CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9466.22 of $21422.68
left sidedonated so farneed $11956.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 3876 entries and growing...
Last updated on 2008-05-09 18:10:24 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    NAI ePolicy Orchestrator Agent (NAIMAGENT32)Lnaimas32.exeRelated to Network Associates anti-virus protection suite http://www.liutilities.com/products/wintaskspro/processlibrary/naimas32/
    NakidoLnakido.exeRelated to Nakido file sharing software. Note: Located in \%Program Files%\Nakido\
    National Instruments Domain Service (NIDomainService)Lnidmsrv.exeRelated to National_Instruments Domain Service. From National Instruments Corp, Note: Located in \%Program Files%\National Instruments\Shared\Security\
    National Instruments PSP Server Locator (lkClassAds)Llkads.exeRelated to National_Instruments Logos. Note: Located in C:\WINDOWS\system32\
    National Instruments Time Synchronization (lkTimeSync)Llktsrv.exeRelated to National_Instruments Logos. Note: Located in C:\WINDOWS\system32\
    National Instruments Variable Engine (NITaggerService)Ltagsrv.exeRelated to National_Instruments Inc. Note: Located in \%Program Files%\National Instruments\Shared\
    NAV AlertLalertsvc.exeRelated to Symemtecn/Norton products
    Navegador de red (ExpIorer)XExpIorer.exeAdded by the Troj/Taladra-E TROJAN!
    Naver Anti-virus Realtime Monitor (Nsavsvc)LNsavsvc.exeRelated to Naver_Anti-virus Realtime Monitor From NHNCorp. Note: Located in \%Program Files%\\Naver\NaverPCGreen\
    Naver Anti-virus Scan Service (nsvmon)Lnsvmon.exeRelated to Naver_Anti-virus Realtime Monitor From NHNCorp. Note: Located in \%Program Files%\\Naver\NaverPCGreen\
    NBServiceLNBService.exeRelated to Nero Backup service. Note: Located in C:\Program Files\Nero\Nero 7\Nero BackItUp\
    NDAS Service (ndassvc)Lndassvc.exeRelated to XIMETA Inc. Smart Network Storage Solution.
    NDIS Adapter (NDIS TCP Layer Transport Device)Xndis.exeAdded by the W32/Forbot-AX WORM! Note: This worm file is found in the System32 folder.
    NdisFilterXndisfilter.sys Troj/NetAtk-F
    ndservndserv.exeRelated to NetDeploy_Launcher from Open Software Associates Ldt. a division of Managesoft.com Note: Located in C:\Program Files\netDeploy\Launcher\
    Neoteris Setup ServiceLNeoterisSetupService.exeRelated to Neoteris_Setup_Service now owned by Juniper.net. Note: Located in \%Program Files%\Neoteris\Installer Service\
    Nero Registry InCD Service (NeroRegInCDSrv)LNBHRegInCDSrv.exeRelated to Nero suite lets you organize your multimedia projects easily, helping you get the most from your digital content! Note: Located in \%Program Files%\Nero\Nero8\InCD\
    neruo.exe (NeroFilterCheck)XExplore.exeAdded by the SDBOT.DIH WORM! Read the link, rootkit type stealth involved.
    Net AgentXdls0523pmw.exeAdded by the Trojan.Downloader-Gen/BasicMath.Process TROJAN Note: This trojan is located in C:\%WINDIR%\
    Net Boot Service Xbig5_gb2312.exeDetected as W32.Agobot-TU Note: Located in WINDOWS\system32
    Net Functions Library (Netlib)XNetlib.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C: folder.
    Net Functions Monitoring (Netmon)XNetmon.exeAdded by the W32/Codbot-R WORM!
    Net Logon (Netlogon)Llsass.exeRelated to the Net_Logon service. Uused to authenticate a user into a domain. Note: Located in C:\%WINDIR%\System32\
    Net message ServiceXnetmsg.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Net Modulation (kilomang)Xnetmodulr.exeIdentified as Trojan.DownLoader.36024 Note: Located in \%WINDIR%\System32\
    Net Service MonitorXnetsvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: Located in C:\WINDOWS\ Note] Netsvc.exe: This tool provides a way to remotely start, stop, and query the status of services from the command line. But is not run as a SERVICE. Here
    NetBackup Client Service (NetBackup INET Daemon)Lbpinetd.exeRelated to VERITAS NetBackup Enterprise Server.
