CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

O23 List of Windows XP/NT services

Currently 4053 entries and growing...
Last updated on 2008-08-02 17:32:28 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    Mouse Hardware Sync (mousehs)Xmousehs.exeAdded by the Troj/Bdoor-HU WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Mouse Movement Monitor (mousemm)Xmousemm.exeAdded by the W32/Cuebot-E WORM!
    Mouse Synchronization (mousesync)Xmousesync.exeAdded by the W32/Esbot-A WORM!
    MousebXMOUSEB.EXEAdded by the SDBOT.CRQ WORM! Read the link, rootkit type stealth involved.
    Movielink Core ServiceLMOVIEL~1.EXEAssociated with Movielink online movie download service with help from IBM. Has also been seen with the file name MOVIEL~2.EXE
    Mozy Backup Service (MozyBackup)Lmozybackup.exeRelated to Mozy Free backup at a secure, remote location. Note: Located in C:\Program Files\Mozy\
    MozyBackupLmozybackup.exeRelated to Mozy Free backup at a secure, remote location. Note: Located in C:\Program Files\Mozy\
    MozyHome Backup Service (mozybackup)Lmozybackup.exeRelated to Mozy Free backup at a secure, remote location. Note: Located in C:\Program Files\MozyHome\
    MozyPro Backup Service (mozyprobackup)Lmozyprobackup.exeRelated to Mozy Free backup at a secure, remote location. Note: Located in C:\Program Files\MozyPro\
    MPICH2 Process Manager, Argonne National Lab
    (mpich2_smpd)
    Lsmpd.exeRelated to MPICH2_Process Manager SMP client. Note: Located in \%Program Files%\MPICH2\bin\
    MpServiceLMPSERVIC.EXERelated to Canon Inc. http://www.canon.com/
    mr2kservLmr2kserv.exeDell Open Management software installs this service http://www.anti-spy.info/process/mr2kserv.exe.html
    MrayPigeonServerXM_Server2006.exe Troj/Hupigon-IV Note: Located in %windir% Read the link, allows remote access
    MRFCKDLLXMRFCKDLL.SYSAdded by the Troj/NtRootK-F TROJAN! Read the link, rootkit type stealth involved.
    MRMonitor (MegaMonitorSrv)LMonitor.exeRelated to Dell SAS RAID Storage Manager. Note: Located in \%Program Files%\Dell SAS RAID Storage Manager\MegaMonitor\
    MrobeServiceLMRobeService.exeRelated to Olympus_America_Inc Imaging products.
    MrPostmanLWrapper.exeRelated to MrPostman: POP email access.
    MRU Web Service (MRUWebService)LApache.exeRelated to Apache web server Note: Located in \%Program Files%\Marvell\61xx\Apache2\bin\
    Ms Builders (Ms Builder)XWupated.exeAdded by the W32/Agobot-SS WORM!
    MS Common ServiceXmscomserv.exeAdded by the Troj/Zlob-RF TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    MS Dns ServiceXwincntrl.exeAdded by a variant of the Sdbot/Rbot worm
    MS Dns Service (WinNet)Xwincntrl.exeAdded by the W32/Rbot-AYH WORM! Note: This worm\trojan file is found in the System32 folder.
    MS DTC consoleXmsdtc.exeAdded by the W32/Sdbot-DTO WORM! Note: This worm\trojan is located in C:\%WINDIR%
    MS Ineterner Explorer Update Services (msieupservice)Xmsupsrv.exeListed as "Adware.SponsorBox.Process". by SuperAdBlocker
    MS Internet Countermeasures Framework (ICF)X\System32:svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note DO NOT delete the svchost.exe file.
    MS Internet Countermeasures Framework (ICF)Xicf.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\
    MS NET ServiceXwiadss.exeIdentified as a variant of the Net-Worm.Win32.Kolabc.b worm. Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    MS Office Updater ServiceXmsrvs32.exeAdded by the W32/Tilebot-HM WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder
    MS Shadow Copy Software (ScSoft)Xscsoft.exe W32/Tilebot-JP Read the link, allows remote access
    MS Software Shadow Download Provider (dnlsvc)Xdnlsvc.exeAdded by DnlSvc.Process TROJAN!
    Ms Valud Loader (Ms Valud Load)XSvhots.exeAdded by the W32/Agobot-SP WORM!
    Ms-javaXms-java.exeAdded by a variant of the Backdoor:Win32/Iroffer TROJAN! Note: This worm\trojan is located in \%WINDIR%\System32\System\ Read the link, allows remote access
    MSAPI32SvcXlcrss.exeAdded by a variant of the BACKDOOR.IRC.BOT Note: This worm\trojan is located in \%WINDIR%\
    MSComXmscom.exeAdded by the W32.Woredbot TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    MSCommmandXmswincom32.exeAdded by the W32/Rbot-FMM WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache (Win9x/Me), C:\%WINDIR%\System32\dllcache (XP/WinNT/2K) Disables the automatic startup of other software, deactivates the Microsoft Internet Connection Firewall (ICF).
    MSCoolServXmscolsrv.exeRahack virus
    MSCRS(mscrs) (MSCRS)Xmscrs.exeAdded by a variant of the SDBot family of worms and IRC backdoor Trojans.
    MSCSPTISRVLMSCSPTISRV.exeRelated to Sony Corporation.
    MsdebugsrvXdbg32hlp.exeAdded by the SDBOT.CNG WORM! Read the link, rootkit type stealth involved.
    msdelv (msdevl)Xmsdevl.exeAdded by the W32/IRCBot-VJ WORM! Note: This worm\trojan is located in C:\Program Files\Common Files\System\
    msdirectxXMSDIRECTX.SYSAdded by the Troj/NtRootK-F TROJAN! Note: This trojan file is dropped by various other worms and trojans to hide their processes. Read the link, rootkit type stealth involved.
    msdllXmsdll.exeAdded by a variant of the IRCbot family of worms and IRC backdoors. Note: located in C:\%WINDIR%\system\
    MSDN Driver (msdndr)Xmsdndr.pifAdded by the Troj/HacDef-EQ TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Msdn Update 32 (msdnupdate32)Xmsdnupdate32Added by the W32/Tilebot-M WORM! Read the link, rootkit type stealth involved.
    Msdn Update 32 (msdnupdate32)Xmsdnupdate32.exeAdded by the SPYBOT.AHT WORM! Read the link, rootkit type stealth involved.
    Msdtc ManagerXwinlogin.exeAdded by the W32/Rbot-FKU WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    MSDV Driver (msdvdr)Xmsdvdr.pifA variant of the HackerDefender rootkit . Note: Located in \%WINDIR%\System32\
    msecure (mcsecure)Xmcsecure.exeAdded by the SDBOT.BZJ WORM! Read the link, rootkit type stealth involved.
    mserv.exeXmserv.exeRelated to Trojan.Win32.Killav.br
    msfsrXmsfsr.sys W32/Piggi-B Note: Located in %windir%\system32 Read the link, changes security settings and may disable antivirus programs

    Engine Version 2.0 by CastleCops

    spacer spacer