| Status | Autorun name | Command | Description |
| X | NT_Authority | smss.exe | Added by the SILLYFDC-EY WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% |
| X | NT_Authority | svchost.exe | Added by the KUKOO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% |
| X | Ntcheck | mapserver.exe | Added by the TOMPAI-B WORM! |
| X | NTCommLib3 | [path to trojan] | Added by the AGENT-AXB TROJAN! |
| X | ntddetect | ntddetect.exe | Added by the AGENT-CU TROJAN! |
| X | NTdhcp | NTdhcp.exe | Added by the QQROB-C TROJAN! |
| X | NTdhcp | CiKewl.exe | Added by the QQROB-N TROJAN! |
| X | ntdll | ntdll.exe | Added by the BIONET.404 TROJAN! |
| X | ntdll.dll | TrustCleaner.exe | Trust Cleaner rogue security software - not recommended |
| X | NTDLM | csrss.exe | Added by the HALE TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Qossrv" subfolder |
| X | Ntech.patchs | [trojan filename] | Added by the LEMIR.G TROJAN! |
| X | ntechin | n20050308.exe | Delfin Media Viewer adware related |
| X | nternet Explorer | iexplore.exe | Added by the FORBOT-CT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | NTFS16 | ntfs16.exe | Added by the RBOT-LY WORM! |
| Y | NTFSCLUP | NTFSCLUP.EXE | Part of ConfigSafe- "checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99+% of the time it will only execute about a dozen instructions before exiting" |
| X | ntfsmonitorpro | ntfs64.exe | Added by the FORBOT-EB WORM! |
| X | NTFSS Microsoft System | filees.exe | Added by the RBOT.GAB WORM! |
| X | NTFSS MICROSOFT SYSTEM | filess.exe | Added by the RBOT.AXZ WORM! |
| X | ntfyapp | ntfyapp.exe | Added by the ZHELATIN WORM! |
| U | NTI Backup NOW! Scheduler | Schdlr32.exe | Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled, this entry places an icon in the System Tray and will automatically load the main program and execute the backup at the set time - as long as the backup media is present |
| Y | ntl Netguard | RPS.exe | Main program for the ntl Netguard internet security package for NTL ISP customers - sourced by Radialpoint. Now superseded by Virgin Media Security - which is also sourced by Radialpoint |
| X | ntldr | ntldr.exe | Browser hijacker re-directing to search-control.com. In addition to the registry changes found by HijackThis it also creates the following system files: %System%\ntldr.exe, C:\m.exe, %Windir%\Search-For-You.url, C:\n.bat, C:\q.exe and C:\r.bat |
| N | ntlfreedom | rundll32 [path] RyDial.dll, QuickStart | NTL Freedom dial-up ISP software - not required |
| X | NTmessageSystem | loadnewmessage.exe | Added by the HIDAGENT-B WORM! |
| X | ntmsevt | ntmsevt.exe | Added by the STOPED-B TROJAN |
| X | ntokrnl | ntokrnl.exe | Added by the BANKER.AWA TROJAN! |
| X | NTP Server | [path to trojan] | Added by the RANKY.F TROJAN! |
| Y | nTrayFw | ntrayfw.exe | System Tray access to the NVIDIA ActiveArmor hardware-optimized firewall built into some older nForce 3 and 4 series motherboard chipsets |
| N | NTrtc | ntrtc.exe | Dell year 2000 tool to deal with non-standard applications. Only required on older Dell PCs that may need this support |
| X | NTSet32 | services.exe | Added by the WINSPY-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dll32 |
| X | NTSF Microsoft System | fylez.exe | Added by a variant of the RBOT WORM! |
| X | NTSF MICROSOFT SYSTEM | wntsf.exe | Added by the RBOT.ATC WORM! |
| X | NTSF MICROSOFT SYSTEM | fufffy.exe | Added by the RBOT-AEL WORM! |
| X | NTSF MICROSOFT SYSTEM | ntssf.exe | Added by a variant of the RBOT WORM! |
| X | NTSF MICROSOFT SYSTEM | scvhost.exe | Added by a variant of the RBOT WORM! |
| X | NTSF MICROSOFT SYSTEM | winsis32.exe | Added by a variant of the RBOT WORM! |
| X | NTSF MICROSOFT SYSTEM | marya.exe | Added by the RBOT-AXY WORM! |
| X | NTSF MICROSOFT SYSTEM | sysman.exe | Added by the RBOT.EDP WORM! |