    NetBackup Volume ManagerLbevmd.exeRelated to VERITAS NetBackup Enterprise Server.
    NetBIOS HelperXnbthlp.exeAdded by the W32.Toxbot.AL WORM! Note: Symantec has developed a removal tool to clean the infections of W32.Toxbot.AL, to download it Click_Here
    netbios helper serviceXaltsvc.exeadserver adtech.de redirects
    NetBIOS Helper Service (NetBIOS Helper)Xnbthlp.exeAdded by the W32/Codbot-AE WORM! Note: This worm\trojan file is found in the System32 folder.
    NetBTD(ntbtd) (NetBTD)Xnetbtd.exeAdded by W32/Sdbot-BLW WORM! Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    NetCNXnetcn.sysAdded by the Hacktool.Rootkit TROJAN! Read the link, rootkit type stealth involved.
    NetconDDE Service (NetconDDE)Xiisctrl.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    netconf32 (netconf32)Xnetconf32.exeAdded by the W32/Tilebot-BN WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    netctrlXsys.dll Troj/Singu-AR Read the link, allows remote access
    netctrolXsysi.dll Troj/Singu-BB
    NetDDE Server (NetDDEsrv)Xnetddesrv.exeAdded by the W32/Codbot-Y WORM! Note: This worm\trojan file is found in the System32 folder.
    NetDDEipx (NetDDEipx)XrandomAdded by the NetDDEipx TROJAN! **note 3ylv.exe may be one of the random file names used
    NetDetectXnetdtect.sys Troj/Pushu-Gen Note: Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K) May also have an additional services installed. Read link
    Netgear Wireless Domain Login Service (NWDLS)LNWDLS.exeRelated to Netgear_Wireless_Domain Login Service. Note: Located in \%WINDIR%\System32\
    Netgear WN311B Wireless Control Service (WN311BFCS)LWN311BFCS.exeRelated to WN311B Wireless Control Service. Note: Located in \%WINDIR%\System32\
    Netgroup Packet Filter (NPF)Xnpf.sys W32/Rbot-GSI Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K)
    NetGroup Packet Filter Driver (NPF)Xnpf.sys Troj/Delf-EQE Note: Located in %windir%\system32\drivers
    NethXnetid.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Netilla SSL Tunnel Helper Service (NetillaVPNService)LNVPNs.exeRelated to Netilla_SSL Tunnel Helper Service. Policy Networking ties network and application access to identity and policy. Note: located in \%WINDIR%\
    NETINFOXnetinfo.exeAdded by the W32/Tilebot-J WORM! Read the link, rootkit type stealth involved.
    NetLimiter (nlsvc)Lnlsvc.exe NetLimiter_2 shows list of all applications communicating over network.
    NetLogonXsvchost.exe -k NetLogonAdded by the Fuwudoor TROJAN!
    NetLogon P2P (NFOSVC)Xnfosvc.exeAdded by a variant of the SdBot.aad family of worms and IRC backdoor Trojans. Note: This trojan is located in C:\WINDOWS\AppPatch\
    NetM (Ne)Xwin32udt.exeAdded by a variant of the SDBOT.CZD family of trojan. Note: This trojan is located in C:\%WINDIR%\
    NetmanXNetserv.dll Troj/Protux-E
    NetOp Helper ver. 7.50 (2002343) (NetOp Host for NT
    Service)
    LNHOSTSVC.EXERelated to Danware NetOp products Note: Located in C:\Program Files\Danware Data\NetOp Remote Control\HOST\
    NetOp Helper ver. 7.65 (2004242) (NetOp Host for NT
    Service)
    LNHOSTSWC.EXERelated to Danware NetOp products
    Netropa NHK ServerLNhksrv.exe nhksrv.exe is a process that belongs to DELL and Compaq systems. It is used to halt any configured hotkeys while the screensaver is running.
