CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 4053 entries and growing...
Last updated on 2008-08-02 17:32:28 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    Client/Server Runtime Server Subsystem (CSRSS)Xcsrss.exe W32/IRCBot-UN Note: Located in %windir%, not to be confused with the legitimate file in %windir%\system32 (%windir%\system on windows 98/ME) Read the link, allows remote access and steals information
    Client32Lclient32.exeNetSupport Manager by "NetSupport Ltd.".
    Cliente de seguimiento de vinculos distribuidosLservices.exeSpanish Windows 2000 distributed links tracking client
    Cliente DHCPLservices.exeSpanish Windows 2000 DHCP client
    Cliente DNSLservices.exeSpanish Windows 2000 DNS client
    Clients Server Runtime ProcessXcsrss.exeAdded by the W32/Sdbot-CPF WORM! Note: This worm\trojan is located in C:\%WINDIR% This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    Clients Server Runtime Process (Windows Internet)Xcsrss.exeAdded by the W32/Sdbot-CPF WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Clip BookXgezi-yasuo.exe Troj/QQHelpe-CY Note: Troj/QQHelpe-CY installs a number of files besides gezi-yasuo.exe in a few locations. Read the link
    ClipBo0kXbook.exeAdded by a variant of the BKDR_HUPIGON.EVG backdoor Trojan. Identified by Trend Micro. Note: Located in \%ROOT%\
    clmss (Content List Management Sub System)Xclmss.exeAdded by the W32/Tilebot-AO WORM! Note: This worm file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Clr_uiLatinpdxx.sysRelated to ATI Specialized PCD VBI Codec. Note: Located in \%WINDIR%\System32\drivers\
    CMG Shield (auet4iogie5an)Xnvslzrygvb.exeAdded by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename.
    CMG Shield (CMGShield)LCredant.exeRelated to CMG_Shield Application from Credant Technologies. CREDANT Mobile Guardian Enterprise Edition (CMG EE) is an integrated, policy-based mobile data security, Note: Located in \%WINDIR%\System32\
    CMGShieldLCmgShieldSvc.exeRelated to Credant_Technologies data encryption software for laptop and USB encryption to CD-DVD recorders, iPods and Smart Phones. Note: Located in \%WINDIR%\System32\
    CNG Key Isolation (KeyIso)Llsass.exePart of Windows Vista Note:Located in C:\%WINDIR%\System32
    Cobian Backup 8 service (CobBMService)LcbService.exeRelated to Cobian_Backup An Open Source projects. Note: Located in C:\Program Files\Cobian Backup 8\ Note Open souce project can be modified. Make sure you scan the program with a Virus protection program before using.
    CodecXWINCODEC.EXEAdded by the SDBOT.CJO WORM! Read the link, rootkit type stealth involved.
    COGECO Security Services (BackWeb Plug-in - 9867844)OSERVIC~1.EXERelated to COGECO_F-Secure Backweb application. Note: Located in \%Program Files%\COGECO~1\backweb\9867844\Program\
    Cognos ReportNetLcogbootstrapservice.exeRelated to Cognos_ReportNet Business Intelligence software. Note: located in C:\Program Files\Cognos\crn\bin\
    Cognos ReportNet (ruzxj7ol3oeak)Xbnoilfhxkgvz.exeAdded by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename.
    ColdFusion Graphing ServerLJRun.exeRelated to MacroMedia_ColdFusion products. Made by MacroMedia,Inc.
    ColdFusion Management Repository Server (ColdFusion
    Management Repository)
    Ljrun.exeRelated to MacroMedia_ColdFusion products. Made by MacroMedia,Inc.
    ColdFusion Management ServiceLCANamingAdapter.exeRelated to MacroMedia_ColdFusion products. Made by MacroMedia,Inc.
    ColdFusion Monitoring Service (ClusterCATS Service)Lccmgr.exeRelated to MacroMedia_ColdFusion products. Made by MacroMedia,Inc.
    ColdFusion MX 7 Search ServerLk2admin.exeRelated to Cold_Fusion from Adobe Systems Incorporated. Note: Located in \%ROOT%\
    ColdFusion MX Application ServerLjrunsvc.exeRelated to Macromedia Cold Fusion software.
    ColdFusion MX ODBC ServerLswstrtr.exeRelated to Macromedia Cold Fusion software.
    Collaboration Runtime Service (xmppd-jse)Lxmppd-jse.exeRelated to Sun_Java_Studio_Enterprise Software. Note: Located in \%Program Files%\Sun\jstudio_ent81\collab\bin\
    COM Host (comHost)LcomHost.exeRelated to Norton/Symantec Internet Security
    COM Message Transfer (mscommt)Xsvchost.exe -k mscommtAdded by the Troj/Dbit-A TROJAN!
    COM+ Component Service (COMCSVC)Xwinmgnt.exeAdded by unknown malware, the file winmgnt.exe may be a Serv-U FTP server used to download other malicious files to your computer. File location is in the System32 folder.
    COM+ Event System (EventSystem)Lsvchost.exe -k LocalServicePart of Windows Vista Note:Located in C:\%WINDIR%\System32
    COM+ Interface (svcmngr)Xsvcgirl.exeAdded by an unknown malware. Note: This worm\trojan is located in C:\%WINDIR%\TEMP\ folder.
    COM+ MessagesXsvchosts.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    COM+ System Application (COMSysApp)Ldllhost.exePart of Windows Vista Note:Located in C:\%WINDIR%\System32
    COM+ System Applications (COMSystemApp)Xdllhost.exe W32/SillyFDC-AV Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K) Turns off anti-virus applications and Steals information
    COM+ System Client (ComSysCnt)Xcmsvc.exeIdentified as the SdBot.bis worm Note: This worm is located in C:\WINDOWS\repair\
    COM+ System Service (COMSS)XSSMS.EXEAdded by unknown malware. File location is in the System32 folder.
    COM+ System Service (DLLHOST)Xdllhost.exeAdded by the Backdoor.Win32.SdBot.xd as identified by Kaspersky TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    COM+ System Source (COMSysSRC)Xvmnat.exe W32/Tilebot-JE Note: Located in %windir%\system32 Read the link, allows remote access
    Com4QlbLCom4Qlb.exeRelated to HP_Compaq Buttons. Note: Located in \%Program Files%\Hewlett-Packard\HP Quick Launch Buttons\
    Command Lsass ServicesXsvshost.exeAdded by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\
    Command Service (cmdService)Xcommand.exeAdware
    CommServerLCommSvr.exeRelated to the HiPath 1220 digital PBX system from Siemens. For more information Click_Here File location is in the Program Files\Siemens\HiPath 1220\CommServer2.0 folder.
    CommServer (audieqaad)Xlmguc.exeAdded by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename.
    Comodo Anti-Virus and Anti-Spyware ServiceLcavasm.exeRelated to Comodo Anti-Virus and Anti-Spyware Service Note: Located in \%Program Files%\Comodo\common\CAVASpy\
    Comodo Application Agent (CmdAgent)Lcmdagent.exeRelated to Comodo_Firewall from Comodo. Note: Located in C:\Program Files\Comodo\Firewall\
    COMODO Firewall Pro Helper Service (cmdAgent)Lcmdagent.exe Comodo_Firewall
    Compaq Advisor (Compaq_RBA)Lcompaq-rba.exeRelated to Compaq
    Compaq DMI Web AgentLWebDmi.exeRelated to Compaq Computer.

    Engine Version 2.0 by CastleCops

    spacer spacer