| X | ntsmod | ntsmod.exe | Adware downloader/installer, probably VX2/Look2Me related - also detected as the WIN32.VB.RL TROJAN! |
| X | NTsocket | NoeWinnt.exe | Added by the ATAKA-E TROJAN! |
| X | NTSpool | NTSpool.exe | Added by the AGENT-GPY TROJAN! |
| X | NTsrv.exe | NTsrv.exe | Added by a variant of the SERVU-O TROJAN! |
| X | Ntsysv | ntsysv.exe | Added by the MIFENG-E TROJAN! |
| U | nTune | nTune.exe | Older version of the NVIDIA nTune utilty for monitoring and modifying the settings (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards from within Windows. Now part of NVIDIA System Tools |
| U | nTuneCmd | nTuneCmd.exe | Now part of NVIDIA System Tools under the "Peformance" tag. NVIDIA nTune is utilty for monitoring and modifying the settings (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards from within Windows. Until version 6.01 (when System Tools was released) graphics settings weren't retained in a profile but now they are. From version 6.05, nTuneCmd is no longer loaded via the registry "Run" keys but instead runs via the Performance Service (nTuneService.exe) |
| X | ntupd32 | ntupd32.exe | Unidentified malware - see here |
| X | ntupdate | dnsvc.exe | Added by the SDBOT-TC WORM! |
| X | NTupdater | [path to trojan] | Added by the DIGARIX-D TROJAN! |
| X | ntuser | ctfmun.exe | Added by the SILLYFDC WORM! |
| X | ntuser | ntuser.exe | Added by an unidentified TROJAN! See here |
| X | ntuser | spool.exe | Added by the DLOADER.DYA TROJAN! |
| X | ntuser | spools.exe | Added by the AGENT-GRO TROJAN! |
| X | ntuser | svchost.exe | Added by the POLYCRYP.DY TROJAN! |
| X | ntuser | ctfmon.exe | Added by the AGENT-GSG TROJAN! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %UserProfile% |
| U | NTVDM | NTVDM.EXE | Windows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS's (Windows NT, 2K and XP). Required if hardware on a machine with these OS's needs 16-bit DOS drivers. You can find a bit more about NTVDM here |
| X | ntvdmd | ntvdmd.exe | Adware downloader - also detected as the DLOADER-YP TROJAN! |
| X | ntvdscm | ntvdscm.exe | Added by the SCKEYLOG-I TROJAN! |
| X | ntx32 | ntx32.exe | Added by an unidentified WORM or TROJAN! |
| X | ntxp2 | ntxp2.exe | Added by the VB-API TROJAN! |
| N | nu | nu.exe | Part of version 14.* of Symantec's Norton Utilities PC tune up suite. This entry will be present if you optionally select any of the following startup options (via Administer → Settings): "Custom Scan", "Privacy Clean & Full Scan" or "Send to tray" |
| U | NUAgentInstallPath | NU_Install.exe | Installer associated with Chily Employee Activity Monitoring surveillance software. Uninstall this software unless you put it there yourself |
| N | Nuance OmniPage 17-reminder | Ereg.exe Ereg.ini | Registration reminder for Ominpage version 17 from Nuance |
| N | Nuance PDF Create! 5-reminder | Ereg.exe Ereg.ini | Registration reminder for PDF Create version 5 from Nuance |
| N | Nuance PDF Professional 6-reminder | Ereg.exe Ereg.ini | Registration reminder for PDF Converter Professional version 6 from Nuance |
| N | Nuance PDF Professional5-reminder | Ereg.exe Ereg.ini | Registration reminder for PDF Converter Professional version 5 from Nuance |
| X | NumberOneMP3 | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | Numerical Xterm Agent | 0x32.exe | Added by the RBOT-FWP WORM! |
| X | Numerical Xterm Agents | 2x32.exe | Added by the RBOT-FWY WORM! |
| X | Numerical Xtermz Agent | 1x32.exe | Added by the RBOT-FWX WORM! |
| X | NumLock | runme.exe | Added by the DELF-IO WORM! |
| U | NUSB3MON | nusb3mon.exe | Included with external USB 3.0 hard drives based upon NEC's µPD720200 controller (and maybe others in the future) such as the Western Digital My Book 3.0 range. Disabling it does not appear to cause a problem - but it may be required to achieve full USB 3.0 transfer speeds |
