| Status | Autorun name | Command | Description |
| Y | NortonAntiBot | NortonAntiBot.exe | Control Center for Norton Antibot from Symantec - which "provides advanced, real-time protection against emerging threats, including bots that are used to perpetrate identity theft and other online crimes" and "protects your PC from unauthorized access and tampering, detects and stops attempts by hackers to take remote control of your computer, and delivers extra protection against emerging 'zero-day' threats." Designed to work with existing antivirus software but now discontinued |
| X | NortonAntivirus | LSASS.exe | Added by the PEXMOR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Temp |
| X | NortonAV | norton_antivirus.exe | Added by the NETJOE TROJAN! Note - this is not the legitimate Symantec AV program |
| X | nortonav | CCUPD32.EXE | Added by an unidentified WORM or TROJAN! |
| U | NortonOnlineBackup | NOBuClient.exe | System Tray access to and notifications for Symantec's Norton Online Backup online storage utility |
| X | nortonp | nortonp.exe | Added by the JD-A TROJAN! |
| X | Nortons AV SYSTEM | scvchost.exe | Added by a variant of the RBOT WORM! |
| X | Nortons AVS Systems | arse.exe | Added by the RBOT.AWY WORM! |
| X | nortonsantivirus | ccEvtMngr.exe | Added by the HZDOOR-A TROJAN! |
| N | NortonUtilities | nu.exe | Part of version 14.* of Symantec's Norton Utilities PC tune up suite. This entry will be present if you optionally select any of the following startup options (via Administer → Settings): "Custom Scan", "Privacy Clean & Full Scan" or "Send to tray" |
| X | NortonVPlus | svchost.exe | Added by the ROAMER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | noskrnl | noskrnl.exe | Added by the PEACOMM.D TROJAN! |
| U | Notebook Maximizer | maximizer_startup.exe | Toshiba Notebook Maximizer software - adjust settings to save battery power and increase efficiency |
| U | NotebookHardwareControl | nhc.exe | "With Notebook Hardware Control you can easily control the hardware components of your Notebook" |
| ? | NotebookManager | nbm.exe | Associated with Acer notebook PCs. What does it do and is it required? |
| N | NoteBurner | VTBurnerGUI.exe | NoteBurner from NoteBurner Inc. - "a versatile music converter that can be used as MP3 music converter, AAC audio converter, WAV to MP3 converter, M4A to MP3 converter, and RM to MP3 converter" |
| X | NotePad | [worm filename] | Added by the SILLYFDC-G WORM! |
| X | Notepad | ntoepad.exe | Added by the DELBOT-AK WORM! |
| X | notepad | rundll32.exe notepad.dll,_IWMPEvents@0 | Added by the OPACHKI.A TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "notepad.dll" file is found in %System% |
| X | notepad | rundll32.exe ntload.dll,_IWMPEvents@0 | Added by the OPACHKI.A TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ntload.dll" file is found in %UserProfile% |
| X | notepad | rundll32.exe notepad.dll,_NtLoad@0 | Added by the AGENT-NJZ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "notepad.dll" file is found in %System% |
| X | Notepad lptt01 | notepad.exe | RapidBlaster variant (in a "windows" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not Windows Notepad which has the same executable name |
| X | Notepad ml097e | notepad.exe | RapidBlaster variant (in a "windows" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not Windows Notepad which has the same executable name |
| X | notepad.exe | upx.exe | Added by a variant of the AGENT.AH TROJAN! |
| X | notepad.exe | msmsgs.exe | Added by the ZLOB TROJAN and variants! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger |
| X | notepad2.exe | popuper.exe | Added by the PUPER-E TROJAN! |
| X | notes | notepaad.exe | Added by the RBOT.BME WORM! |
| X | notes | notes.exe | Added by the SYKIPOT BACKDOOR! |
