| Name | Status | Filename | Description |
|---|
| Security System Manager | X | spoolvc.exe | W32/Sdbot-DCW Read the link, allows remote access |
| Security Task Manager | X | spoolvc.exe | Added by the W32/Tilebot-IX WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Security Windows services (WinSecurServ05) | X | svchost.exe | Unknown malware Note: Located in \%WINDIR%\System32\\Microsoft\ This infection should not be confused with the legitimate \%WINDIR%\System32\svchost.exe file. Note: Use SDFix under supervision. |
| Security_Service | L | TmrService.exe | Related to Child Control 2007
Lets you set time limits for the PC and the Internet, and block or filter unwanted Internet content.
Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
Securom User Access for Windows 2000 and Windows XP a technology by Sony DADC (UserAccess) | L | useraccess.exe | Related to Sony DADC Blu-ray Disc is the next generation optical disc format. |
| SecuROM User Access Service (UserAccess) | L | UAService.exe | Added by SecuROM |
| SecuROM User Access Service (V7) (UserAccess7) | L | UAService7.exe | Used by virtual CD programs like Alcohol to access CD images protected by SecureROM. |
| Senao Network Controller | X | winsno.exe | W32/Vanebot-AU Read the link, steals information |
| Sentinel Keys Server (SentinelKeysServer) | L | sntlkeyssrvr.exe | Related to Sentinel_Keys_Server from SafeNet Inc. Disks and Files encryption. Note: Located in \%Program Files%\Common Files\SafeNet Sentinel\Sentinel Keys Server\ |
| Sentinel Protection Server (SentinelProtectionServer) | L | spnsrvnt.exe | Related to one of the SafeNet_Inc
programs or services. |
| Sentry 2020 | L | SentryService.exe | www.softwinter.com |
| SerDgeonServer (SerDry_igeon_Server) | X | IExplore.exe | Added by the Troj/Feutel-AC
TROJAN!
Note: This is not the legitimate Windows process IExplore.exe (Which should be found in the Program Files\Internet Explorer folder.) This worm\trojan file (IExplore.exe) is found in the Windows or Winnt folder.
|
| Serv-U FTP Server (Serv-U) | O | ServUDaemon.exe | Related to Serv-U an FTP server from RhinoSoft.com NoteIf you did not install this server you should remove it. |
| Server 2.0 (Server 2.0) | X | Server.exe | Added by the Troj/GrayBrd-AN
TROJAN!
Note: This worm\trojan file is found in the Windows or Winnt folder. |
| Server Advance (ServerAC) | X | Security.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Server Management Service | X | svchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder.
Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) |
| Server Network Debug (SerND) | X | NetDebug.exe | W32/VB-DOS Note: Located in %windir%\system32 |
| Server VSS System | X | sysvrs32.exe | W32/Sdbot-DES Read the link, allows remote access |
| Servers Alive (salive) | L | serversalive.exe | Related to Servers_Alive a network monitoring tool |
| Service | X | Service.exe | Added by the Troj/SrchSpy-A
TROJAN!
Note: This is not the legitimate Windows process services.exe (Notice the difference in the spelling.) This trojan file (Service.exe) is also found in the System32 folder. Do not confuse the two!
|
| Service | X | Service.exe | Added by the Haxdoor.Fam HAXDOOR!
Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| SERVICE (WINDOWS) | X | spoolsvc.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Service 8 (Service Filter) | X | smncs.exe | Added by the W32/Tilebot-CK WORM! which attempts to spread to remote network shares and messaging applications |
| Service Cache Terminal (SVCTERM) | X | svscache.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Service Configurator (Service_v1) | X | service.exe | Added by the Backdoor.Win32.SdBot.aad TROJAN! Note: This trojan is located in \%WINDIR%\Config\ |
| Service Controller (Services) | X | services.exe | W32/Sdbot-DDT Read the link, allows remote access |
| Service Cvasvr (Service Cvas) | X | csvas.exe | Spyware Worm reported as Backdoor.Win32.SdBot.aad by Kaspersky Anti-Virus |
| Service de l'iPod (iPod Service) | L | iPodService.exe | Related to Apple iPod |
| Service de lancement de WlanCfg (Wlancfg) | L | wlancfg.exe | Driver for wireless router. Owner: Inventel-Found in C:\Program Files\Inventel\Gateway\ |
| Service Hosts (ServiceHost) | X | shost.exe | Added by the W32/Rbot-AXG
WORM!
