Need help? Click here to register for free! Absolutely zero advertisements on this site!
O23 List of Windows XP/NT services
Currently 4053 entries and growing... Last updated on 2008-08-02 17:32:28 Eastern.
This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.
KEY:
"L" = Legitimate
"O" = Open to Debate
"X" = Malware/Bad
"?" - Unknown
ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z
Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename.
Related to eTrust_Internet_Security_Suite from
Computer Associates International Inc. Note: Located in C:\Program Files\CA\eTrust Internet Security Suite\
Added by an unidentified TROJAN! of the Sdbot family. Note: This is not the legitimate Windows Process smss.exe. (Which is found in the System32 folder.) This worm/trojan file (smss.exe) is found in the Windows or Winnt folder.
Related to Brazil_r/s_CaReTaKeR-CT NetMgr. Brazil r/s is the industry standard for high-end quality, flexibility, reliability, and artist-friendly workflow in 3ds Max. Note: Located in \%ROOT%\sfmgr\
Identified by Kaspersky as a variant of the Trojan-Downloader.Win32.Agent.jhj Trojan. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
Identified by Kaspersky as a variant of the Backdoor.Win32.SdBot.aad worm and IRC backdoor. Note: located in \%WINDIR%\ Note: Use SDFix under supervision.