakido\ |
| naPrdMgr | X | naPrdMgr.exe | Added by the W32/Tilebot-KX WORM! Note: located in \%WINDIR%\ Note: Use SDFix under supervision. |
| National Instruments Domain Service (NIDomainService) | L | nidmsrv.exe | Related to National_Instruments Domain Service. From National Instruments Corp, Note: Located in \%Program Files%\National Instruments\Shared\Security\ |
| National Instruments PSP Server Locator (lkClassAds) | L | lkads.exe | Related to National_Instruments Logos. Note: Located in C:\WINDOWS\system32\ |
| National Instruments Time Synchronization (lkTimeSync) | L | lktsrv.exe | Related to National_Instruments Logos. Note: Located in C:\WINDOWS\system32\ |
| National Instruments Variable Engine (NITaggerService) | L | tagsrv.exe | Related to National_Instruments Inc. Note: Located in \%Program Files%\National Instruments\Shared\ |
| NAV Alert | L | alertsvc.exe | Related to Symemtecn/Norton products |
| Navegador de red (ExpIorer) | X | ExpIorer.exe | Added by the Troj/Taladra-E
TROJAN! |
| Naver Anti-virus Realtime Monitor (Nsavsvc) | L | Nsavsvc.exe | Related to Naver_Anti-virus Realtime Monitor From NHNCorp. Note: Located in \%Program Files%\\Naver\NaverPCGreen\ |
| Naver Anti-virus Scan Service (nsvmon) | L | nsvmon.exe | Related to Naver_Anti-virus Realtime Monitor From NHNCorp. Note: Located in \%Program Files%\\Naver\NaverPCGreen\ |
| NBService | L | NBService.exe | Related to Nero Backup service. Note: Located in C:\Program Files\Nero\Nero 7\Nero BackItUp\ |
| NDAS Service (ndassvc) | L | ndassvc.exe | Related to XIMETA Inc. Smart Network Storage Solution. |
| NDIS Adapter (NDIS TCP Layer Transport Device) | X | ndis.exe | Added by the W32/Forbot-AX
WORM!
Note: This worm file is found in the System32 folder.
|
| NdisFilter | X | ndisfilter.sys | Troj/NetAtk-F |
| ndserv | | ndserv.exe | Related to NetDeploy_Launcher from Open Software Associates Ldt. a division of Managesoft.com Note: Located in C:\Program Files\netDeploy\Launcher\ |
| Neokernel Web Server (nkservice) | L | nkservice.exe | Related to Neokernel_Web_Server a lightweight and secure ASP.NET web application server. Note: Located in \%Program Files%\cometway\neokernel\ |
| Neoteris Setup Service | L | NeoterisSetupService.exe | Related to Neoteris_Setup_Service now owned by Juniper.net. Note: Located in \%Program Files%\Neoteris\Installer Service\ |
| Nero Registry InCD Service (NeroRegInCDSrv) | L | NBHRegInCDSrv.exe | Related to Nero suite lets you organize your multimedia projects easily, helping you get the most from your digital content! Note: Located in \%Program Files%\Nero\Nero8\InCD\ |
| neruo.exe (NeroFilterCheck) | X | Explore.exe | Added by the SDBOT.DIH
WORM!
Read the link, rootkit type stealth involved.
|
| Net Agent | X | dls0523pmw.exe | Added by the Trojan.Downloader-Gen/BasicMath.Process TROJAN
Note: This trojan is located in C:\%WINDIR%\ |
| Net Boot Service | X | big5_gb2312.exe | Detected as W32.Agobot-TU
Note: Located in WINDOWS\system32 |
| Net Functions Library (Netlib) | X | Netlib.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C: folder. |
| Net Functions Monitoring (Netmon) | X | Netmon.exe | Added by the W32/Codbot-R
WORM! |
| Net Logon (Netlogon) | L | lsass.exe | Related to the Net_Logon service. Uused to authenticate a user into a domain. Note: Located in C:\%WINDIR%\System32\ |
| Net message Service | X | netmsg.exe | Added by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Net Modulation (kilomang) | X | netmodulr.exe | Identified as Trojan.DownLoader.36024 Note: Located in \%WINDIR%\System32\ |
| Net Service Monitor | X | netsvc.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: Located in C:\WINDOWS\ Note] Netsvc.exe: This tool provides a way to remotely start, stop, and query the status of services from the command line. But is not run as a SERVICE. Here |
| NetBackup Client Service (NetBackup INET Daemon) | L | bpinetd.exe | Related to VERITAS NetBackup Enterprise Server. |
| NetBackup Volume Manager | L | bevmd.exe | Related to VERITAS NetBackup Enterprise Server. |
| NetBIOS Helper | X | nbthlp.exe | Added by the W32.Toxbot.AL
WORM!
