Need help? Click here to register for free! Absolutely zero advertisements on this site!
$9736.22 of $21422.68
Help CastleCops serve the community on new servers, Donate Here to reach our goal.
O23 List of Windows XP/NT services
Currently 4053 entries and growing... Last updated on 2008-08-02 17:32:28 Eastern.
This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.
KEY:
"L" = Legitimate
"O" = Open to Debate
"X" = Malware/Bad
"?" - Unknown
ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z
Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
Added by Backdoor.Win32.SdBot.aad as identified by Kaspersky. TROJAN!
Note: located in C:\WINDOWS\. Not to be confused with the Original Microsoft file in C:\WINDOWS\system32\
Added by the W32/Rbot-ABD WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) terminate threads and processes read the information
Unknown owner: Location C:\Windows\System32\srvany.exe
In this case srvany.exe is loading resetservice.exe as a service.
May be found in the company of
O20 - Winlogon Notify: reset5 - C:\WINDOWS\SYSTEM32\reset5.dll
Windows XP Product Activation Bypass
So as to avoid the registration process on boot-up.
Typically used on a pirated Operating System.