| X | NotFaut | flxper.exe | Added by the SDBOT-AGZ WORM! |
| U | NoticeP.exe | NoticeP.exe | Part of iSync which allows "you to transfer songs from any music downloading software to your iTunes® library". The trial version displays advertisements which disappear if you purchase the software |
| X | Notification Utility | altpayV2.exe | AltPay adware |
| X | Notn | Eber.exe | PurityScan adware |
| X | Notn | wtta.exe | PurityScan adware |
| U | NovaBackup * Tray Control | NbkCtrl.exe | Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version number |
| ? | NovaPortal Single User Service | NPSU.exe | ?? |
| U | NovastorSchedulerd | SCHENGD.EXE | NovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it |
| X | novavapp | ccsmn.exe | Sysinternals Antivirus rogue security software - not recommended, removal instructions here |
| X | novavappr | ccsrr.exe | Sysinternals Antivirus rogue security software - not recommended, removal instructions here |
| X | novsvida.exe | novsvida.exe | GlobalAccess dialer |
| X | NoWayVirus | pgs.exe | NoWayVirus rogue security software - not recommended, removal instructions here. A member of the AVSystemCare family |
| N | Nowe Gadu-Gadu | gg.exe | Polish language Instant Messaging client |
| X | NOYPI_KANG_ASTIG | Exit to DosPrompt.pif | Added by the FILUKIN.A WORM! |
| X | np | upnp.exe | Added by the YABE.AE TROJAN! |
| U | NPDTray | NPDTray.exe | System Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and mulitple display options. Scheme selection and settings are also available via Fn+F7 key combination on some models |
| X | NPF Value | NPFMONTR.exe | Added by the RBOT-AWD WORM! |
| Y | NPFMonitor | NPFMntor.exe | Norton AntiVirus Firewall Install Monitor. Helps Norton AntiVirus detect immediately after boot-up whether the Personal Firewall part is currently installed and working properly, whether it is currently enabled or disabled, and what features of the firewall are turned on. Loads via a registry "RunServices" key in 98/Me and as a service in XP |
| X | npkmnc | npkmnc.exe | WebVia adware |
| U | NPROTECT | NPROTECT.EXE | Supports the Norton Protected Recycled Bin feature of older versions of Norton Utilities (either as a standalone product or as part of Norton SystemWorks). Adds an extra layer of safety to the deletion of information from the standard Windows Recycled Bin. Loads via the registry "Run" or "RunServices" keys in 98/Me and as a service in XP |
| ? | NPS Event Checker | npscheck.exe | Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event Checker |
| N | NPSAgent | NPSAgent.exe | Installed with the SAMSUNG New PC Studio mobile device management utility. Detects when a supported mobile device is connection and optionally automatically loads the main program |
| X | NS | ns.exe | Added by the AGOBOT-HS WORM! |
| X | NSCheck | nscheck.exe | MarketScore parasite - ActiveX control used to download premium-rate diallers |
| X | nscntrl | nscntrl.exe | Added by the DLOAD-DC TROJAN! |
| X | nsdcmd services | nsdcmdav.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | nsdcmd vid process | nsdcmdwin.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | nsdlua | nsdlua.exe | All-In-One Telcom - adult content dialler |
| X | nsdriver | nssys32.exe | NetShagg adware |
| X | nse | nse.exe | Added by the AGOBOT-ML WORM! |
| U | Nsengine | Nsengine.exe | Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here |
| U | NSHelper | aexnsinstallhelper.exe | Altiris Express Notification Server Install helper - monitors integrity of the installation |
| U | NSK | NSK.exe | Ardakey keystroke logger/monitoring program - remove unless you installed it yourself! |