Note: Symantec has developed a removal tool to clean the infections of W32.Toxbot.AL, to download it Click_Here
|
| netbios helper service | X | altsvc.exe | adserver adtech.de redirects |
| NetBIOS Helper Service (NetBIOS Helper) | X | nbthlp.exe | Added by the W32/Codbot-AE
WORM!
Note: This worm\trojan file is found in the System32 folder.
|
| NetBTD(ntbtd) (NetBTD) | X | netbtd.exe | Added by W32/Sdbot-BLW WORM! Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| NetCN | X | netcn.sys | Added by the Hacktool.Rootkit
TROJAN!
Read the link, rootkit type stealth involved.
|
| NetCom3 Service (Netcom3) | X | PSCMonitor.exe | Netcom3 Cleaner, rated as adware by sophos |
| NetconDDE Service (NetconDDE) | X | iisctrl.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. |
| netconf32 (netconf32) | X | netconf32.exe | Added by the W32/Tilebot-BN
WORM!
Note: This worm\trojan file is found in the Windows or Winnt folder.
|
| netctrl | X | sys.dll | Troj/Singu-AR Read the link, allows remote access |
| netctrol | X | sysi.dll | Troj/Singu-BB
|
| NetDDE Server (NetDDEsrv) | X | netddesrv.exe | Added by the W32/Codbot-Y
WORM!
Note: This worm\trojan file is found in the System32 folder.
|
| NetDDEipx (NetDDEipx) | X | random | Added by the NetDDEipx TROJAN! **note 3ylv.exe may be one of the random file names used
|
| NetDetect | X | netdtect.sys | Troj/Pushu-Gen
Note: Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K) May also have an additional services installed. Read link |
| Netgear Wireless Domain Login Service (NWDLS) | L | NWDLS.exe | Related to Netgear_Wireless_Domain Login Service. Note: Located in \%WINDIR%\System32\ |
| Netgear WN311B Wireless Control Service (WN311BFCS) | L | WN311BFCS.exe | Related to WN311B Wireless Control Service. Note: Located in \%WINDIR%\System32\ |
| Netgroup Packet Filter (NPF) | X | npf.sys | W32/Rbot-GSI
Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K) |
| NetGroup Packet Filter Driver (NPF) | X | npf.sys | Troj/Delf-EQE Note: Located in %windir%\system32\drivers |
| Neth | X | netid.exe | Added by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Netilla SSL Tunnel Helper Service (NetillaVPNService) | L | NVPNs.exe | Related to Netilla_SSL Tunnel Helper Service. Policy Networking ties network and application access to identity and policy. Note: located in \%WINDIR%\ |
| NETINFO | X | netinfo.exe | Added by the W32/Tilebot-J
WORM!
Read the link, rootkit type stealth involved.
|
| NetLimiter (nlsvc) | L | nlsvc.exe | NetLimiter_2 shows list of all applications communicating over network. |
| NetLogon | X | svchost.exe -k NetLogon | Added by the Fuwudoor TROJAN! |
| NetLogon P2P (NFOSVC) | X | nfosvc.exe | Added by a variant of the SdBot.aad family of worms and IRC backdoor Trojans. Note: This trojan is located in C:\WINDOWS\AppPatch\ |
| NetM (Ne) | X | win32udt.exe | Added by a variant of the SDBOT.CZD family of trojan. Note: This trojan is located in C:\%WINDIR%\ |
| Netman | X | Netserv.dll | Troj/Protux-E |
NetOp Helper ver. 7.50 (2002343) (NetOp Host for NT Service) | L | NHOSTSVC.EXE | Related to Danware NetOp products Note: Located in C:\Program Files\Danware Data\NetOp Remote Control\HOST\ |
NetOp Helper ver. 7.65 (2004242) (NetOp Host for NT Service) | L | NHOSTSWC.EXE | Related to Danware NetOp products |
| Netropa NHK Server | L | Nhksrv.exe | nhksrv.exe is a process that belongs to DELL and Compaq systems. It is used to halt any configured hotkeys while the screensaver is running. |
| Netropa NHK Server (nhksrv) | L | nhksrv.exe | Netropa Hotkey Server task seen only on DELL and Compaq PCs running Windows NT4/2000/XP |
| Netscape Update Service (NCUpdateSvc) | L | ncupdatesvc.exe | Netscape Communications Corporation updater |
| NetSendServer (NetSendServer) | X | NetSend.exe | Added by the Troj/Hupigon-DQ
TROJAN!
Note: This trojan file is found in the Windows or Winnt folder.
|
| netservice (DDMP) | X | netservice.exe | Troj/Delf-EXQ
Note: Located in %User%\Favorites\ Turns off anti-virus applications
Allows others to access the computer |
| NetSign AutoUpdate Service (NsAUSvc) | L | NsAUSvc.exe | Related to SecurityFocus - http://www.securityfocus.com/ |
| nettoservice | X | time.exe | W32/Otamyu-A
Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
Leaves non-infected files on computer |
| NetVeda Safety.Net (ipcSvc) | L | ipcsvc.exe | Related to Safety_net from Netveda. Security and advanced Internet firewall protection for all your LAN computers. |
| Network | ? | nettcp.exe | Unknown owner: Location C:\WINDOWS\system32\nettcp.exe |
| Network ADSL Server (Network ADSL Server) | X | woaisaomm.exe | Added by the Troj/GrayBrd-AQ
TROJAN!
Note: This trojan file is found in the System32 folder.
|
| Network Associates McShield (McShield) | L | Mcshield.exe | Related to McAfee_Virus_Shield Note: Located in \%Program Files%\Network Associates\VIRUSSCAN\ |
| Network Associates Task Manager (McTaskManager) | L | VsTskMgr.exe | Related to Network Associates Virus protection software. |
| Network Client (nwclntg) | X | winlogon.exe | Added by the Boxed.E TROJAN! |
| Network Confg System | X | lviss.exe | WORM_SDBOT.AXG Read the link, allows remote access |
| Network Configuration Service (NetCfgSvr) | L | NetCfgSv.EXE | Related to AT&T
http://www.anti-spy.info/process/netcfgsv.exe.html |
| Network Connections Sharing (RpcTftpd) | X | svchost.exe | Added by the W32.Welchia WORM! **Note - This service will be set to start manually |
| Network DDE Client (NetDDEclnt) | X | netddeclnt.exe | Added by the W32/Codbot-M
WORM!
|
| Network dde connections | X | service.exe | adtech.de redirections |
| Network DDE Connections (NETDDEC) | X | winmgnt.exe | Added by unknown malware, the file winmgnt.exe may be a Serv-U FTP server used to download other malicious files to your computer. File location is in the System32 folder. |
| Network DDE DSMA (NetDDEdsma) | X | svchost.exe | Added by the W32/Sdbot-BMG
WORM!
Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) This worm file is found in the Windows or Winnt folder. |
| Network DDS (NetDDS) | X | NetDDS.exe | Reported as Troj/ServU-Gen See Sophos
Unknown owner :Location: C:\WINDOWS\system32\NetDDS.exe
|
| Network Devices Controller (ndcsvc) | X | random.$$$ | Added by the Alnica TROJAN! |
| Network Devices Controller (ndcsvc) | X | random file name | Added by the Alnica TROJAN! |
Network Distributed Transaction Coordinator for Workstation (MSDCSRV32) | X | mssrv.exe | Added by the PWSteal.Drorar
TROJAN!
Note: This trojan file is found in the Program Files\Common Files\system\ado folder. |
| Network DRV (NTDRV) | X | netdrvr.exe | Added by the W32/Sdbot-AZK
WORM!