    Netropa NHK Server (nhksrv)Lnhksrv.exeNetropa Hotkey Server task seen only on DELL and Compaq PCs running Windows NT4/2000/XP
    Netscape Update Service (NCUpdateSvc)Lncupdatesvc.exeNetscape Communications Corporation updater
    NetSendServer (NetSendServer)XNetSend.exeAdded by the Troj/Hupigon-DQ TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    netservice (DDMP)Xnetservice.exe Troj/Delf-EXQ Note: Located in %User%\Favorites\ Turns off anti-virus applications Allows others to access the computer
    NetSign AutoUpdate Service (NsAUSvc)LNsAUSvc.exeRelated to SecurityFocus - http://www.securityfocus.com/
    nettoserviceXtime.exe W32/Otamyu-A Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Leaves non-infected files on computer
    NetVeda Safety.Net (ipcSvc)Lipcsvc.exeRelated to Safety_net from Netveda. Security and advanced Internet firewall protection for all your LAN computers.
    Network?nettcp.exeUnknown owner: Location C:\WINDOWS\system32\nettcp.exe
    Network ADSL Server (Network ADSL Server)Xwoaisaomm.exeAdded by the Troj/GrayBrd-AQ TROJAN! Note: This trojan file is found in the System32 folder.
    Network Associates McShield (McShield)LMcshield.exeRelated to McAfee_Virus_Shield Note: Located in \%Program Files%\Network Associates\VIRUSSCAN\
    Network Associates Task Manager (McTaskManager)LVsTskMgr.exeRelated to Network Associates Virus protection software.
    Network Client (nwclntg)Xwinlogon.exeAdded by the Boxed.E TROJAN!
    Network Confg System Xlviss.exe WORM_SDBOT.AXG Read the link, allows remote access
    Network Configuration Service (NetCfgSvr)LNetCfgSv.EXERelated to AT&T http://www.anti-spy.info/process/netcfgsv.exe.html
    Network Connections Sharing (RpcTftpd)Xsvchost.exeAdded by the W32.Welchia WORM! **Note - This service will be set to start manually
    Network DDE Client (NetDDEclnt)Xnetddeclnt.exeAdded by the W32/Codbot-M WORM!
    Network dde connectionsXservice.exeadtech.de redirections
    Network DDE Connections (NETDDEC)Xwinmgnt.exeAdded by unknown malware, the file winmgnt.exe may be a Serv-U FTP server used to download other malicious files to your computer. File location is in the System32 folder.
    Network DDE DSMA (NetDDEdsma)Xsvchost.exeAdded by the W32/Sdbot-BMG WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) This worm file is found in the Windows or Winnt folder.
    Network DDS (NetDDS)XNetDDS.exeReported as Troj/ServU-Gen See Sophos Unknown owner :Location: C:\WINDOWS\system32\NetDDS.exe
    Network Devices Controller (ndcsvc)Xrandom.$$$Added by the Alnica TROJAN!
    Network Devices Controller (ndcsvc)Xrandom file nameAdded by the Alnica TROJAN!
    Network Distributed Transaction Coordinator for
    Workstation (MSDCSRV32)
    Xmssrv.exeAdded by the PWSteal.Drorar TROJAN! Note: This trojan file is found in the Program Files\Common Files\system\ado folder.
    Network DRV (NTDRV)Xnetdrvr.exeAdded by the W32/Sdbot-AZK WORM! Note: This worm file is found in the System or System32 folder.
    Network Gateway Manager (npx)Xcsrsc.exeAdded by the W32/Sdbot-CPE WORM! Note: This worm\trojan is located in C:\%WINDIR%
    Network helper Service (MSDisk)Xirdvxc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Network Location Awareness (Network Location)XNetwork.exe Troj/Dloadr-BBE Copies itself to %Common Files%\Microsoft Shared\MSInfo\
    Network Location ManagerXlssc.exeAdded by the Trojan.Backdoor.Gen TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Network Management Center Time (W32Times)XTIMEMAN32.EXEAdded by the Troj/GrayBrd-AA TROJAN! Note: This worm\trojan file is found in the Program Files\Internet Explorer\plugins folder.
