CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 4053 entries and growing...
Last updated on 2008-08-02 17:32:28 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    M-Audio CMIDI Installer (MA_CMIDI_InstallerService)LMA_CMIDI_Inst.exeRelated to M-Audio_CMIDI Installer from Avid Technology, inc. Note: Located in C:\Program Files\M-Audio MA_CMIDI\
    M-Audio Fast Track Installer
    (FastTrackInstallerService)
    LMAUSBFTInst.exeRelated to M-Audio_Fast_Track Installer from Avid Technology, inc. Note: Located in C:\Program Files\M-Audio\Fast Track USB\
    M-Audio Fast Track Pro Installer
    (MAudioFAstTrackProService)
    LMAUSBFTPInst.exeRelated to M-Audio_Fast_Track Pro Installer from Avid Technology inc. Note: Located in \%Program Files%\M-Audio\Fast Track Pro\
    M-Audio Ozone Installer (OzoneInstallerService)Lozinst.exeRelated to M-Audio_Ozone products. Note: Located in C:\Program Files\M-Audio\Ozone\Install\
    M-Audio Producer USB Installer (MAudioProducerService)LMAUSBProducerInst.exeRelated to M-Audio_Producer_USB Installer from Avid Technology, Inc. Note: Located in \%Program Files%\M-Audio\Producer USB\
    M-BUS/M-NET Administration (MCONTROL)Lmcontrol.exeRelated to Siemens Energy & Automation Platform. Note: located in C:\Program Files\ProcessSuite\MBUSDRVR\
    M1 Licensing Helper (iLicenseSvc)LiLicenseSvc.exeRelated to Related to GE_Fanuc_Automation enable you to act in real-time to optimize productivity and increase profitability. Note: located in C:\WINDOWS\Intellution\
    M1crosoft AgantXqhotsew.exeAdded by a variant of the Backdoor.Sdbot Note: Located in \%WINDIR%\System32\dllcache\
    Ma-Config Service (maconfservice)Lmaconfservice.exeRelated to Ma-Config from CybelSoft Find the componants hardware, and programs installed on your computer. (The site is in french.) Note: Located in \%Program Files%\ma-config.com\
    mac128Xmac128.sysAdded by the Troj/Klutz-A Trojan!
    MacDriveServiceLMacDriveService.exeRelated to MacDrive From Mediafour Corp. Share your file between MAC and Windows Operating systems. Note: Located in \%Program Files%\Mediafour\MacDrive 7\
    MacFormatServiceLFORMATM.EXERelated to Conversions Plus from DataViz
    Machine Debug Manager (Machine_Dbg-Mgr)Xmdm.exeAdded by a variant of the SdBot.aad family of worms and IRC backdoor Trojans. Note: This trojan is located in C:\WINDOWS\AppPatch\
    Machine Debug Manager (MCH_Debug)Xmdm.exeDetected as Backdoor.Win32.SdBot.aad by Kapersky Note: Located in C:\WINDOWS\Resources
    Machine Debug Manager (MDM)Lmdm.exeVisual studio debuger, if you install vs2003, mdm.exe is found in c:/program files/common files/microsoft shared/vs7debug For more info Click_Here
    Macro Scheduler Service (mschedsvc)Lmsschedsvc.exeRelated to Macro_Scheduler from MJT Net Ltd. Save time and increase productivity by automating frequent tasks.
    Macromedia Licensing ServiceLMacromedia Licensing.exeRelated to Macromedia products: Flash, Dreamweaver, etc.
    Macromedia Updater (mmupdate)X19D.tmp".exeAdded by a variant of the Win32.Small.oa TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\TEMP\ The filename is randum in the format xxxx.tmp".exe
    Madentec Discover MonitorLMadResServ.exeRelated to Madentec_Discover Monitor from Madentec Limited. Note: Located in \%Program Files%\Madentec Limited\Discover\Services\
    Madentec USBLMadWinServ.exeRelated to Madentec_USB discover service. Note: Located in \%Program Files%\Madentec Limited\Discover\Services\
    MagicTuneEngineLMagicTuneEngine.exeRelated to MagicTune_Engine from Samsung. Magic Tune Premium is an update of MagicTune 3.6 for Samsung monitors. Note: Located in C:\Program Files\MagicTune Premium\
    Mailgate Mail/Proxy ServiceLmgatesvc.exeMailgate Internet Connectivity Server
    MailList ControllerLamlcSVC.exeRelated to MailList Controller from arclab.com Note: Located in \%Program Files%\Arclab\MailList Controller\
    Mamutu Service (Mamutu)La2service.exeRelated to Manatu service from Emsi Software . Protects against completely new pests. Note: Located in \%Program Files%\Mamutu\
    Manageer Network ConnectionsXtelcmd.exeBAD - Look how manager is spelled.