Note: This worm file is found in the System or System32 folder.
|
| Network Gateway Manager (npx) | X | csrsc.exe | Added by the W32/Sdbot-CPE WORM! Note: This worm\trojan is located in C:\%WINDIR% |
| Network helper Service (MSDisk) | X | irdvxc.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Network Location Awareness (Network Location) | X | Network.exe | Troj/Dloadr-BBE
Copies itself to %Common Files%\Microsoft Shared\MSInfo\ |
| Network Location Manager | X | lssc.exe | Added by the Trojan.Backdoor.Gen TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Network Management Center Time (W32Times) | X | TIMEMAN32.EXE | Added by the Troj/GrayBrd-AA
TROJAN!
Note: This worm\trojan file is found in the Program Files\Internet
Explorer\plugins folder. |
| Network Messenger (MStdc ) | L | mstdc.exe | Related to Microsoft Personal Web Server and Microsoft SQL Sever software
http://www.2-files.com/process/microsoft-distributed-transaction-coordinator |
| Network Monitor | X | netmon.exe | Reported by Panda as the Trj/Cicos.H TROJAN! This trojan if found in the \Program Files\Network Monitor\ folder. Note: This is not the legitimate Microsoft Network Monitor (Netmon.exe) process which is legitimate to capture network traffic. Article_Q812953 |
| Network Provision Managing Service (xmlprovman) | X | provsvc.exe | Added by the W32/Sdbot-CRS WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Network Security Service | X | random | CoolWebSearch res:// variant |
| Network Security Service (NSS) | X | random | CoolWebSearch res:// variant |
| Network Security Service (__NS_Service_3) | X | sdkbj32.exe | Detected as Trojan.Agent.bi by ewido(now known as AVG-antispyware) |
| Network Source Engine (NSEsvc) | X | nsecvc.exe | Identified by Bitdefender as Trojan.Peed.Gen Note: located in \%WINDIR%\Help\ |
| Network Station Task Manager (TASKSQ) | X | tasksch.exe | Added by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ |
| Network Station Task Manager (TSKIB) | X | taskib.exe | Added by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ |
| Network Switching Alerter | X | windlls.exe | Probable variant of W32/Rbot-AZQ |
| Network System (NetSystem) | X | NetSystem.exe | Troj/QQRob-ADE Read the link, steals information |
| Network System Logon (NSLSVC) | X | netmsvc.exe | Added by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\Cursors\ |
| Network Translation System Service (NTSS) | X | ntss.exe | Added by the Backdoor.Unpdoor backdoor Trojan. A Trojan horse that opens a random port and connects to a remote Web site. Note: located in \%WINDIR%\System32\ |
| NetWorker Power Monitor (nsrpm) | L | nsrpm.exe | Related to NetWorker_Power Monitor from LEGATO Software. Note: Located in \%Program Files%\nsr\bin\ |
| NetWorker Remote Exec Service (nsrexecd) | L | nsrexecd.exe | Related to NetWorker_Remote Exec Service from LEGATO Software. Note: Located in \%Program Files%\nsr\bin\ |
| NetWorkLogon | X | KB8964225.log | Troj/Lmir-FF Note: Located in %windir%\system32 Read the link, steals information |
| NI Configuration Manager (mxssvr) | L | nimxs.exe | Related to NI_Configuration_Manager from National Instruments Corp. Note: Located in \%Program Files%\National Instruments\MAX\ |
| NI Service Locator (niSvcLoc) | L | niSvcLoc.exe | Related to National_Instruments corp. |
| Nicrosoft f11nt | X | vvvhost.exe | Added by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\system32\dllcache\ |
| NICSer_G200v2 | L | NICServ.exe | Related to Linksys config utility. |
| NICSer_WMP11 | L | NICServ.exe | Related to Linksys config utility. |
| NICSer_WPC54G | L | NICServ.exe | Related to Linksys config utility. Note: Located in \%Program Files%\Linksys\Wireless-G Notebook Adapter\ |