| U | NSRKey | NSRTray.exe | System Tray access to and notifications for Symantec's Norton Save and Restore 1.0 backup software (either as a standalone product or as part of Norton SystemWorks Premier) - which is a renamed version of Norton Ghost |
| U | NSRTray | NSRTray.exe | System Tray access to and notifications for Symantec's Norton Save and Restore 1.0 backup software (either as a standalone product or as part of Norton SystemWorks Premier) - which is a renamed version of Norton Ghost |
| X | nssysconf | [random filename] | Added by the VIVIA.A TROJAN! |
| X | nstat | netstat.exe | Adult content dialler |
| Y | nsu_ui_client | nsu_ui_client.exe | Utility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devices |
| Y | nsu_ui_client.exe | nsu_ui_client.exe | Utility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devices |
| X | NSupdate | NSupdate.exe | Added by the Dial/Laet-B premium rate dialer! |
| X | Nsv | nsvsvc.exe | Delfin PromulGate adware |
| X | nsvcin | n20050308.exe | Delfin Media Viewer adware related |
| X | Nsvdr | nsvdr.exe | Adult content dialler |
| U | NSWCfg.exe | NSWCfg.exe | Information wizard for older versions of Symantec's now discontinued Norton SystemWorks system utility suite. On the first run after installation this entry looks after registration, subscription and confirms the default configuration settings |
| U | NSWosCheck | osCheck.exe | Part of Symantec's now discontinued Norton SystemWorks security and utility suite. Checks at boot-time to see if you are still using the same OS as your last Windows session and terminates if you are. If Windows has been upgraded it will attempt to download the relevant updates for the new OS on the first reboot |
| N | NswUiTray | NswUiTray.exe | System Tray access to Symantec's now discontinued Norton SystemWorks 2009 security and utility suite |
| U | nsys | nsys.exe | NetSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | nsys32 | nsys32.exe | Added by the AGOBOT-SU WORM! |
| X | nsysconf | [7 random letters].exe | ZioCom.C adware |
| N | NSystemMonitor | Symmon.exe | Norton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging |
| N | NT Kernel Patch | ntkrnlpt.exe | FaxServe network fax software |
| X | NT LM Security Support Provider | WinNTLM.exe | Added by a variant of the SDBOT WORM! |
| X | NT Logging Service | Syslog32.exe | Added by the DONK.B WORM and variants! |
| X | NT Logging Service | cool.exe | Added by the SDBOT-OO BACKDOOR! |
| X | NT Logging Service | sysmgr.exe | Added by the SDBOT-OO BACKDOOR! |
| X | NT MICROSOFT SVCD | ntvsvcd.exe | Added by a variant of the RBOT WORM! |
| X | NT Printing Service | spoolsc.exe | Added by the BUZUS-K WORM! |
| X | NT Printing Service | chkdsks.exe | Added by the ARCHIVARIUS series of WORMS! |
| X | NT Printing Service | chkdskss.exe | Added by the ARCHIVARIUS series of WORMS! |
| X | NT Printing Services | chkdsks.exe | Added by the BUZUS-M TROJAN! |
| X | NT security | rundll32.com | Added by the RBOT-AJC WORM! |
| X | NT Service | NTOKSRNL.EXE | Added by the RBOT-AAG WORM! |
| X | NT Services | ntsvc.exe | Added by the AGOBOT.VJ WORM! |
| X | Nt System Kernel | ntsyskrnl.exe | Added by the AGOBOT.IK WORM! |
| X | Nt System Protocol | ntsystem.exe | Added by the RBOT.DSB BACKDOOR! |
| X | NT Video API32 | NTAPI32.exe | Added by the RBOT-FW WORM! |
| X | NT Virtual Machine | [path to file] | Added by the SCAERBOT-A WORM! |
| X | NT Windows System Manager Loader | csrlss.exe | Added by the AGOBOT.OX WORM! |
| X | Nt**.exe [* = random char] | Nt**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Nt**32.exe [* = random char] | Nt**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | NT-Virtual Device Manager | ntvdmn.exe | Added by the SDBOT-AAA WORM! |
| X | NT_Authority | lsass.exe | Added by the KUKOO-A WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% |