Note: This worm file is found in the Windows or Winnt folder.
|
| Service Ithea (itheaService) | L | itheaSvc.EXE | Related to ITHEA a french protection software. Note: Located in \%WINDIR%\System32\ |
| Service Logon Protocol (SVSLOG) | X | svslogon.exe | Added by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ |
| Service Manager | X | testing.exe | Added by a of the IRCBot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\ |
| Service name: Messenger | X | system32.exe | See Symantec
Trojan.Esteems.B Location:
C\Windows\system\system32.exe (9X\ME) or C\Windows or Winnt\system32\system32.exe (NT\2000\XP) |
| Service name: Messenger | X | zone-h.ddo.jp.exe -k netsvcs | Trojan.Esteems.C See Symantec
Location: C:\Winnt\System32 ( NT/2000), or C:\Windows\System32 (XP). |
| Service name: Messenger | X | 514.exe | Trojan.Esteems.D See Symantec
Location C:\Windows\System32 (XP) C:\Winnt\System32 (NT\2000) |
| Service Norton AntiVirus Auto-Protect (navapsvc) | L | navapsvc.exe | Related to Norton/Symantec AntiVirus. |
| Service Request Monitor | L | RxMon.exe | Related to Roxio EasyCD Creator application. |
| Service Scheduler | X | scheduler.exe | W32/Agobot-PH See Sophos
Unknown owner: Location: C:\WINDOWS\System32\scheduler.exe -service |
| Service Security Manager (scekrnl) | X | scekrnl.exe | Added by the Backdoor.Win32.Agent.alx TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Service Updater (servfjhf) | X | servfjhf.exe | Identified as Downloader.Agent.dxm by AVG Anti-Spyware Note: located in \%WINDIR%\ |
| Service1 | L | windowsserviceexample.exe | Related to Microsoft .Net Application. VB.NET_Forums |
| Service32 (Service Sequence) | X | services32.exe | Added by the W32/Tilebot-C
WORM!
Read the link, rootkit type stealth involved.
|
| Service: Access Remote PC Service 4.3 (RpcSvr4x) | O | rpcsetup.exe | Access_Remote_PC remote access software. Legitimate, but remote access could be considered dangerous unless monitored carefully. |
| Service: LicenseManagerReminder | L | LicenseManagerReminder.exe | Related to UIC License Manager a propriatiry Sofstware. Used to activate a software on customer computers for a specified length of time. Note: Located in C:\Program Files\Universal Instruments\License Manager\ |
| Service: Microsoft Net API (NETAPI) | X | ntps.exe | Added by the Backdoor.Win32.SdBot.aad as identified by Kaspersky. TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Service: Network Client (nwclnta) | X | netclna.exe | Troj/Boxed-I. Owner:Unknown. Location: C:\WINDOWS\system32\netclna.exe |
| ServiceHost32 | X | ServiceHost32.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32 Note: Use SDFix under supervision. |
| ServiceLayer | L | ServiceLayer.exe | Related to Nokia Connectivity Library software. Note: located in C:\Program Files\Common Files\PCSuite\Services\ |
| ServiceM | X | ServiceM.exe | Added by Trojan/Backdoor W32/Suspicious_M.gen TROJAN! Note: Located in \%WINDIR%\System32\Common Files\ArcSoft\Connection Service\Bin\ |