| nidevldu | L | nipalsm.exe | Related to National_Instruments Inc. Note: Located in \%WINDIR%\System32\ |
| NILM License Manager | L | lmgrd.exe | Related to the Macrovision License Manager. |
| NinjaVideo Helper (NinjaVideo Helper.exe) | L | NinjaVideo Helper.exe | Related to NinjaVideo_Helper is required in order to view videos on NinjaVideo.net. Note: Located in \%Program Files%\NinjaVideo\NinjaVideo Helper\ |
| ninsvc | X | ninsvc.exe | Added by the W32/Akbot-AL WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Modifies the HOSTS file |
| nipxirmu | L | nipalsm.exe | Related to National_Instrument Corp. |
| NkPtpEnumP2 | L | NkPtpEnum.exe | Related to Nikon Wireless Camera Setup utility. Note: Located in \%Program Files%\Nikon\Wireless Camera Setup Utility\ |
| NMap | L | nmapserv.exe | NMapWin Port Scanner utility service. |
| NMIndexingService | L | NMIndexingService.exe | Part of a Nero product |
| NMSAccess | L | NMSAccess.exe | Related to Cheetah_DVD_Burner Note Must only be used on NT4/2000/XP |
| NMSAccessU | L | NMSAccessU.exe | Related to CDBurnerXP a free application to burn CDs and DVDs. Note: Located in \%Program Files%\CDBurnerXP\ |
| nMtskBar Service (nMtskService) | ? | nMtsk.exe | Taskbar control for ISDN NetMod modem |
| NMU Emergency Broadcast System (nmuebs) | L | nmuebs.exe | Related to Northern_Michigan_University On-line services. Note: Located in \%ROOT%\nmutools\ |
| NNServ | X | nnrun.exe | Added by NewDotNet AdWare! Note: Located in C:\Program Files\NewDotNet\ |
| NNSvc | L | nnsvc.exe | NetNanny Internet Filter |
| NobleNet Portmapper for TCP | L | portserv.exe | Actuate_Enterprise Reporting Applications for business intelligence analytic services |
| NOD AV service (nodantivir) | X | nodantivir.sys | Added by the Troj/Haxdoor-AK
TROJAN!
Note: This trojan file is found in the System32 folder. The file nodantivir.sys provides stealthing functionality. |
| NOD32 Kernel Service (NOD32krn) | L | nod32krn.exe | NOD32 Antivirus |
| Nofeel FTP Server Service | L | nftpdsvc.exe | Related to Nofeel_FTP_Server |
| NoIPDUCService | L | DUC20.exe | Related to Vitalwerks Internet Solutions |
| Norman API-hooking helper (NipSvc) | L | nipsvc.exe | Norman Anti-Virus |
| Norman eLogger service 6 (eLoggerSvc6) | L | ELOGSVC.EXE | Related to Norman_eLogger Internet Control. Note: Located in \%ROOT%\Norman\Npm\bin\ |
| Norman NJeeves | L | NJEEVES.EXE | Norman Anti Virus |
| Norman Type-R | L | NPFSVICE.EXE | Norman Virus Control Service. Made by Norman Data Defense Systems, Inc.
For more information Click_Here
File is located in the Norman\Nvc\BIN folder. |
| Norman Virus Control on-access component (nvcoas) | L | nvcoas.exe | Norman Virus Control on-access component |
| Norman Virus Control Scheduler (NVCScheduler) | L | NVCSCHED.EXE | Norman Virus Control Scheduler |
| Norman ZANDA | L | Zanda.exe | Norman Anti Virus |
| Nortel CVC Service (NvcRpcServer) | L | NvcRpcSvr.exe | Related to Nortel_CVC Service. Service - VNP Client. Note: Located in \%Program Files%\Nortel Networks\ |
| Nortel Networks i2050 QoS Service (i2050QoSSvc) | L | i2050QosSvc.exe | Related to Networks_IP_Softphone from Nortel Note: located in \%WINDIR%\system32\ |
| Nortel Networks TunnelGuard (tunnelguardservice) | L | CueAgent_srv.exe | Related to Nortel_Networks_TunnelGuard designed to ease the deployment of very large site-to-site and remote access Virtual Private Networks (VPNs). Note: Located in C:\Program Files\Nortel Networks\TunnelGuard\ |
| Norton antivirus and Firewall (it) | X | fime.exe | Bogus Norton Antivirus and Firewall service.
Unknown owner.
|
| Norton AntiVirus Auto Protect Service (navapsvc) | L | navapsvc.exe | Related to Norton/Symantec AntiVirus. |
| Norton AntiVirus Auto-Protect Service (navapsvc) | L | navapsvc.exe | Related to Norton/Symantec AntiVirus. |
| Norton AntiVirus Auto-Protect-Dienst (navapsvc) | L | navapsvc.exe | Related to Norton/Symantec AntiVirus. |
| Norton AntiVirus Auto-Protect-service (navapsvc) | L | navapsvc.exe | Related to Norton/Symantec AntiVirus. |
| Norton AntiVirus Client (Norton AntiVirus Server) | L | rtvscan.exe | Norton Anti-virus related |
| Norton AntiVirus Firewall Monitor Service (NPFMntor) | L | NPFMntor.exe | Norton Internet Worm Protection |
| Norton Ghost | L | PQV2iSvc.exe | symantec Norton Ghost Image related |
| Norton Ghost | L | VProSvc.exe | Related to symantec Norton Ghost Image. Note: Located in \%Program Files%\Norton Ghost\Agent\ |
| Norton Internet Security Accounts Manager (NISUM) | L | NISUM.EXE | Related to Norton Internet Security |
Norton Internet Security Professional Accounts Manager (NISUM) | L | NISUM.EXE | Related to Norton Internet Security |
| Norton Internet Security Proxy Service (SymProxySvc) | L | SymProxySvc.exe | Related to Symantec Corporation |
| Norton Internet Security Service | L | NISSERV.EXE | Related Symantec Corporation |
| Norton Online Anti Virus | X | avll32.exe | Added by the Backdoor.Win32.SdBot.aad reported by Kaspersky TROJAN! Note: This worm\trojan is located in C:\%WINDIR% |
| Norton Personal Firewall Proxy Service | L | SymProxySvc.exe | Related to Norton Firewall Proxy service |
| Norton Personal Firewall Service | L | NISSERV.EXE | Related to Norton Personal Firewall service |
| Norton Program Scheduler | L | npssvc.exe | Related to Norton Scheculer |
| Norton Protection Center Service (NSCService) | L | NSCSRVCE.EXE | Related to Norton Internet Security 2006 and Norton AntiVirus 2006. Made by Symantec_Corporation
|
| Norton Save and Restore | L | VProSvc.exe | Related to Symantec Norton Ghost Note: Located in C:\Program Files\Norton Save and Restore\Agent\ |
| Norton UnErase Protection (NProtectService) | L | NPROTECT.EXE | Norton Protected Recycle Bin |
| Notebook Manager Service (anbmService) | L | anbmServ.exe | Related to Acer Notebooks Hardware Monitoring program. Made by OSA_Technologies
Inc.
|
Notebook Performance Tuning Service (TempoMonitoringService) | L | TempoSVC.exe | Related to Toshiba_TEMPO It will advise you on how to fine-tune the performance of your notebook and keep you informed of the latest Toshiba software and driver updates as soon as they are released. Note: Located in \%Program Files%\Toshiba TEMPO\ |
| NOTEPAD | X | notepad.exe | W32/Sdbot-DHU
Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K)
Allows others to access the computer |
| Novell Application Launcher (NALNTSERVICE) | L | NALNTSRV.EXE | Novell NAL NT service |
| Novell Workstation Manager (WM) | L | wm.exe | Novell Workstation Manager |
| Novell XTier Agent Services (XTAgent) | L | XTAgent.exe | Related to Novell, Inc. \%WINDIR%\System32\Novell\ |
| Novell XTier Service Manager (XTSvcMgr) | L | XTSvcMgr.exe | Related to Novell Inc. Note: Located in \%Program Files%\Novell\Client\XTier\Services\ |
| Novell ZfD Remote Management | L | ZenRem32.exe | |
Novell ZfD Wake on LAN Status Agent (Prometheus Wake-On-LAN Status Agent) | L | WolSerNT.exe | Novell ZfD Wake on LAN Status Agent |
| Now.WAP Proxy Gateway Service (WAP3GX) | L | WAP3GXNT.EXE | Related to Now.WAP_Proxy a WAP Gateway that is designed to meet the needs of WAP 2.0 and multimedia applications. Note: Located in C:\PROGRAM Files\NowWAP\ |
| NPDOR File Monitor Service (NFMService) | L | NPDORNT.exe | Related to NPD Online Research. |
| NPF | X | npf.sys | Added by the Troj/NtRootK-I
TROJAN!