    Network Messenger (MStdc )Lmstdc.exeRelated to Microsoft Personal Web Server and Microsoft SQL Sever software http://www.2-files.com/process/microsoft-distributed-transaction-coordinator
    Network MonitorXnetmon.exeReported by Panda as the Trj/Cicos.H TROJAN! This trojan if found in the \Program Files\Network Monitor\ folder. Note: This is not the legitimate Microsoft Network Monitor (Netmon.exe) process which is legitimate to capture network traffic. Article_Q812953
    Network Provision Managing Service (xmlprovman)Xprovsvc.exeAdded by the W32/Sdbot-CRS WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Network Security ServiceXrandomCoolWebSearch res:// variant
    Network Security Service (NSS)XrandomCoolWebSearch res:// variant
    Network Security Service (__NS_Service_3)Xsdkbj32.exeDetected as Trojan.Agent.bi by ewido(now known as AVG-antispyware)
    Network Source Engine (NSEsvc)Xnsecvc.exeIdentified by Bitdefender as Trojan.Peed.Gen Note: located in \%WINDIR%\Help\
    Network Station Task Manager (TASKSQ)Xtasksch.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    Network Station Task Manager (TSKIB)Xtaskib.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    Network Switching AlerterXwindlls.exeProbable variant of W32/Rbot-AZQ
    Network System (NetSystem)XNetSystem.exe Troj/QQRob-ADE Read the link, steals information
    Network System Logon (NSLSVC)Xnetmsvc.exeAdded by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\Cursors\
    Network Translation System Service (NTSS)Xntss.exeAdded by the Backdoor.Unpdoor backdoor Trojan. A Trojan horse that opens a random port and connects to a remote Web site. Note: located in \%WINDIR%\System32\
    NetWorker Power Monitor (nsrpm)Lnsrpm.exeRelated to NetWorker_Power Monitor from LEGATO Software. Note: Located in \%Program Files%\nsr\bin\
    NetWorker Remote Exec Service (nsrexecd)Lnsrexecd.exeRelated to NetWorker_Remote Exec Service from LEGATO Software. Note: Located in \%Program Files%\nsr\bin\
    NetWorkLogonXKB8964225.log Troj/Lmir-FF Note: Located in %windir%\system32 Read the link, steals information
    NI Configuration Manager (mxssvr)Lnimxs.exeRelated to NI_Configuration_Manager from National Instruments Corp. Note: Located in \%Program Files%\National Instruments\MAX\
    NI Service Locator (niSvcLoc)LniSvcLoc.exeRelated to National_Instruments corp.
    Nicrosoft f11ntXvvvhost.exeAdded by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\system32\dllcache\
    NICSer_G200v2LNICServ.exeRelated to Linksys config utility.
    NICSer_WMP11LNICServ.exeRelated to Linksys config utility.
    NICSer_WPC54GLNICServ.exeRelated to Linksys config utility. Note: Located in \%Program Files%\Linksys\Wireless-G Notebook Adapter\
    nidevlduLnipalsm.exeRelated to National_Instruments Inc. Note: Located in \%WINDIR%\System32\
    NILM License ManagerLlmgrd.exeRelated to the Macrovision License Manager.
    ninsvcXninsvc.exeAdded by the W32/Akbot-AL WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Modifies the HOSTS file
    nipxirmuLnipalsm.exeRelated to National_Instrument Corp.
    NkPtpEnumP2LNkPtpEnum.exeRelated to Nikon Wireless Camera Setup utility. Note: Located in \%Program Files%\Nikon\Wireless Camera Setup Utility\
    NMapLnmapserv.exeNMapWin Port Scanner utility service.
    NMIndexingServiceLNMIndexingService.exePart of a Nero product
    NMSAccessLNMSAccess.exeRelated to Cheetah_DVD_Burner Note Must only be used on NT4/2000/XP
    nMtskBar Service (nMtskService)?nMtsk.exeTaskbar control for ISDN NetMod modem
    NMU Emergency Broadcast System (nmuebs)Lnmuebs.exeRelated to Northern_Michigan_University On-line services. Note: Located in \%ROOT%\nmutools\
    NNServXnnrun.exeAdded by NewDotNet AdWare! Note: Located in C:\Program Files\NewDotNet\
    NNSvcLnnsvc.exeNetNanny Internet Filter
    NobleNet Portmapper for TCPLportserv.exe Actuate_Enterprise Reporting Applications for business intelligence analytic services
    NOD AV service (nodantivir)Xnodantivir.sysAdded by the Troj/Haxdoor-AK TROJAN! Note: This trojan file is found in the System32 folder. The file nodantivir.sys provides stealthing functionality.
