CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

O23 List of Windows XP/NT services

Currently 4053 entries and growing...
Last updated on 2008-08-02 17:32:28 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    Gray_Pigeon (GrayPigeon) XG_Server2.0.exe Troj/Hupigon-CH Note: Located in %windir% Read the link, allows remote access
    Gray_Pigeon_Serve (GrayPigeonServer)XG_Server.exeAdded by the Troj/Feutel-I or Troj/Feutel-AI TROJAN!
    Gray_Pigeon_Server (GrayPigeonServer)XG_Server1.2.exeAdded by the Troj/GrayBrd-AP TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Gray_Pigeon_Server1.236 (GrayPigeonServer1.236)XG_Server1.236.exe Troj/Hupigon-RW Read the link, allows remote access
    Gray_Pigeon_Server2.0 (GrayPigeonServer2.0)XG_Server2.0.exeAdded by the Troj/GrayBird-O TROJAN!
    GreenBorder Client Manager Service (clnt_ClientMan)LClientMan.exeRelated to GreenBorder Secure your browsing activities on the internet. Note: Located in C:\Program Files\GreenBorder\
    greenstdSystem32Xgreenstd.exe Unclassified.Spyware.61 Note: Located in %system%\
    GridIron X-Factor After Effects Peer #1 (XFACTORAE1)Lxlr8d.exeRelated to GridIron Nucleo For digital post production professionals using Adobe® After Effects® on a multi-processor or new multi-core computer
    Groove Audit Service (GrooveAuditService)LGrooveAuditService.exeRelated to Groove_Manager_Server from IBM allows administrators with onsite servers to audit Groove client activities Note: Located in \%Program Files%\Groove Networks\Groove\Bin\
    Groove Installer Service (GrooveInstallerService)LGrooveInstallerService.exeRelated to Groove_Manager_Server from IBM allows administrators with onsite servers to audit Groove client activities Note: Located in \%Program Files%\Groove Networks\Groove\Bin\
    GrooveRunOnceInstallerLGrooveRunOnceInstaller.exeRelated to Groove_Manager_Server from IBM allows administrators with onsite servers to audit Groove client activities Note: Located in \%Program Files%\Groove Networks\Groove\Bin\
    Group Policy Client (gpsvc)Lgpapi.dllPart of Windows Vista Note:Located in C:\%WINDIR%\System32
    GS30sLGS30s.exeRelated to Gizmo!_Secure USB flash drive software by Crucial
    handle (handle)Xhandle.exeAdded by the SDBOT.CDD WORM! Read the link, rootkit type stealth involved.
    Handling the DHCP requests (DHCP Client)Xdhcpclient.exeMost likely a W32.Toxbot_variant
    HanWangTabletLJWPEN.exeRelated to HanWang_Tablet Hanwang Writing Tablet gives you the power to quickly input handwriting Chinese and Japanese into Microsoft Word, Excel, PowerPoint, MSN, ICQ, WPS and over 100 other software applications easily and pleasurably. Note: Located in \%WINDIR%\System32\
    Hardware Clock Driver (hwclock)Xhwclock.exeAdded by the W32/Hwbot-A WORM!
    Hardware Detection (Serv-U)Xsvchost.exeReported by Kaspersky Anti-Virus as Win32.Serv-U.gen Note: This is not the legitimate Windows process (Which is always found in the System32 folder). This file is found in the System32\drivers\etc\data\ folder.
    Hardware Monitor Service (Hardware Monitor)Xmshms.exeAdded by the Troj/Wollf-A TROJAN!
    Hardware Monitoring Program (ADMService)LadmServ.exeRelated to Avocent Embedded Software and Solutions Division
    HarmonyLRSOBSERV.EXERelated to Rockwell_Automation Inc. FactoryTalk suite
    HASP License Manager (hasplms)Lhasplms.exeRelated to HASP_License Manager from Aladdin Knowledge Systems. HASP HL is a USB Hardware Key or Dongle based software copy protection solution. Note: Located in \%WINDIR%\System32\
    HauppaugeTVServerLHCWTVServer.exe HCWTVS~1.EXERelated to TVServer from Hauppauge Computer Works, Inc. Note: Located in \%Program Files%\WinTV\
    haxdrvXhaxdrv.sysAdded by the Troj/Rootkit-U TROJAN! Read the link, rootkit type stealth involved.