Note: This trojan file is found in the System32 folder. |
| npkcmsvc | L | npkcmsvc.exe | Related to KeyCrypt Encryption Manager Service from INCA Internet Co. Note: Located in \%WINDIR%\System32\ |
| npkcsvc | L | npkcsvc.exe | INCA Internet |
| NS (MSLLR) | X | ns.exe | W32/Agobot-HS |
| NSC Agent (NSDUAgent) | L | NSCAGENT.EXE | Related to NSC_Agent service from Symantec. Note: Located in \%ROOT%\NAgent\ |
| NsEngine | L | NSENGINE.exe | Scheduling engine of NovaSTOR Backup Service |
| nservice | X | nservice.exe | Added by the W32/Agobot-AHR WORM! Note: This worm is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) Read the link, allows remote access |
| nsssvc | X | isssvc.exe | Troj/Agent-BIY Note: Located in :\Program Files\W3CS |
| NSUService | L | NSUService.exe | A network utility for Sony laptops see here Note: Located in \%Program Files%\Sony\Network Utility\ |
| NT LM Security Support Provider (NtLmSsp) | L | lsass.exe | Related to the NT_LM_Security_Support_Provider Windows NT 4.0 is responsible for handling NTLM authentication requests. Note: Located in C:\%WINDIR%\System32\ |
| NT login service (ntlogin32) | X | libsys32.exe | Added by the W32/Sdbot-ACK
WORM!
|
| NT login service - Unknown | X | libsysmgr.exe | Added by the W32/SDBOT-CAF WORM!
(Castle Cops) |
| NT Online Protection | L | ONLNSVC.EXE | Related to AntiVirus_Quick Heal Virus protection. Note: located in C:\Program Files\QUICKH~1\ |
| Nt System Kernel | X | ntsyskrnl.exe | related to WORM_AGOBOT.IK |
| NTBOOTMGR (NTBOOT) | X | ntuser.exe | Flagged as Backdoor.Iroffer / Backdoor.Noer |
| NTCHARGE | L | winlogon.exe | Related to Microsoft Internet Information Services (IIS). |
| NTFS Crypto Technology (NTFSCrypt) | X | ntfscrypt.exe | Added by the W32/Spybot-NC WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| NTFS File Location Service (NTFSFLS) | X | ntfsloc.exe | Added by the W32/Sdbot-CSG WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| NTFSprotect (ntfsdiscman) | X | ntfsprotect.exe | Added by the SDBOT.CCF
WORM!
Read the link, rootkit type stealth involved.
|
| ntldr.sys | X | ntldr.sys | Troj/SpamToo-AQ
Creates the file %Root% |
| Ntlm_Drive_Connect (Ntlm_Drive_Connect) | X | TimerU.sys | Added by the Tuimer TROJAN! |
| NTLOAD | X | ntsrv.exe | Identified as Win32.Iroffer.b by Kasperksy. Note: Located in \%WINDIR%\System32\dllcache\win32\ |
| NTLOAD | X | winlogon.exe | Other files in the same directory identified as Win32.Iroffer.b by Kaspersky |
| ntmssvc | X | svchost.exe -k ntmssvc | Added by the Fuwudoor TROJAN! |
| ntmssvc | X | SysPkOs.dll | Troj/BkDoor-A
Troj/BkDoor-A may overwrite registry entries, to enable it to run as a service.
Read link |
| NTP (Network Time Protocol) | X | winlogon.exe | Added by the Troj/Jtram-D
TROJAN!