| Y | NuTCSetupEnviron | ncoeenv.exe | Used by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows, so disabling this would be unwise if you are using NuTCracker or any 3rd party package that is using it. Since you might not know what is actually using it it's probably best left alone |
| U | NuvaTime | NuvaTime.exe | NuvaTime - reminder for women using NuvaRing |
| X | NvagNT | nvagNT.exe | Added by the AGOBOT-RV WORM! |
| X | nvc Win32 | nvcvc.exe | Added by the RBOT-ADD WORM! |
| X | NvCCCpl | NvCCCpl.exe | Added by the NOGATA-A TROJAN! |
| X | NvCCpl | NvCCpl.exe | Added by the CHILIN-A WORM! |
| X | nvchost | winlogon.exe | Added by the KLONE-J TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | NvClipRsv | svchost.exe | Added by the DUMARU-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | NvClipRsv | swchost.exe | Added by the DUMARU-AK WORM! |
| ? | NVCLOCK | rundll32 nvclock.dll, fnNvclock | Overclocking utility for nVidia based graphics cards? |
| X | nvcoi | nvcoi.exe | Added by the DLOADER.TYO TROJAN! |
| ? | NvColorInit | rundll32.exe NvQtwk.dll, NvColorInit | Associated with Nvidia based graphics cards |
| X | NVCOM | NVCOM.exe | Added by the AGOBOT-SB WORM! |
| X | NvCp1Do | [path to trojan] | Added by the DWNLDR-GWE TROJAN! The most common filename seen is "smss.exe" - which is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| U | NvCpl | RUNDLL32.EXE NvCpl.dll,NvStartup | If you use a utility (such as RivaTuner) to overclock any of the default display settings (system clock, memory clock, etc) for NVIDIA based graphics chipsets and want to apply these new settings at startup then this entry will maintain these. Leaving this entry enabled doesn't appear to have an impact on startup time. Not required if you use default settings and if you disable this entry you may also have to disable the associated "NVIDIA Display Driver Service" or "NVIDIA Driver Helper Service". Included with drivers since late 2002 |
| X | NvCpl | NvCpl.EXE | Added by the YANZ.B WORM! |
| X | NvCpl | [random filename] | Added by the AGOBOT-APJ WORM! |
| X | NvCpl | windowsp.exe | Added by a variant of the SDBOT WORM! |
| X | NvCpl | rundl32.exe | Added by the AGOBOT-TO WORM! Note - the valid version of this entry has the command line as "rundll32.exe NvCpl.dll,NvStartup" |
| X | NvCpl28Deamon | mdosft.exe | Added by the SPYBOT-AD WORM! |
| X | NvCPL32 | nvcpl32.exe | Added by the AGOBOT.DAA WORM! |
| X | NvCpl32Deamon | nvcpl.exe | Added by the SPYBOT.S WORM! |
| X | NvCplD | m2gr32.exe | "Switch" premium rate adult content dialler variant |
| X | NvCplD | ntcpl.exe | "Switch" premium rate adult content dialler variant |
| U | NvCplDaemon | RUNDLL32.EXE NvQTwk,NvCplDaemon | Installed with display drivers for NVIDIA based graphics cards prior to late 2002, this entry allows the System Tray icon to be displayed - which gives access to (amongst others) the display settings (such as Antialiasing, OpenGL, Direct3D and colour) and Desktop Manager (nView). If you don't change display settings very often then this is not required and settings can be changed manually via display properties |
| U | NvCplDaemon | RUNDLL32.EXE NvCpl.dll,NvStartup | If you use a utility (such as RivaTuner) to overclock any of the default display settings (system clock, memory clock, etc) for NVIDIA based graphics chipsets and want to apply these new settings at startup then this entry will maintain these. Leaving this entry enabled doesn't appear to have an impact on startup time. Not required if you use default settings and if you disable this entry you may also have to disable the associated "NVIDIA Display Driver Service" or "NVIDIA Driver Helper Service". Included with drivers since late 2002 |
| X | NvCplDaemon | msmsgrs.exe | Added by the DLOADER-YI TROJAN! |
| X | NvCplDaemon | Xplorer.exe | Added by the ORBINA-A WORM! |
| X | NvCplDaemon32 | anvshell32.exe | Added by the VB-XU TROJAN! |