CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

O23 List of Windows XP/NT services

Currently 4053 entries and growing...
Last updated on 2008-08-02 17:32:28 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    Security System ManagerXspoolvc.exe W32/Sdbot-DCW Read the link, allows remote access
    Security Task ManagerXspoolvc.exeAdded by the W32/Tilebot-IX WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Security Windows services (WinSecurServ05)Xsvchost.exeUnknown malware Note: Located in \%WINDIR%\System32\\Microsoft\ This infection should not be confused with the legitimate \%WINDIR%\System32\svchost.exe file. Note: Use SDFix under supervision.
    Security_ServiceLTmrService.exe Related to Child Control 2007 Lets you set time limits for the PC and the Internet, and block or filter unwanted Internet content. Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Securom User Access for Windows 2000 and Windows XP a
    technology by Sony DADC (UserAccess)
    Luseraccess.exeRelated to Sony DADC Blu-ray Disc is the next generation optical disc format.
    SecuROM User Access Service (UserAccess)LUAService.exeAdded by SecuROM
    SecuROM User Access Service (V7) (UserAccess7)LUAService7.exeUsed by virtual CD programs like Alcohol to access CD images protected by SecureROM.
    Senao Network ControllerXwinsno.exe W32/Vanebot-AU Read the link, steals information
    Sentinel Keys Server (SentinelKeysServer)Lsntlkeyssrvr.exeRelated to Sentinel_Keys_Server from SafeNet Inc. Disks and Files encryption. Note: Located in \%Program Files%\Common Files\SafeNet Sentinel\Sentinel Keys Server\
    Sentinel Protection Server (SentinelProtectionServer)Lspnsrvnt.exeRelated to one of the SafeNet_Inc programs or services.
    Sentry 2020LSentryService.exewww.softwinter.com
    SerDgeonServer (SerDry_igeon_Server)XIExplore.exeAdded by the Troj/Feutel-AC TROJAN! Note: This is not the legitimate Windows process IExplore.exe (Which should be found in the Program Files\Internet Explorer folder.) This worm\trojan file (IExplore.exe) is found in the Windows or Winnt folder.
    Serv-U FTP Server (Serv-U)OServUDaemon.exeRelated to Serv-U an FTP server from RhinoSoft.com NoteIf you did not install this server you should remove it.
    Server 2.0 (Server 2.0)XServer.exeAdded by the Troj/GrayBrd-AN TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Server Advance (ServerAC)XSecurity.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Server Management ServiceXsvchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    Server Network Debug (SerND)XNetDebug.exe W32/VB-DOS Note: Located in %windir%\system32
    Server VSS SystemXsysvrs32.exe W32/Sdbot-DES Read the link, allows remote access
    Servers Alive (salive)Lserversalive.exeRelated to Servers_Alive a network monitoring tool
    ServiceXService.exeAdded by the Troj/SrchSpy-A TROJAN! Note: This is not the legitimate Windows process services.exe (Notice the difference in the spelling.) This trojan file (Service.exe) is also found in the System32 folder. Do not confuse the two!
    ServiceXService.exeAdded by the Haxdoor.Fam HAXDOOR! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    SERVICE (WINDOWS)Xspoolsvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Service 8 (Service Filter)Xsmncs.exeAdded by the W32/Tilebot-CK WORM! which attempts to spread to remote network shares and messaging applications
    Service Cache Terminal (SVCTERM)Xsvscache.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Service Configurator (Service_v1)Xservice.exeAdded by the Backdoor.Win32.SdBot.aad TROJAN! Note: This trojan is located in \%WINDIR%\Config\
    Service Controller (Services)Xservices.exe W32/Sdbot-DDT Read the link, allows remote access
    Service Cvasvr (Service Cvas)Xcsvas.exeSpyware Worm reported as Backdoor.Win32.SdBot.aad by Kaspersky Anti-Virus
    Service de l'iPod (iPod Service)LiPodService.exeRelated to Apple iPod
    Service de lancement de WlanCfg (Wlancfg)Lwlancfg.exeDriver for wireless router. Owner: Inventel-Found in C:\Program Files\Inventel\Gateway\
    Service Hosts (ServiceHost)Xshost.exeAdded by the W32/Rbot-AXG WORM! Note: This worm file is found in the Windows or Winnt folder.
    Service Ithea (itheaService)LitheaSvc.EXERelated to ITHEA a french protection software. Note: Located in \%WINDIR%\System32\
    Service Logon Protocol (SVSLOG)Xsvslogon.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    Service ManagerXtesting.exeAdded by a of the IRCBot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\
    Service name: MessengerXsystem32.exeSee Symantec Trojan.Esteems.B Location: C\Windows\system\system32.exe (9X\ME) or C\Windows or Winnt\system32\system32.exe (NT\2000\XP)
    Service name: MessengerXzone-h.ddo.jp.exe -k netsvcsTrojan.Esteems.C See Symantec Location: C:\Winnt\System32 ( NT/2000), or C:\Windows\System32 (XP).
    Service name: MessengerX514.exeTrojan.Esteems.D See Symantec Location C:\Windows\System32 (XP) C:\Winnt\System32 (NT\2000)
    Service Norton AntiVirus Auto-Protect (navapsvc)Lnavapsvc.exeRelated to Norton/Symantec AntiVirus.
    Service Request MonitorLRxMon.exeRelated to Roxio EasyCD Creator application.
    Service SchedulerXscheduler.exeW32/Agobot-PH See Sophos Unknown owner: Location: C:\WINDOWS\System32\scheduler.exe -service
    Service Security Manager (scekrnl)Xscekrnl.exeAdded by the Backdoor.Win32.Agent.alx TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Service Updater (servfjhf)Xservfjhf.exeIdentified as Downloader.Agent.dxm by AVG Anti-Spyware Note: located in \%WINDIR%\
    Service1Lwindowsserviceexample.exeRelated to Microsoft .Net Application. VB.NET_Forums
    Service32 (Service Sequence)Xservices32.exeAdded by the W32/Tilebot-C WORM! Read the link, rootkit type stealth involved.
    Service: Access Remote PC Service 4.3 (RpcSvr4x)Orpcsetup.exe Access_Remote_PC remote access software. Legitimate, but remote access could be considered dangerous unless monitored carefully.
    Service: LicenseManagerReminderLLicenseManagerReminder.exeRelated to UIC License Manager a propriatiry Sofstware. Used to activate a software on customer computers for a specified length of time. Note: Located in C:\Program Files\Universal Instruments\License Manager\
    Service: Microsoft Net API (NETAPI)Xntps.exeAdded by the Backdoor.Win32.SdBot.aad as identified by Kaspersky. TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Service: Network Client (nwclnta)Xnetclna.exeTroj/Boxed-I. Owner:Unknown. Location: C:\WINDOWS\system32\netclna.exe
    ServiceHost32XServiceHost32.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32 Note: Use SDFix under supervision.
    ServiceLayerLServiceLayer.exeRelated to Nokia Connectivity Library software. Note: located in C:\Program Files\Common Files\PCSuite\Services\
    ServiceMXServiceM.exeAdded by Trojan/Backdoor W32/Suspicious_M.gen TROJAN! Note: Located in \%WINDIR%\System32\Common Files\ArcSoft\Connection Service\Bin\

    Engine Version 2.0 by CastleCops

    spacer spacer