    NOD32 Kernel Service (NOD32krn)Lnod32krn.exeNOD32 Antivirus
    Nofeel FTP Server ServiceLnftpdsvc.exeRelated to Nofeel_FTP_Server
    NoIPDUCServiceLDUC20.exeRelated to Vitalwerks Internet Solutions
    Norman API-hooking helper (NipSvc)Lnipsvc.exeNorman Anti-Virus
    Norman eLogger service 6 (eLoggerSvc6)LELOGSVC.EXERelated to Norman_eLogger Internet Control. Note: Located in \%ROOT%\Norman\Npm\bin\
    Norman NJeevesLNJEEVES.EXENorman Anti Virus
    Norman Type-RLNPFSVICE.EXENorman Virus Control Service. Made by Norman Data Defense Systems, Inc. For more information Click_Here File is located in the Norman\Nvc\BIN folder.
    Norman Virus Control on-access component (nvcoas)Lnvcoas.exeNorman Virus Control on-access component
    Norman Virus Control Scheduler (NVCScheduler)LNVCSCHED.EXENorman Virus Control Scheduler
    Norman ZANDALZanda.exeNorman Anti Virus
    Nortel CVC Service (NvcRpcServer)LNvcRpcSvr.exeRelated to Nortel_CVC Service. Service - VNP Client. Note: Located in \%Program Files%\Nortel Networks\
    Nortel Networks TunnelGuard (tunnelguardservice)LCueAgent_srv.exeRelated to Nortel_Networks_TunnelGuard designed to ease the deployment of very large site-to-site and remote access Virtual Private Networks (VPNs). Note: Located in C:\Program Files\Nortel Networks\TunnelGuard\
    Norton antivirus and Firewall (it)Xfime.exeBogus Norton Antivirus and Firewall service. Unknown owner.
    Norton AntiVirus Auto Protect Service (navapsvc)Lnavapsvc.exeRelated to Norton/Symantec AntiVirus.
    Norton AntiVirus Auto-Protect Service (navapsvc)Lnavapsvc.exeRelated to Norton/Symantec AntiVirus.
    Norton AntiVirus Auto-Protect-Dienst (navapsvc)Lnavapsvc.exeRelated to Norton/Symantec AntiVirus.
    Norton AntiVirus Auto-Protect-service (navapsvc)Lnavapsvc.exeRelated to Norton/Symantec AntiVirus.
    Norton AntiVirus Client (Norton AntiVirus Server)Lrtvscan.exeNorton Anti-virus related
    Norton AntiVirus Firewall Monitor Service (NPFMntor)LNPFMntor.exeNorton Internet Worm Protection
    Norton GhostLPQV2iSvc.exesymantec Norton Ghost Image related
    Norton GhostLVProSvc.exeRelated to symantec Norton Ghost Image. Note: Located in \%Program Files%\Norton Ghost\Agent\
    Norton Internet Security Accounts Manager (NISUM)LNISUM.EXERelated to Norton Internet Security
    Norton Internet Security Professional Accounts Manager
    (NISUM)
    LNISUM.EXERelated to Norton Internet Security
    Norton Internet Security Proxy Service (SymProxySvc)LSymProxySvc.exeRelated to Symantec Corporation
    Norton Internet Security ServiceLNISSERV.EXERelated Symantec Corporation
    Norton Online Anti VirusXavll32.exeAdded by the Backdoor.Win32.SdBot.aad reported by Kaspersky TROJAN! Note: This worm\trojan is located in C:\%WINDIR%
    Norton Personal Firewall Proxy ServiceLSymProxySvc.exeRelated to Norton Firewall Proxy service
    Norton Personal Firewall ServiceLNISSERV.EXERelated to Norton Personal Firewall service
    Norton Program SchedulerLnpssvc.exeRelated to Norton Scheculer
    Norton Protection Center Service (NSCService)LNSCSRVCE.EXERelated to Norton Internet Security 2006 and Norton AntiVirus 2006. Made by Symantec_Corporation
    Norton Save and RestoreLVProSvc.exeRelated to Symantec Norton Ghost Note: Located in C:\Program Files\Norton Save and Restore\Agent\
    Norton UnErase Protection (NProtectService)LNPROTECT.EXENorton Protected Recycle Bin
    Notebook Manager Service (anbmService)LanbmServ.exeRelated to Acer Notebooks Hardware Monitoring program. Made by OSA_Technologies Inc.