    Manageer Network Connections (Kern32)Xtelcmd.exeA new service added by the Troj/Agent-CP TROJAN, with a display name of Manageer Network Connections.
    Management Consultants (CLMCs)Xclmcs.exeAdded by a variant of the Backdoor.Sdbot Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Management System (XSML)Xsxml.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Manager (Windows XP Manager)Xmsnmgr.exeAdded by the W32/Kassbot-L Read the link, rootkit type stealth involved.
    Managing FAT and NTFS partitions (Defragmentation
    Manage)
    Xdfrgfat16.exeAdded by the W32/Codbot-N WORM!
    Mangomind Drive Repair (MindRepair)Ldirtcon.exeRelated to Mangomind access your business critical files from anywhere, at any time, from any computer. Note: Located in C:\Program Files\Mango\Mind\Utilities\
    MarkVision Server (MvServer)Llexmvservice.exeRelated to MarkVison_Server From Lexmar. Note: Located in C:\WINDOWS\SYSTEM32\
    MarkVision Web Server (MvWebServer)Llexwebservice.exeRelated to MarkVison_Server From Lexmar. Note: Located in C:\WINDOWS\SYSTEM32\
    Marvell RAID Event Agent (Marvell RAID)Lmvraidsvc.exeRelated to Marvell_RAID Event Agent. Note: Located in \%Program Files%\Marvell\61xx\svc\
    Mass Effect(TM) Xbox 360Xmfxbox.exe W32/Spybot-MS Read the link, allows remote access
    Mass Effect™ Xbox 360Xmfxbox.exeAdded by the W32/Spybot-MS WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) disabling the automatic startup of other software
    MATLAB Server (matlabserver)Lmatlabserver.exeRelated to The MathWorks Inc.
    MaxBackServiceIntLMaxBackServiceInt.exeRelated to Maxtor_backup service. Note: Located in C:\Program\Maxtor\Maxtor Backup\
    MaxSyncService (NTService1)LSyncServices.exeRelated to Maxtor_OneTouch service. Note: Located in C:\Program\Maxtor\OneTouch\Utils\
    Maxtor Performance Analysis ToolXwinrcn.exe Troj/IRCBot-VY Read the link, allows remote access
    Maya 6 PLE Documentation ServerLwrapper.exeRelated to Alias Systems Corp.
    Maya 7.0 Documentation Server (maya70docserver)Lwrapper.exeRelated to Maya
    MBackMonitorLMBackMonitor.exeMcafee related
    MBAMServiceLmbamservice.exe Malwarebytes'_Anti-Malware
    MC/Empower i.collect Service (iCollectService)Licserv.exean internet cleaning utility issued by various ISP's for their customers use
    McAfee AgentLmyAgtSvc.exeRelated to Network Associates, Inc.
    McAfee Alert Manager (AlertManager)Lamgrsrvc.exeRelated to McAfee_Alert_Manager , http://www.mcafee.com/ deals with alert management. Note: Located in C:\Program Files\Network Associates\Alert Manager\
    McAfee AntiSpyware Real-Time Scanner
    (McAfeeAntiSpyware)
    LMsssrv.exeRelated to Network Associates, Inc.
    McAfee AntiSpyware ServiceLmassrv.exeRelated to McAfee AntiSpyware service.
    McAfee Application Installer Cleanup?012703~1.EXE Appears to be related to a mcafee uninstaller, if it is still present after a reboot, it should be removed
    McAfee Desktop Firewall Service (FireSvc)LFireSvc.exeRelated to McAfee Desktop Firewall Service. Note: located in C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\
    McAfee E-mail Proxy (Emproxy)Lemproxy.exeRelated to McAfee_Email_Proxy c:\program files\common files\mcafee\EmProxy\
    McAfee FirewallLCPD.EXERelated to Network Associates
    McAfee Framework Service (McAfeeFramework)LFrameworkService.exeMcAfee/CA related
    McAfee HackerWatch ServiceLHWAPI.exeRelated to McAfee_HackerWach Service installed by the McAfee Internet Security suite and whose role is to update the HackerWatch.org website with any suspected hacker attack which you decide to report to the HackerWatch service run by McAfee. Down to end-user preference. Note, however, that this service, introduced in mid-2006, has a tendency to gobble up memory on some PCs, from 30Mb to 50Mb. Read the recommandations. Note: Located in C:\Program Files\Common Files\McAfee\HackerWatch\