    hcalwayXhcalway.sysAdded by the PigSearch Adware. Read the link, rootkit type stealth involved.
    HDD Information Service (HDDSvc)LHDDSvc.exeRelated to HDD_Information Service from Altrixsoft.com Note: Located in \%WINDIR%\System32\
    HDDlife HDD Access serviceLhldasvc.exeRelated to Hard_disk Access service. Reads S.M.A.R.T. data from all of your hard drives and allows you to see clearly the health and resources of your disks. Note: Located in \%Program Files%\BinarySense\
    Health Key and Certificate Management (hkmsvc)Lkmsvc.dllPart of Windows Vista Note:Located in C:\%WINDIR%\System32
    Help and Support (helpsvc)Xineters.exeIdentified as Malware.Gen Note: Located in \%WINDIR%\System32\
    Help and Support Service (hasvc)Xusnsvc.exeAdded by a variant of the SDBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    hexadecimal (HexadecimaRepresentation)XEdit.exeAdded by the W32/Sdbot-AAY WORM! Note: File name may be different. Read the link, rootkit type stealth involved.
    HF30ServiceLHF30Service.exeRelated to Lock_Folder Password protection for files, folders, and drives. Note: Located in c:\Program Files\Everstrike Software\Hide Folder 3.1\
    hgzXHacker.com.cn.exeAdded by a variant of the Troj/Feutel-CJ TROJAN Note: This worm\trojan is located in C:\%WINDIR%\HgzServer\ Folder.
    HibernationLhibserv.exeRelated to Compaq-Hewlett Packard hibernation service.
    HICOM LAN Bridge VCapiDrv (vcapidrv)?vcapintsvc.exeCould be related to a new version of HICOM LAN Bridge?
    HID Input Service WIN32 (HID_Input_Service_WIN32)Xmsiexecu.exeAdded by the Troj/Raser-AS TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Creates this file SndSystem.sys which acts as a rootkit.
    HID Output Service (HODSrv)Xhpsvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    HiPath Cardserver (FMCardService)LFMCardServ.exeRelated to HiPath service from Siemens. Note: Located in \%Program Files%\Siemens\HiPathCardManager\
    HIPS Configuration Interpreter (UmxCfg)LUmxCfg.exeRelated to HIPS_Firewall Helper Service CA (Computer Associate) Host Intrusion Prevention System. Note: Located in \%Program Files%\CA\SharedComponents\HIPSEngine\
    HIPS Event Manager (UmxAgent)LUmxAgent.exeRelated to HIPS_Firewall Helper Service CA (Computer Associate) Host Intrusion Prevention System. Note: Located in \%Program Files%\CA\SharedComponents\HIPSEngine\
    HIPS Firewall Helper (UmxFwHlp)LUmxFwHlp.exeRelated to HIPS_Firewall Helper Service CA (Computer Associate) Host Intrusion Prevention System. Note: Located in \%Program Files%\CA\SharedComponents\HIPSEngine\
    HIPS Policy Manager (UmxPol)LUmxPol.exeTiny Firewall
    HiWired Client Core Service (HiWiredCore)LHiWired.Client.Core.exeRelated to HiWired_Service from HiWired, Inc. On-line PC services. Note: Located in \%Program Files%\HiWired\PC Check & Connect\
    Horario de WindowsLservices.exeSpanish Windows 2000 "windows time"
    host (host)Xhost.exeAdded by the Troj/GrayBrd-AR TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    Host Process for Win32 ServicesXsvchost.exeAdded by a variant of the SDBOT Note: Located in \%WINDIR%\system\ Note: Use SDFix under supervision.
    host Service For Windows (mshost)Xmshost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\
    Host Services (Host Services)Xsvhosts.exeAdded by the W32/Tilebot-AC WORM! Note: This is not the legitimate Windows process svchost.exe (Notice the difference in the spelling.) This worm\trojan file (svhosts.exe) is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Host Services (Host Services)Xmyhost.exeAdded by the W32/Tilebot-AT WORM! Note: This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Hosts AOL Network Update Services (AOL Update Service)Xaolup.exeAdded by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\System32\

    Engine Version 2.0 by CastleCops

    spacer spacer