    Notebook Performance Tuning Service
    (TempoMonitoringService)
    LTempoSVC.exeRelated to Toshiba_TEMPO It will advise you on how to fine-tune the performance of your notebook and keep you informed of the latest Toshiba software and driver updates as soon as they are released. Note: Located in \%Program Files%\Toshiba TEMPO\
    NOTEPADXnotepad.exe W32/Sdbot-DHU Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K) Allows others to access the computer
    Novell Application Launcher (NALNTSERVICE)LNALNTSRV.EXENovell NAL NT service
    Novell Workstation Manager (WM)Lwm.exeNovell Workstation Manager
    Novell XTier Agent Services (XTAgent)LXTAgent.exeRelated to Novell, Inc. \%WINDIR%\System32\Novell\
    Novell XTier Service Manager (XTSvcMgr)LXTSvcMgr.exeRelated to Novell Inc. Note: Located in \%Program Files%\Novell\Client\XTier\Services\
    Novell ZfD Remote ManagementLZenRem32.exe
    Novell ZfD Wake on LAN Status Agent (Prometheus
    Wake-On-LAN Status Agent)
    LWolSerNT.exeNovell ZfD Wake on LAN Status Agent
    Now.WAP Proxy Gateway Service (WAP3GX)LWAP3GXNT.EXERelated to Now.WAP_Proxy a WAP Gateway that is designed to meet the needs of WAP 2.0 and multimedia applications. Note: Located in C:\PROGRAM Files\NowWAP\
    NPDOR File Monitor Service (NFMService)LNPDORNT.exeRelated to NPD Online Research.
    NPFXnpf.sysAdded by the Troj/NtRootK-I TROJAN! Note: This trojan file is found in the System32 folder.
    npkcmsvcLnpkcmsvc.exeRelated to KeyCrypt Encryption Manager Service from INCA Internet Co. Note: Located in \%WINDIR%\System32\
    npkcsvcLnpkcsvc.exeINCA Internet
    NS (MSLLR)Xns.exeW32/Agobot-HS
    NSC Agent (NSDUAgent)LNSCAGENT.EXERelated to NSC_Agent service from Symantec. Note: Located in \%ROOT%\NAgent\
    NsEngineLNSENGINE.exeScheduling engine of NovaSTOR Backup Service
    nserviceXnservice.exeAdded by the W32/Agobot-AHR WORM! Note: This worm is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) Read the link, allows remote access
    nsssvcXisssvc.exe Troj/Agent-BIY Note: Located in :\Program Files\W3CS
    NSUServiceLNSUService.exeA network utility for Sony laptops see here Note: Located in \%Program Files%\Sony\Network Utility\
    NT LM Security Support Provider (NtLmSsp)Llsass.exeRelated to the NT_LM_Security_Support_Provider Windows NT 4.0 is responsible for handling NTLM authentication requests. Note: Located in C:\%WINDIR%\System32\
    NT login service (ntlogin32)Xlibsys32.exeAdded by the W32/Sdbot-ACK WORM!
    NT login service - UnknownXlibsysmgr.exeAdded by the W32/SDBOT-CAF WORM! (Castle Cops)
    NT Online ProtectionLONLNSVC.EXERelated to AntiVirus_Quick Heal Virus protection. Note: located in C:\Program Files\QUICKH~1\
    Nt System KernelXntsyskrnl.exerelated to WORM_AGOBOT.IK
    NTBOOTMGR (NTBOOT)Xntuser.exeFlagged as Backdoor.Iroffer / Backdoor.Noer
    NTCHARGELwinlogon.exeRelated to Microsoft Internet Information Services (IIS).
    NTFS Crypto Technology (NTFSCrypt)Xntfscrypt.exeAdded by the W32/Spybot-NC WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    NTFS File Location Service (NTFSFLS)Xntfsloc.exeAdded by the W32/Sdbot-CSG WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    NTFSprotect (ntfsdiscman)Xntfsprotect.exeAdded by the SDBOT.CCF WORM! Read the link, rootkit type stealth involved.
    ntldr.sysXntldr.sys Troj/SpamToo-AQ Creates the file %Root%
    Ntlm_Drive_Connect (Ntlm_Drive_Connect)XTimerU.sysAdded by the Tuimer TROJAN!
    NTLOADXntsrv.exeIdentified as Win32.Iroffer.b by Kasperksy. Note: Located in \%WINDIR%\System32\dllcache\win32\
    NTLOADXwinlogon.exeOther files in the same directory identified as Win32.Iroffer.b by Kaspersky
    ntmssvcXsvchost.exe -k ntmssvcAdded by the Fuwudoor TROJAN!
    ntmssvcXSysPkOs.dll Troj/BkDoor-A Troj/BkDoor-A may overwrite registry entries, to enable it to run as a service. Read link
    NTP (Network Time Protocol)Xwinlogon.exeAdded by the Troj/Jtram-D TROJAN! Note: This trojan file is found in the System32\Client folder.