    McAfee Internet security suiteXAvsynmgr.exe W32/Tilebot-KC Note: Located in C:\Windows Turns off anti-virus applications, Allows others to access the computer. Read the link
    McAfee Log Manager (McLogManagerService)Lmclogsrv.exeRelated to McAfee_SecurityCenter Log Manager. Note: Located in C:\Program Files\McAfee\MSC\
    McAfee McShield (McShield)Lmcshield.exeRelated to McAfee_Virus_Shield Note: Located in \%Program Files%\McAfee\VirusScan Enterprise\
    McAfee Network Agent (McNASvc)Lmcnasvc.exeRelated to McAfee_Network_Agent Note: Located in c:\program files\common files\mcafee\mna\
    McAfee Personal Firewall Service (MpfService)LMPFSrv.exeRelated to McAfee_Personal_Firewall Service. Note: Located in C:\Program Files\McAfee\MPF\
    McAfee Personal Firewall Service (MpfService)LMPFSERVICE.exeRelated to McAfee.com Personal Firewall. Note: Located in \%Program Files%\McAfee.com\PERSON~1\
    McAfee Privacy Service (GuardDogEXE)LGUARDDOG.EXEBelongs to the software McAfee Internet Security or McAfee Privacy Service. For more information Click_Here
    McAfee Privacy Service (MPS9)Lmps.exeRelated to McAfee_Privacy_Service Includes many features for families online including Internet content filtering, blocking personal information from being sent, an event log, and Internet time limits. Note: Located in C:\Program Files\McAfee\MPS\
    McAfee Protection Manager (mcpromgr)Lmcpromgr.exeRelated to McAfee_Integrated_Security Platform. Note: Located in C:\Program Files\McAfee\MSC\
    McAfee Proxy Service (McProxy)Lmcproxy.exeRelated to McAfee Proxy Service Note: Located in c:\Program Files\COMMON~1\mcafee\mcproxy\
    McAfee Real-time Scanner (McShield)Lmcshield.exeRelated to McAfee_Virus_Shield Note: Located in C:\Program Files\McAfee\VIRUSSCAN\
    McAfee Redirector Service (McRedirector)Lredirsvc.exeRelated to McAfee_Redirector Service Module. Note: Located in c:\program files\common files\mcafee\redirsvc\
    McAfee Scanner (McODS)Lmcods.exeRelated to McAfee_VirusScan On Demand Scan. Note: Located in C:\Program Files\McAfee\VIRUSSCAN\
    McAfee Security Agent Taskbar Extension.XMctray.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    McAfee SecurityCenter Update ManagerLmcupdmgr.exeMcAfee Antivirus updater
    McAfee SecurityCenter Update Manager (mcupdmgr.exe)Lmcupdmgr.exeMcAfee Update manager - http://castlecops.com/s5681-MCUPDMGR_EXE.html
    McAfee Services (mcmscsvc)Lmcmscsvc.exe Related to mcafee
    McAfee SpamKiller Server (MskService)LMSKSrvr.exePart of McAfee Spamkiller. http://computercops.biz/s6154-MSKSrvr_exe.html
    McAfee SpamKiller Service (MSK80Service)LMskSrver.exeRelated to McAfee SpamKiller Note: Located in C:\Program Files\McAfee\MSK\
    McAfee SystemGuards (McSysmon)Lmcsysmon.exeRelated to McAfee_SystemGuards Service. Note: Located in C:\Program Files\McAfee\VIRUSSCAN\
    McAfee Task Manager (McTaskManager)LVsTskMgr.exeRelated to Network Associates Virus protection software. Previously known as McAfee.
    McAfee Task Scheduler (McTskshd.exe)Lmctskshd.exeRelated to McAfee_Task_Scheduler Note: Located in C:\Program Files\McAfee\MSC\
    McAfee Update Manager (mcmispupdmgr)Lmcupdmgr.exeRelated to McAfee_SecurityCenter Update Manager. Note: Located in C:\Program Files\McAfee\MSC\
    McAfee User Manager (mcusrmgr)Lmcusrmgr.exeRelated to McAfee_SecurityCenter MISP User Manager. Note: Located in C:\Program Files\McAfee\MSC\
    McAfee Wireless Network Security Service (MWLSvc)LMwlSvc.exeRelated to McAfee_Wireless_Security_Service, http://www.fileresearchcenter.com/M/MWLSVC.EXE-6002.html Note: Located in \%Program Files%\Mcafee\MWL\MwlSvc.exe
    McAfee Wireless Security Service (MwlSvc)LMwlSvc.exeRelated to McAfee_Wireless_Security_Service Note: located in C:\PROGRA~1\McAfee\MWL\
    McAfee WSC Integration (McDetect.exe)Lmcdetect.exeRelated to McAfee WSC Integration.
    McAfee.com McShield (McShield)Lmcshield.exeRelated to McAfee
    McAfee.com Personal Firewall ServiceLMPFSERVICE.exeRelated to McAfee.com Personal Firewall
    McAfee.com VirusScan Online Realtime Engine (MCVSRte)Lmcvsrte.exeMcAfee AntiVirus
    McciCMServiceLMcciCMService.exeRelated to McciCMService from Motive Communications. Note: Located in \%Program Files%\Common Files\Motive\
    MCFservice (mcfdrv)Xmcfdrv.sysAdded by the TROJ_ROOTKIT.R TROJAN! Read the link, rootkit type stealth involved.
    mchInjDrvXmc2A.tmpAdded by the Dialer.ICcontrol DIALER! Note: This malware can make the modem dials long-distance phone numbers that were not configured in the system. This malware file can be found in the Documents and Settings\[CURRENT USER]\Local Settings\Temp folder.
    mcmmng32 (Microsoft Control Manager)Xmcmmng32.exeAdded by the W32/Tilebot-HK WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. disabling the automatic startup of other software
    mcpLmcp.exeTransbase® CD, http://www.transaction.de/ permits the distribution of data base contents on CD/DVD ROM and a following actualization of the data over the Web to Transbase® CD unites in ideal way variable and static data. Note: Located in c:\opt\MBCASE\pm\bin\mcp
    McShieldLmcshield.exeRelated to McAfee_Virus_Shield Note: Located in \%Program Files%\Common Files\Network Associates\McShield\
    MD Simple Burner DB Access Service (mdrcdb)Lmdrcdb.exeSony Corp. MiniDisk Simple Burner
    MD Simple Burner Service (NetMDSB)LNetMDSB.exeSony Corp. MiniDisk Simple Burner
    MDaemon - Alt-N Technologies, Ltd.LMDAEMON.EXERelated to MDaemon,a Windows-based email server.
    MdeRyXrpe.sysAdded by the Backdoor.Ryejet TROJAN! Read the link, rootkit type stealth involved.
    MEAOI Service (MEAOI)X_meaoi.exeAdded by the W32/Tilebot-AM WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Media Center Receiver Service (ehRecvr)LehRecvr.exeRelated to Media_Center_Receiver Service from Microsoft. Note: Located in \%ROOT%\%WINDIR%\eHome\
    media playr (mediaply)Xmediaply32.exeAdded by a variant of the IRCbot family of worms and IRC backdoors. Note: located in C:\%WINDIR%\
    Mediabee (Mediabee Desktop Server)LMbXmlRpcServer.exeRelated to Mediabee Group Planner & Dashboard
    MediaMall ServerLMediaMallServer.exeRelated to MediaMall Server. Access to Internet video services, delivered over broadband to the Entertainment System. Note: Located in \%Program Files%\MediaMall\
    MediaMax XL Service (MediaMaxXLService)LMediaMaxXLService.exeRelated to MediaMax_XL from Streamload, Inc. An application that automatically backs up your files and syncs files between computers. Note: Located in C:\Program Files\Streamload\MediaMax XL\
    Medie Sariel Number ServicesXmoviemk.exeAdded by the Troj/DownLd-AAP TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    MemDRV (vdnt32)Xvdnt32.sysAdded by the Troj/Haxdoor-AA TROJAN!
    Memeo (BMUService)LMemeoService.exeRelated to Memeo backup service. Note: Located in C:\Program Files\Tanagra\Memeo\
    Memorex Network Analysis ToolXwinsntp.exeAdded by the W32/Vanebot-AT WORM! Note: This worm is located in C:\%WINDIR%\dllcache\
    Memory Check Service (AcerMemUsageCheckService)LMemCheck.exeFound on Acer laptops
    mental ray 3.5 Satellite (32-bit)
    (mi-raysat_3dsmax9_32)
    Lraysat_3dsmax9_32server.exeRelated to Autodesk_3ds_Max_9_3D_animation Create rich and complex design visualization. Note: Located in D:\3dsMax9\mentalray\satellite\
    mental ray 3.5 Satellite (32-bit)
    (mi-raysat_3dsmax9_32)
    Lraysat_3dsmax9_32server.exeRelated to Autodesk_3ds_Max_9_3D_animation Create rich and complex design visualization. Note: Located in \%Program Files%\Autodesk\3ds Max 9\mentalray\satellite\
    mental ray 3.5 Satellite (64-bit)
    (mi-raysat_3dsmax9_64)
    Lraysat_3dsmax9_64server.exeRelated to Autodesk_3ds_Max_9_3D_animation Create rich and complex design visualization. Note: Located in \%Program Files%\Autodesk\3ds Max 9\mentalray\satellite\
    mental ray 3.5 Satellite for Autodesk VIZ 2008
    (mi-raysat_VIZ2008_32)
    Lraysat_VIZ2008_32server.exeRelated to Autodesk on line game. Note: Located in \%Program Files%\Autodesk\VIZ2008\mentalray\satellite\
    mental ray 3.6 Satellite for Autodesk 3ds Max 2008
    32-bit 32-bit (mi-raysat_3dsMax2008_32)
    Lraysat_3dsMax2008_32server.exeRelated to Autodesk on line game. Note: Located in \%Program Files%\Autodesk\VIZ2008\mentalray\satellite\
    mental ray 3.6 Satellite for Autodesk 3ds Max 2009
    32-bit 32-bit (mi-raysat_3dsMax2009_32)
    Lraysat_3dsMax2009_32server.exeRelated to Autodesk_3ds_Max_9_3D_animation Create rich and complex design visualization. Note: Located in \%Program Files%\Multimedia\Autodesk\3ds Max 2009\mentalray\satellite\
    Merak GroupWare Server (MerakCalendar)Lcalendar.exeRelated to Merak_GroupWare from Merak. Note: Located in \%Program Files%\Merak\
    Merak Instant Messaging Server (MerakIM)Lim.exeRelated to Instant_Messaging from Merak. Note: Located in \%Program Files%\Merak\
    Merak Mail Server Control (MerakControl)Lcontrol.exeRelated to Merak_Mail_Server Software. A high performance mail server software suite for Windows or Linux
    Merak Mail Server POP3/IMAP (MerakPOP3)Lpop3.exeRelated to Merak_Mail_Server Software. A high performance mail server software suite for Windows or Linux
    Merak Mail Server SMTP (MerakSMTP)Lsmtp.exeRelated to Merak_Mail_Server Software. A high performance mail server software suite for Windows or Linux
    MERANT XDB Server for NX 3.1Lxsrvnx.exeRelated to SERENA Software, Inc. - http://www.serena.com/
    MespangerXsvchost.exeAdded by a variant of the Trojan-Downloader.Win32.Delf.asz Trojan. Note: Located in \%ROOT%\Recyclers\ This infection should not be confused with the legitimate Note: \%WINDIR%\System32\svchost.exe file.
    MessagerXsvchost.exeIdentified as a variant of the Trojan:Win32/Small.gen!AG malware. Note: Located in \%Temp%\ This infection should not be confused with the legitimate C:\Windows\System32\svchost.exe file. Note: Use SDFix under supervision.
    Messaging Application Programming Interface (Mapi)Xmapi.exeAdded by the W32/Sdbot-DFC Worm Read the link, allows remote access
    MessanderXsvchost.exeAdded by a variant of the Trojan-Downloader.Win32.Delf.asz Trojan. Note: Located in \%ROOT%\Recyclers\ ,or \%ROOT%\Recyclers\. This infection should not be confused with the legitimate Note: \%WINDIR%\System32\svchost.exe file.
    MessangerXsvchost.exeAdded by a variant of the Trojan-Downloader.Win32.Delf.asz Trojan. Note: Located in \%ROOT%\Recyclers\ This infection should not be confused with the legitimate Note: \%WINDIR%\System32\svchost.exe file.
    MessengerXsvchost.exe -k MessengerAdded by the Fuwudoor TROJAN!
    MessengerXkernel32.exeAdded by the Troj/Kyth-A TROJAN! Note: Replaces any existing services named Messenger.
    MessengerXsys.exeAdded by the Troj/PcClient-H TROJAN! Note: This worm\trojan file is found in the System32 folder.
    MessengerXKB08953265.exeAdded by the Esteems.F TROJAN! Note: Drops multiple files.
    Messenger (Messenger)X(TROJAN FILE NAME)Added by the Trojan.Neasemal TROJAN! Note: This trojan file will be found in the System32 folder and may have one of the following file extensions: .kop or .del or .axs
    Messenger (Messenger)Xhacker.exeAdded by the Troj/PcClient-M TROJAN! Note: This trojan file is found in the System32 and Temp folders.
    Messenger Accelerator (Accelerator Tools)Xmdn.exe Troj/Bifrose-UV Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Messenger Sharing Folders USN Journal Reader service
    (usnjsvc)
    Lusnsvc.exeRelated to Messenger_Sharing_Folders_USN_Journal Reader service from Microsoft. Note: Located in C:\Program Files\MSN Messenger\
    Messenger Sharing USN Journal ServiceXusnsv.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    MessssangerXsvchost.exeAdded by a variant of the Trojan-Downloader.Win32.Delf.asz Trojan. Note: Located in \%ROOT%\Recyclers\ This infection should not be confused with the legitimate Note: \%WINDIR%\System32\svchost.exe file.
    MetaFrame COM Server (MFCom)Lmfcom.exeRelated to Citrix MetaFrame
    MFA Security Services (MFASec)Lmfasvc.exeRelated to Sentry_At_Home Parental Controls software. Note: Located in \%WINDIR%\System32\
    MGABGEXELmgabg.exeMatrox BIOS Guard. What does it do and is it required?
    MGACtrlLmgasc.exeRelated to products from Matrox graphics
    MgiSvrLuMgiSvr.exeRelated to Magic-i from ArcSoft A powerful webcam application designed to enhance users' video chat experience. Note: Located in C:\Program Files\ArcSoft\Magic-i 3\
    Micr0s0ft AgentXsxch0st.exeAdded by a variant of the Worm.RBot.UTA family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\dllcache\
    MICR0SOFT SVCH0ST (MS_SVCH0ST)XSVCH0ST.EXEDetected by BitDefender as Trojan.Spy.Agent.PV
    Microsoft AgentXrschost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System\dllcache (Win9x/Me), C:\%WINDIR%\System32\dllcache (XP/WinNT/2K)
    Microsoft AgentXsnchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) More: here
    Microsoft AgentXffchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: Located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft AgentXlpohost.exeAdded by the W32/Sdbot-CWQ WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft AgentXqxchost.exeAdded by the W32/Sdbot-CWP WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft AgentXlkmhost.exe W32/Vanebot-AD Note: Located in %windir%\system32\dllcache Read the link, allows remote access
    Microsoft AgentXxnchost.exeAdded by an unidentified TROJAN! of the Sdbot family.
    Microsoft AgentXppchost.exeAdded by a variant of the W32/Sdbot-CYE WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft AgentXsuchost.exe W32/Sdbot-DDD Read the link, allows remote access
    Microsoft AgentXcvchost.exe W32/Sdbot-DFH Read the link, allows remote access
    Microsoft AgentXshvhost.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\dllcache\ Note: Use SDFix under supervision.
    Microsoft AntiSpyware (Beta 1)LgcasDtServ.exeMicrosoft AntiSpyware Data Service
    Microsoft AntiSpyware (Beta 1)LgcasServ.exe Microsoft AntiSpyware Service
    Microsoft AntiSpyware (Beta 1)LGIANTAntiSpywareMain.exe Microsoft AntiSpyware Main
    Microsoft Apache for Windows (Windows Apache Service)Xwpablin.exeAdded by the W32/Tilebot-IL WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder
    Microsoft ASPI Manager (aspi113210)Xaspi113210.exeAdded by the Troj/Danmec-T TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Modify the hosts file, Terminate AV related processes and services, Steal information. Read the article. Filename is partly random (aspinnnnnn.exe) n representing a number.
    Microsoft ASPI Manager (aspimgr)Xaspimgr.exeDetected as Backdoor.Win32.Agent.aju by Kaspersky
    Microsoft authenticate service (MsaSvc)Xmsasvc.exeAdded by Worm_Ircbot_Gen Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Bluetooth Support (BthSupp)Xbthsupp.exeAdded by the W32/Btbot-A WORM!
    Microsoft cache control (MSControlService)XwindowsDetected by NOD32 as Win32/Adware.SecToolbar application Note: Located in %windir%\System32
    Microsoft Client Agent Service (Microsoft Client Agent)Xmsclient.exeAdded by the W32/Tilebot-BP WORM! Note: This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Microsoft Config (mscfg)Xdczznet.exeAdded by the W32/Rbot-ARK WORM! Note: This is not the legitimate Windows process Msconfig.exe (Which is found in the System or System32 folder.) This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Microsoft CorporationXsystemi32.exeVariant of the W32.SPYBOT WORM
    Microsoft CorporationXutorrent.exeAdded by a variant of the Backdoor.Win32.Bifrose.la TROJAN! Note: This trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    Microsoft Corporation (Windows Wordpad)Xwordpad.exeAdded by the W32/Tilebot-GL WORM! Note: This worm\trojan is located in C:\%WINDIR%\ This is not Microsoft's wordpad.exe. To make sure check the properties of the file.
    Microsoft Coyshader RuntimeXserv32.exeAdded by the W32/Rbot-GHJ WORM! Note: This worm\trojan is located in C:\%WINDIR%\ Install a rookit. rdriv.sys run a rootkit removal tool
    Microsoft Coyshader RuntimeXservice.exeAdded by the W32/Rbot-GHJ WORM! Note: This worm\trojan is located in C:\%WINDIR%\ Install a rookit. rdriv.sys run a rootkit removal tool
    Microsoft CTF LoaderLctfmon.exeCTF Loader
    Microsoft DHCPA ServiceXmshcp.exeAdded by the W32/Rbot-FNA WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft Digital Identity Service (InfoCard Service)Linfocard.exeRelated to Microsoft_NET_Framework .NET Framework is a development and execution environment that allows different programming languages & libraries to work together seamlessly to create Windows-based applications.
    Microsoft Dir32XDirhost.com W32/IRCBot-YC Note:Located in C:\Windows\System\dllcache (Win9x/Me), C:\%WINDIR%\System32\dllcache (XP/WinNT/2K) Steals information, allows remote access, read the link
    Microsoft Display ServiceXmsds.exe Troj/Spybot-NZ Note: Note:Located in C:\Windows\System\dllcache (Win9x/Me), C:\%WINDIR%\System32\dllcache (XP/WinNT/2K) Allows others to access the computer
    Microsoft Distributed Transaction (MSDT)Xmsdt.exeAdded by the W32/Tilebot-BQ WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Microsoft DLL SystemXsmsc.exeAdded by the W32/Tilebot-FY WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Genuine AdvantageXwinmga.exe Reported as Backdoor.Win32.VanBot.dk Note: Located in \%WINDIR%\system32\dllcache (XP/WinNT/2K)
    Microsoft Genuine Update AdvantageXmswan.exeIdentified as a variant of the Backdoor.Win32.VanBot.dk worm. Note: Located in \%WINDIR%\System32\dllcache\
    Microsoft HDA Protocol (svhda)Xsvhda.exeaDEED BY THE Backdoor.Win32.IRCBot.rr as detected by Kaspersky TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Microsoft IEXIEXPLORE.EXEAdded by the W32/Forbot-AG WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Note: This is not the legitimate Windows Process. (Which is found in the C:\Program Files\Internet Explorer\ folder.) This worm\trojan file is found in the C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32
    Microsoft IIS helperXmsiishlp.exeAdded by the Backdoor.Isen.Rootkit TROJAN! Read the link, rootkit type stealth involved.
    Microsoft Inet ServiceX_svchost.exeAdded by the Troj/Dwnldr-GYS Trojan! Note: Located in \%WINDIR%\System32\ This infection should not be confused with the legitimate \%WINDIR%\System32\svchost.exe file.
    Microsoft information dll service (msidll)Xmsidll.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    Microsoft Internet ExplorerXiexplore.exe W32/Tilebot-JS Read the link, allows remote access
    Microsoft Internet Information Services kernel mode
    driver
    Xmsiisdrv.exeAdded by the Backdoor.Isen.Rootkit TROJAN! Read the link, rootkit type stealth involved.
    Microsoft Java Service (Windows Java Service)Xjusched.exeAdded by an unidentified TROJAN! Note: This trojan is located in C:\%WINDIR%\
    Microsoft Language Service (Windows Language Service)Xalg.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder
    Microsoft Loading ServiceXfiles.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    Microsoft Loading ServiceXloader.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft Loading ServiceXmsdates.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft Logitech WLANXmslw.exeAdded by a variant of the Win32/IRCBot.UG Note: Located in \%WINDIR%\System32\dllcache Note: Use SDFix under supervision.
    Microsoft Logon ServiceXmslogon.exeAdded by the W32.Woredbot.C TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft Logon User Interface Skining (LogonUInterf)Xlogonui.exeDetected by Ewido as Backdoor.SdBot.aad. This worm file is found in the Windows or Winnt folder.
    Microsoft Main Window ServiceXmainwin32.exeAdded by the W32/Spybot-MR WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) disabling autostart for the SharedAccess service deactivates the Microsoft Internet Connection
    Microsoft MediaXrtsecas.exe W32/Rbot-KPH Read the link, allows remote access
    Microsoft MediaXRtsecar.exe W32/Vanebot-AX Read the link, allows remote access
    MicroSoft Media ToolsXMSMEDIA.EXEAdded by the SDBOT.CUH WORM! Note: This worm file is found in the System32 folder. (NT/2000/XP) Read the link, rootkit type stealth involved.
    MicroSoft Media Tools (MicroSoft Media Tools)XMSmedia.exeAdded by the W32/Tilebot-BC WORM! Note: This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Microsoft MSI ServiceXmsi.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft Name ServerXnssrv.exe W32/Tilebot-EK Read the link, allows remote access
    Microsoft Net API (NETAPI)Xmsapi.exeAdded by the W32/Tilebot-HJ WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft NetWork FireWall ServicesXNet_Services.exehttp://www.sophos.com/virusinfo/analyses/w32lovgateaa.html
    Microsoft NetWork FireWall ServicesXNetServices.exehttp://www.sophos.com/virusinfo/analyses/w32lovgateaa.html
    Microsoft Network RPCXmsnetrpc.exeRelated to the Troj/Isen-B
    Microsoft Networks DN (msndn)Xmsndn.exeAdded by the Backdoor.SdBot.AQZ, A.K.A. Ircbot_Gen WORM! Allows a remote intruder to gain access and control over the computer.
    Microsoft New Game 2 (svehost32)Xsvehost32.exeAdded by the W32/Tilebot-I TROJAN! Read the link, rootkit type stealth involved.
    Microsoft NewssXnewhost.exeAdded by an unknown_Trojan Note: Located in \%WINDIR%\System32\dllcache\ Note: Use SDFix under supervision.
    Microsoft Null Development Monitor (msdevnull)Xmsdevnull.exeAdded by the W32/Rbot-AGE Worm! Read the link, rootkit type stealth involved.
    Microsoft Passport Network CyberShotsXcybershots.exeAdded by the W32/Spybot-ND WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) disabling autostart for the SharedAccess service deactivates the Microsoft Internet Connection Firewall (ICF).
