CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

O23 List of Windows XP/NT services

Currently 4053 entries and growing...
Last updated on 2008-08-02 17:32:28 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    Microsoft Registry Viewer (Dumpreg)XDUMPREG.EXEAdded by the SDBOT.BXI WORM! Read the link, rootkit type stealth involved.
    Microsoft RPC API Helper (Random Letters)X(Random FileName).sys Troj/Conhook-AG Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K) Installs multiple services. Read Link
    Microsoft Sata emulation (mside)Xmside.exeAdded by the Worm.Opanki.BK WORM! Note: This worm\trojan is located in C:\%WINDIR%\SYSTEM\ Read the technical details
    Microsoft SCC Host Protocol (POOLSVR)Xpoolsv.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    Microsoft SCC Host Protocol (TaskMGM)Xtaskmg.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    Microsoft sdk core (sdk)Xlsass.exeAdded by the Troj/IRCBot-PF TROJAN! Note: Located in C:\%WINDIR%\
    Microsoft Security Center Extension (msscenter)Xmsscntr32.exeIdentified as Danmec/Asprox password-stealing trojan. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft Security Login ServiceXmssecure32.exeAdded by the W32/Vanebot-R WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) Attempts to terminate a number of processes related to security and anti-virus applications.
    Microsoft security update service (msupdate)Xmsvcrtd.exeRelated to a variant of the Trojan.Win32.Agent.NCR family. TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    Microsoft security update service (msupdate)Xmssrv32.exe Troj/Agent-GCE Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K)
    Microsoft Service Manager (winmdgr)Xwinsvcmgr.exeAdded by the W32/Rbot-AAD WORM! Read the link, rootkit type stealth involved.
    Microsoft SQL Server Debug (sql)Xsqldebug.exeAdded by the W32/Tilebot-FF WORM! Note: Located in C:\%WINDIR%\
    Microsoft SSL (ssl)Xssl.exeAdded by the W32.Esbot.C WORM! Note: This Worm\Trojan file is found in the System32 folder and has nothing to do with the (Secure Socket Layer)
    Microsoft Star Window ServiceXstarwin32.exeAdded by the W32/Rbot-FNT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ dllcache\ (XP/WinNT/2K)
    Microsoft Star Window ServiceXsvcshoter.exeAdded by the WORM_SDBOT.ANK WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache (Win9x/Me), C:\%WINDIR%\System32]dllcache (XP/WinNT/2K) provides the remote user virtual control over the affected system, thus compromising system security.
    Microsoft Star Window ServiceXstarwksvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\dllcache\ (Win9x/Me), C:\%WINDIR%\dllcache\ (XP/WinNT/2K)
    Microsoft Startup Manager. (Microsoft Startup Manager)Xmsput.exeAdded by the W32/Sdbot-BAY WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Svc Services DispatcherXsvcsrv.ldrunknown malware
    Microsoft Terminal ServiceXmsterminal.exeAdded by the W32/Sdbot-CPZ WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\DllCache\ (XP/WinNT/2K)
    Microsoft TG MannagerXmtgm.exeAdded by the WORM_SDBOT.EMT WORM! Note: This worm is located in C:\%WINDIR%\ Read the link, allows remote access
    Microsoft Translation Service (MTServ)Xmtserv.exeAdded by the W32/Rbot-GAL WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Updata ver2005 (Microsoft Updata ver2005)Xtw725.exeAdded by the Troj/Feutel-P TROJAN!
    Microsoft UpdateXSCVVC.exeAdded by a variant of the W32/Malware Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Microsoft update (msnupdate)Xwindupdate.exeAdded by the SDBOT.CGV WORM! Read the link, rootkit type stealth involved.
    Microsoft update ServiceXmsiupdate32.exeAdded by the W32/Vanebot-S WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) disabling autostart for the SharedAccess service deactivates the Microsoft Internet Connection Firewall (ICF). Attempts to terminate a number of processes related to security and anti-virus applications
    Microsoft usnsvc ServiceXusnsvc.exeAdded by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\