Note: This trojan file is found in the System32\Client folder.
|
| NTRU Hybrid TSS v1.05 TCSD (tcsd_win32.exe) | L | tcsd_win32.exe | Related to NTRU_Cryptosystems Inc. Provider a public key cryptography system (PKCS) |
| NTRU Hybrid TSS v2.0.7 TCS (tcsd_win32.exe) | L | tcsd_win32.exe | Related to NTRU_Cryptosystems Inc. Provider a public key cryptography system (PKCS) Note: Located in \%Program Files%\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.7\bin\ |
| NTSec(ntsec) (NTSec) | X | ntsec.exe | Identified as Trojan-Dropper.VB.22 by VBA32 Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) This should not be confused with Keylog_Ardamax A program may have legitimate uses in contexts where an authorized administrator has knowingly installed this application. Located in %Documents and Settings% \Start Menu\Programs\Ardamax Keylogger. If you did not install this program remove it. |
| NTSecure | O | srvany1234.exe | Unknown owner: Location C:\WINDOWS\system32\srvany1234.exe |
| NTSVCMGR | X | winlogon.exe | Identified as Win32.Iroffer.b by Kasperksy. Note: Located in \%WINDIR%\System32\dllcache\win32\ Note: This is not the legitimate Windows Process which is found in \%WINDIR%\System32\ folder. |
| NTSVCMGR | X | ntsrv.exe | Identified as Win32.Iroffer.b by Kasperksy. Note: Located in \%WINDIR%\System32\dllcache\win32\ |
| NTsyslog | L | ntsyslog.exe | Related to Open_Source_Technology Group. An application logging functionality. |
| nTune Service (nTuneService) | L | nTuneService.exe | Related to NVIDIA Access Manager. Note: Located in C:\Program Files\NVIDIA Corporation\nTune\ |
| NTVDM | X | ntvdm.exe | W32/Tilebot-JZ
Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR%(XP/WinNT/2K) Used in DOS attacks, Allows others to access the computer Please read information on link |
| NuTCRACKER Kernel | L | nutkserv.exe | Related to openUTM from Fujitsu Siemens Computers |
| NuTCRACKER Service | L | nutsrv4.exe | Related to Rational Rose, MKS Toolkit for Enterprise Developers |
| NuTCRACKERService | L | nutsrv4.exe | Related to MKS from DataFocus Inc. Toolkit for Enterprise Developers. |
| NvCplScan | X | msc32.exe | Related to the W32/FORBOT-DD |
| NvCplScan | X | nvsc32.exe | another example, added by Forbot_ET. |
| Nvedavt | L | ousbehci.sys | Related to OrangeWare Corp. |
| nvidGUIv (nvidGUIv2) | X | NVIDGUIV.EXE | Added by the SDBOT.CTQ
WORM!
Read the link, rootkit type stealth involved. |
| NVIDIA Display Driver Service (NVSvc) | L | nvsvc32.exe | Related to NVIDIA drivers. |
NVIDIA Display Driver Service (Omega 1.6693) (P) (NVSvc) | L | nvsvc32.exe | Related to NVIDIA, http://www.nvidia.com/ drivers. |
| NVIDIA Display Service (NVIDIA Display Driver Service) | X | Nvds.exe | Added by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\%WINDIR%\ folder |
| NVIDIA Driver Helper Service (NVSvc) | L | nvsvc32.exe | Related to NVIDIA drivers. Note: Located in \%WINDIR%\System32\ |
| NVIDIA Driver Serviceˇˇ (NVSv ) | X | svchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ |
| Nvidia Graphic Displacement (nvideoGUI) | X | nvideogui.exe | Added by the SDBOT.CQD
WORM!
Read the link, rootkit type stealth involved.
|
| NVIDIA PVR Schedule Monitor (nvpvrmon) | L | nvpvrmon.exe | Related to NVIDIA ForceWare driver. Note: Located in C:\Program Files\NVIDIA Corporation\ForceWare\Multimedia\NVPVR\ |
| nvsec(nvsec) (NvSec) | X | nvsec.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here |
| nvsvc32.exe | X | wmisp.exe | Added by the Backdoor_Win32_SdBot_aad WORM! - Reported by KASPERSKY ON-LINE SCANNER |