    NTRU Hybrid TSS v1.05 TCSD (tcsd_win32.exe)Ltcsd_win32.exeRelated to NTRU_Cryptosystems Inc. Provider a public key cryptography system (PKCS)
    NTRU Hybrid TSS v2.0.7 TCS (tcsd_win32.exe)Ltcsd_win32.exeRelated to NTRU_Cryptosystems Inc. Provider a public key cryptography system (PKCS) Note: Located in \%Program Files%\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.7\bin\
    NTSec(ntsec) (NTSec)Xntsec.exeIdentified as Trojan-Dropper.VB.22 by VBA32 Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) This should not be confused with Keylog_Ardamax A program may have legitimate uses in contexts where an authorized administrator has knowingly installed this application. Located in %Documents and Settings% \Start Menu\Programs\Ardamax Keylogger. If you did not install this program remove it.
    NTSecureOsrvany1234.exeUnknown owner: Location C:\WINDOWS\system32\srvany1234.exe
    NTSVCMGRXwinlogon.exeIdentified as Win32.Iroffer.b by Kasperksy. Note: Located in \%WINDIR%\System32\dllcache\win32\ Note: This is not the legitimate Windows Process which is found in \%WINDIR%\System32\ folder.
    NTSVCMGRXntsrv.exeIdentified as Win32.Iroffer.b by Kasperksy. Note: Located in \%WINDIR%\System32\dllcache\win32\
    NTsyslogLntsyslog.exeRelated to Open_Source_Technology Group. An application logging functionality.
    nTune Service (nTuneService)LnTuneService.exeRelated to NVIDIA Access Manager. Note: Located in C:\Program Files\NVIDIA Corporation\nTune\
    NTVDMXntvdm.exe W32/Tilebot-JZ Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR%(XP/WinNT/2K) Used in DOS attacks, Allows others to access the computer Please read information on link
    NuTCRACKER KernelLnutkserv.exeRelated to openUTM from Fujitsu Siemens Computers
    NuTCRACKER ServiceLnutsrv4.exeRelated to Rational Rose, MKS Toolkit for Enterprise Developers
    NuTCRACKERServiceLnutsrv4.exeRelated to MKS from DataFocus Inc. Toolkit for Enterprise Developers.
    NvCplScanXmsc32.exeRelated to the W32/FORBOT-DD
    NvCplScanXnvsc32.exeanother example, added by Forbot_ET.
    NvedavtLousbehci.sysRelated to OrangeWare Corp.
    nvidGUIv (nvidGUIv2)XNVIDGUIV.EXEAdded by the SDBOT.CTQ WORM! Read the link, rootkit type stealth involved.
    NVIDIA Display Driver Service (NVSvc)Lnvsvc32.exeRelated to NVIDIA drivers.
    NVIDIA Display Driver Service (Omega 1.6693) (P)
    (NVSvc)
    Lnvsvc32.exeRelated to NVIDIA, http://www.nvidia.com/ drivers.
    NVIDIA Display Service (NVIDIA Display Driver Service)XNvds.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\%WINDIR%\ folder
    NVIDIA Driver Helper Service (NVSvc)Lnvsvc32.exeRelated to NVIDIA drivers. Note: Located in \%WINDIR%\System32\
    NVIDIA Driver Serviceˇˇ (NVSv )Xsvchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\
    Nvidia Graphic Displacement (nvideoGUI)Xnvideogui.exeAdded by the SDBOT.CQD WORM! Read the link, rootkit type stealth involved.
    NVIDIA PVR Schedule Monitor (nvpvrmon)Lnvpvrmon.exeRelated to NVIDIA ForceWare driver. Note: Located in C:\Program Files\NVIDIA Corporation\ForceWare\Multimedia\NVPVR\
    nvsec(nvsec) (NvSec)Xnvsec.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    nvsvc32.exeXwmisp.exeAdded by the Backdoor_Win32_SdBot_aad WORM! - Reported by KASPERSKY ON-LINE SCANNER

    Engine Version 2.0 by CastleCops

    spacer spacer