    Microsoft Validation ServiceXmvsr32.exeDetected as Backdoor.SdBot.bem by AVG-antispyware
    Microsoft Validation ServiceXwmiprsv.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\%WINDIR%\
    Microsoft Virtual Private Network (MS Virtual Private
    Network)
    XMSVPN32.exeAdded by the W32/Rbot-AIO WORM!
    Microsoft Vista Updater SystemXnvcsc23.exeAdded by a variant of the BACKDOOR.IRC.BOT Note: This worm\trojan is located in \%WINDIR%\
    Microsoft Visual BasicXMSVCRT.exeAdded by a variant of the RBOT family of IRC Backdoor trojan. Note: Located in \%WINDIR%\System\ Note: Use SDFix under supervision.
    Microsoft Visual Studio (W32MVS)Xw32mvs.exeIdentified by VBA32 as a variant of the Backdoor.Win32.Agent.cjo malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft VPS ServiceXmsvps.exeAdded by the W32/Rbot-FNI WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) disables the automatic startup of other software
    Microsoft Webserver (Microsoft Webserver)XMicrosoft Webserver.exeAdded by the Troj/Hupigon-FU TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    Microsoft Windows (Microsoft Windows)Xsystem.exeAdded by the W32/Rbot-AMQ WORM! Note: This worm file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Microsoft Windows Avantage Service (Windows Avantage)Xavantage32.exeAdded by the W32/Tilebot-HE WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. disables the automatic startup of other software.
    Microsoft Windows BDA ServiceXsvhba.exeAdded by the W32/Vanebot-P WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) disables the automatic startup of other software
    Microsoft Windows DMR Service (Windows DMR Service)Xdmrproc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ More here
    Microsoft windows FTPdXupdtftpini.exeAdded by the W32/Rbot-FUS WORM! Note: This worm\trojan is located in C:\Windows\dllcache\ (Win9x/Me), C:\%WINDIR%\dllcache\ (XP/WinNT/2K) More] here
    Microsoft Windows HDA ServiceXsvhda.exeAdded by the W32/IRCBot-SL WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft Windows HelpFile (Windows Helpfile)Xservices.exeAdded by the W32/Tilebot-FQ WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. disabling the automatic startup of other software
    Microsoft Windows Internet Connections Manager (net32b)Xnet32b.exeAdded by the W32/Cuebot-N WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Deactivates the Microsoft Internet Connection Firewall (ICF).
    Microsoft Windows Man Service (Windows Man Service)Xwinmgr.exeAdded by the W32/Sdbot-DTL WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Microsoft Windows Protection (Windows Protection
    Service)
    Xwinlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Microsoft Windows Software Update Service (mswsus)Xmswsus.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Windows Spool Service (Windows Spool Service)Xwdfmgr.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ Not to be mistaken with wdfmgr.exe which is part of Microsoft Windows Media Player and located in, C:\WINDOWS\System32\.
    Microsoft Windows Spool Service (Windows Spool Service)Xservices.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) This worm\trojan file is found in the Windows or Winnt folder.
    Microsoft Windows Spooler Service (Windows Spooler
    Service)
    Xwinlogon.exeAdded by the W32/Tilebot-FR WORM!Note: This is not the legitimate Windows process (Which is always found in the System32 folder). This worm file is found in the Windows or Winnt folder. Allows a remote intruder to gain access and control over the computer, read the link.
    Microsoft Windows Spooler Service (Windows Spooler
    Service)
    Xservices.exeAdded by the W32/Tilebot-FW WORM! Note: This is not the legitimate Windows process (Which is always found in the System32 folder). This worm file is found in the Windows or Winnt folder. Allows a remote intruder to gain access and control over the computer, read the link.
    Microsoft Windows SQL Service Xwinesql.exe Win32/IRCBot.UG

    Engine Version 2.0 by CastleCops

    spacer spacer