CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    NetTimeUNETTIME.EXEFrom a visitor - "This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols, e.g. NTP."
    NetworkKeyXnetkey.exeAdded by the Troj/IRCBot-AJ TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Netzip Smart DownloaderXnpnzdad.exeAdvertising spyware
    Norton Guard 32Xntguard32.exeAdded by a variant of the WIN32.RBOT WORM!
    NTFSCLUPYNTFSCLUP.EXEPart of ConfigSafe- "checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99 % of the time it will only execute about a dozen instructions before exiting"
    NETServicesXcsxrs.exeAdded by a variant of the W32/SDBOT WORM!
    Norton Personal FirewallXlah.exeAdded by a variant of the WIN32.RBOT WORM!
    NvCplUrundll32.exe,NvCpl.dllIntializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
    NNSvcUnnsvc.exe Net Nanny internet filter
    NI.UWA6P_0001_N69M0303XWinAntiVirusPro2006Installer[1].exeWinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
    ntldrXntldr.exeBrowser hijacker to search-control.com (TrojanDropper.Win32.Small.ig). In addition to Registry changes found by HijackThis, also creates the following system files: * Creates file C:\WINDOWS\SYSTEM\ntldr.exe. * Creates file C:\m.exe. * Creates file C:\WINDOWS\Search-For-You.url. * Creates file C:\n.bat. * Deletes file c:\q.exe. * Creates file C:\q.exe. * Creates file C:\r.bat
    Norton Ghost 9.0NGhostTray.exe Norton_Ghost tray icon - the application can be launched manually
    NetAdm7XNETADM7.EXEAdded by the BANCOS.F VIRUS! Read the link, keylogger/password stealing trojan(s) involved.
    NVagentXInforme.exeAdded by the W32.Vig.C VIRUS! Note: Copies it's self to multiple Drives and folders.
    NvCplDaemonUrundll32.exe,NvCpl.dllIntializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
    NDIS AdapterXservenxpp.exeAdded by the W32/FORBOT-GP WORM!
    NAVMD25UUpdtNv28.exeRelated to Symantec_MicroDefs for updating their AV products. Though this is a legitimate file, it is unknown whether or not it needs to be running at startup. Note: located in C:\WINDOWS\UpdtNv28.exe without the /2003 if you are running NAV 2004.
    NVRTNnvrt.exeNVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports
    NAV AgentXwinsnav.vbsAdded by the W32.ANPES WORM!
    NoteBurnerUVTBurnerGUI.exeRelated to NoteBurner A M4P converter software. Note: Located in \%Program Files%\NoteBurner\
    NcaoXurpo.exe PurityScan/Clickspring Adware
    Norton Disk DoctorNNdd32.exeNorton Disk Doctor from Norton Utilities. Automatically runs at start-up, checking for disk errors. Better than ScanDisk but can be started manually via Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well
    NvCplScanXmsc32.exeAdded by the W32/FORBOT-DD WORM!
    NsvXnsvsvc.exe Delfin_Promulgate adware
    NEWDOT~1Xrundll32.exe,NewDotNetStartup,Newdot~2.exe NewDotNet Foistware
    Norton System DoctorNSysdoc32.exeNorton Disk Doctor from Norton Utilities. Automatically runs at start-up, major resource hog and best started manually form Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well
    NvCplXwindowsp.exeAdded by a variant of the W32/SDBOT WORM!
    NAVSCAN32.EXEXNAVSCAN32.exeAdded by the W32/SDBOT-DO WORM!
    Norton UpdaterXnavupdtr.exeAdded by the SDBOT.AXV WORM!
    Norton Live UpdaterXCavapsvc.exeAdded by the GAOBOT.AO WORM!
    NET protection systemXnetst.exeIdentified as the Backdoor.Rizo.A malware. Note: Located in \%WINDIR%\System32\Com\
    NotebookHardwareControlUnhc.exeRelated to Notebook_Hardware_Control controls the hardware components of your Notebook. Note: Located in C:\Program Files\Notebook Hardware Control\
    Network SecurityXNSecurity.exeAdded by the IRCBOT.AAV WORM!
    NavPassXNavPass.exeFree system for gaining access to and downloading from adult content web-sites
    Network ServiceXsvchost.exeHijacker, also detected as Win32.Omal.C Trojan.
    NTSet32Xservices.exeAdded by the Troj/WinSpy-C TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows\dll32 or Winnt\dll32 folder.
    NT ServiceXNTOKSRNL.EXEAdded by the W32/RBOT-AAG WORM!
    NvCplDaemonNrundll32.exe,NvQtwk.dll, NvCplDaemonSystem Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here)
    NTSF MICROSOFT SYSTEMXfufffy.exeAdded by the W32/Rbot-AEL Worm!
    NAMEDPIPE SYSTEMXnamedpipe.exeAdded by the W32.Mytob.LO WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    nbustrce1D?nbustrce1D.exeDevice driver, possibly CD-ROM/DVD-ROM related - what exactly is it and is it required in startup?
    NetLinkXnetlink32.exeAdded by the GAOBOT.WO WORM!
    NeroCheck.exeXNeroCheck.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This is NOT related to "Nero Burning Rom" CD writing software. Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    NetServiceXntsvc.exeAdded by the Troj/QQPass-DU TROJAN!
    netservicesXsvchostn.exeAdded by the SDBOT.GI WORM!
    nVidia DriversXnVidiaDrvers.exeAdded by the W32/Sdbot-AFX WORM!
    NECMFKYnecmfk.exeNEC wireless keyboard driver
    NSystemMonitorNSymmon.exeNorton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
    NTSF MICROSOFT SYSTEMXntssf.exeAdded by a variant of the WIN32.RBOT WORM!
    NWEReboot?dummy.exe??
    nvjxueXnvjxue.exeAdded by the W32/EYEVEG-J WORM!
    Net Activity DiagramUnad.exeNet Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start -> Programs
    NvCplDXntcpl.exe "Switch" adult content dialer
    NDrvXNDrv.exe PurityScan/Clickspring Adware
    Nod32 ServiceXnod64.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer