CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

O23 List of Windows XP/NT services

Currently 4053 entries and growing...
Last updated on 2008-08-02 17:32:28 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    remon (remon)Xremon.sysAdded by the Troj/RKFu-A TROJAN! Read the link, rootkit type stealth involved.
    Remote Acces (WindowsDown)Xservet.exe Troj/Dloadr-AYT
    Remote Acces (WindowsFix)Xservet.exe W32/Sekap-A Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Allows remote access
    Remote Access Controller 4 (RAC) (racsvc)Lracsvc.exeRelated to Dell Open Manage NT Utilities program that allows remote access and control of a computer. This is a common program for hackers to install on a computer, so if it is installed, and you did not install it, it should be removed.
    Remote Account Manager (ramtsvc)Xrasmvc.exeAdded by an Unknown malware Note: Located in \%WINDIR%\System32\mui\
    Remote Administrator Service (r_server)Xsystemram.exeAdded by the Troj/Radnag-B Trojan!
    Remote Administrator Service (r_server)Xr_server.exeAdded by the Troj/Remadm-J TROJAN! Note: This trojan file is found in Program Files\real\RealOne Player\lang folder.
    Remote Administrator Service (r_server)Or_server.exeRelated to r_server.exe part of a remote administrator application that allows a user to work on one or more remote computers. The application contains features such as File Transfer, NT security and Telnet. Note: Located in \%WINDIR%\System32\ If you did not installed this server it is suggested that your remove it
    Remote Break ManagerXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Desktop Help Session Manager (RDSessMgr)Lsessmgr.exeRelated to Microsoft's remote assistance windows plugin. This allows an end user to call for assistance when a remote assistance network service is in place. This process shouldn't be terminated if the fore-mentioned service is in place on your local area network.
    Remote Displays ServiceXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Help Session Manager (Rasautol)Xntsokele.exe W32/Fujacks-AP Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Allows others to access the computer
    Remote HID Service (LvHidSvc)Olvhidsvc.exeRemote access service by Philips Inc. Legitimate, but remote access could be considered dangerous unless monitored carefully.
    Remote Logon ManagerXsmcs.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Remote management (Novell WUser Agent)Lwuser32.exeRelated to Novel, Inc.
    Remote Map ManagerXlssc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Media PlayerXlsscs.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Neon ServicesXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote NetBIOS ManagerXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote NTstat ServicesXsvshost.exeAdded A variant of the Backdoor.Sdbot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Packet Capture Protocol v.0 (experimental)
    (rpcapd)
    Lrpcapd.exeRelated to Winpcap (Windows Packet Capture Library)
    Remote Print Spooler (RPSGV)Xgcsvc.exeAdded by a variant of the Win32.SdBot.aad a TROJAN! identified by F-Secure. Note: This trojan is located in C:\%WINDIR%\
    Remote Procadure Call (RPC) (RpeSs) Xsvchost.exe Troj/Hupigo-UN Read the link, steals information Note: Located in %windir%
    Remote Procedure Call (RPC) Client (RpcClient)Xrpcclient.exeAdded by the W32/Codbot-L WORM!
    Remote Procedure Call (RPC) HelperXrandomCoolWebSearch malware
    Remote Procedure Call (RPC) Helper ( 6Q'8)Xipjp32.exeAdded by the Trojan.Win32.Agent.bi TROJAN! Note: located in \%WINDIR%\
    Remote Procedure Call (RPC) Locator (Locator)Xrpclocator.exeAdded by the W32/Codbot-Q WORM!
    Remote Procedure Call (RPC) Monitoring (Rpcmon)XRpcmon.exeAdded by the W32/Codbot-T WORM!
    Remote Procedure Call (RPC) Net (Rpcnet)LRpcnet.exeRelated to Laptop_Retriever
    Remote Procedure Call (RPC) Relocator (RpcRelocator)Xrelocater.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    Remote Procedure Call (RPC) Remote (RpcRemotes)Xremote.exeAdded by the W32/Mytob-EW WORM! or Troj/Agent-FB TROJAN! Note: This worm\trojan file is found in the System32 folder.
    Remote Procedure Call (RPC) Service (RpcSssvc)XRpcSs.exeAdded by the W32/Cuebot-J WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Note: The file RpcSs.exe is also a good Microsoft file. Before deleting check the propriatiry of the file.
    Remote Procedure Call (RPC) Subsystem (RPCS)Xrpcss.exe W32/Tilebot-JF Read the link, allows remote access
    Remote Procedure Call System (RPCS)XWin.exe Troj/Dropper-PT Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Procedure Call System(RPCS) (RpcS)XRpcs.exeAdded by the Troj/QQRob-ABS TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    Remote Procedure Call System(RPCS) (RpcSe)XRpcse.exeAdded by the Troj/Mdrop-BMK TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Procedure Call System(RPCSss) (RpcSss)XRpcSss.exeAdded by the Troj/QQRob-ACI TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Procedure Call System(RPCSU) (RpcSu)XRpcsu.exeAdded by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    Remote Procedure Call System(RPCSx) (RpcSx)XRpcsx.exeAdded by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    Remote Process KillerORKillSrv.exeThe Windows NT Resource Kits, both NT4 and Windows 2000 Professional, include a remote kill process commandline utility rkill.exe . To be able to kill a process or processes running on a remote server, you must have admin privileges and the rkillsrv.exe service must be installed and running. If this service was not installed by you or an LAN Admin. remove it. Note: Located in \%WINDIR%\System32\
    Remote Reader MachineXssmc.exeAdded by the Backdoor.SdBot.avk as detected by ewido. More here
    Remote Record Service (RemoteRecord)Lremoterecordclient.exeRelated to MSN_TV Note: Located in c:\program files\microsoft corporation\msn remote record service\
    Remote Republic ServicesXsvshost.exeAdded by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\
    Remote Run ServicesXsvshost.exeAdded by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\
    Remote Services Manager (RSMSS)X(Trojan file name)Added by the Troj/Bckdr-BBK TROJAN!
    Remote Solver for COSMOSFloWorks 2006LStandAloneSlv.exeRelated to COSMOS_FloWorks From COSMOS. CAD program. Note: Located in C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\
    Remote Storage (Rmtstrg)Xtaskmgr.exeAdded by the Troj/Spy-UN TOJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K) Read the link, monitors websites visited and report them to a remote site
    Remote Storage (RS) (Rmtstrg2)Xtaskmgr.exeAdded by a varian the Troj/Spy-UN TOJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K) Read the link, monitors websites visited and report them to a remote site
    Remote Task Manager service (RTM)LRTMService.exeRelated to Remote_Task_Manager remote control suite. Note: Located in C:\Program Files\Remote Task Manager\
    Remote TCP ServicesXvcmon.exeAdded by the W32/Tilebot-HX WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) disabling the automatic startup of other software.

    Engine Version 2.0 by CastleCops

    spacer spacer