    Microsoft Path Finder Service (MSpath)Xmspath.exeAdded by the W32/Sdbot-AEO WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Microsoft Path Finder Service (mspathfinder)XmspathfinderAdded by the W32/Tilebot-AH WORM! Rootkit Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Performance WMI Adapter AddOn (WMIPervAddOn)Xwmiapsv.exeAdded by the Backdoor.Win32.SdBot.aad TROJAN! Reported by Kaspersky More Note: This worm\trojan is located in C:\%WINDIR%\
    Microsoft Print Spooler (WINDRIVER)Xscvhost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft proxysys (proxysys)Xproxysys.exe W32/Tilebot-JC Read the link, allows remote access
    Microsoft PS ServiceX_svchost.exeIdentified as a variant of the TrojanDownloader:Win32/Tipikit.A malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft register shieldXMrshield.exeAdded by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\
    Microsoft Registry Viewer (Dumpreg)XDUMPREG.EXEAdded by the SDBOT.BXI WORM! Read the link, rootkit type stealth involved.
    Microsoft RPC API Helper (Random Letters)X(Random FileName).sys Troj/Conhook-AG Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K) Installs multiple services. Read Link
    Microsoft Sata emulation (mside)Xmside.exeAdded by the Worm.Opanki.BK WORM! Note: This worm\trojan is located in C:\%WINDIR%\SYSTEM\ Read the technical details
    Microsoft SCC Host Protocol (POOLSVR)Xpoolsv.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    Microsoft SCC Host Protocol (TaskMGM)Xtaskmg.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    Microsoft sdk core (sdk)Xlsass.exeAdded by the Troj/IRCBot-PF TROJAN! Note: Located in C:\%WINDIR%\
    Microsoft Security Center Extension (msscenter)Xmsscntr32.exeIdentified as Danmec/Asprox password-stealing trojan. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft Security Login ServiceXmssecure32.exeAdded by the W32/Vanebot-R WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) Attempts to terminate a number of processes related to security and anti-virus applications.
    Microsoft security update service (msupdate)Xmsvcrtd.exeRelated to a variant of the Trojan.Win32.Agent.NCR family. TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    Microsoft security update service (msupdate)Xmssrv32.exe Troj/Agent-GCE Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K)
    Microsoft Service Manager (winmdgr)Xwinsvcmgr.exeAdded by the W32/Rbot-AAD WORM! Read the link, rootkit type stealth involved.
    Microsoft SQL Server Debug (sql)Xsqldebug.exeAdded by the W32/Tilebot-FF WORM! Note: Located in C:\%WINDIR%\
    Microsoft SSL (ssl)Xssl.exeAdded by the W32.Esbot.C WORM! Note: This Worm\Trojan file is found in the System32 folder and has nothing to do with the (Secure Socket Layer)
    Microsoft Star Window ServiceXstarwin32.exeAdded by the W32/Rbot-FNT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ dllcache\ (XP/WinNT/2K)
    Microsoft Star Window ServiceXsvcshoter.exeAdded by the WORM_SDBOT.ANK WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache (Win9x/Me), C:\%WINDIR%\System32]dllcache (XP/WinNT/2K) provides the remote user virtual control over the affected system, thus compromising system security.
    Microsoft Star Window ServiceXstarwksvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\dllcache\ (Win9x/Me), C:\%WINDIR%\dllcache\ (XP/WinNT/2K)
    Microsoft Startup Manager. (Microsoft Startup Manager)Xmsput.exeAdded by the W32/Sdbot-BAY WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Svc Services DispatcherXsvcsrv.ldrunknown malware
    Microsoft Terminal ServiceXmsterminal.exeAdded by the W32/Sdbot-CPZ WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\DllCache\ (XP/WinNT/2K)
    Microsoft TG MannagerXmtgm.exeAdded by the WORM_SDBOT.EMT WORM! Note: This worm is located in C:\%WINDIR%\ Read the link, allows remote access
    Microsoft Translation Service (MTServ)Xmtserv.exeAdded by the W32/Rbot-GAL WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Updata ver2005 (Microsoft Updata ver2005)Xtw725.exeAdded by the Troj/Feutel-P TROJAN!
    Microsoft UpdateXSCVVC.exeAdded by a variant of the W32/Malware Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Microsoft update (msnupdate)Xwindupdate.exeAdded by the SDBOT.CGV WORM! Read the link, rootkit type stealth involved.
    Microsoft update ServiceXmsiupdate32.exeAdded by the W32/Vanebot-S WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) disabling autostart for the SharedAccess service deactivates the Microsoft Internet Connection Firewall (ICF). Attempts to terminate a number of processes related to security and anti-virus applications
    Microsoft usnsvc ServiceXusnsvc.exeAdded by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\
    Microsoft Validation ServiceXmvsr32.exeDetected as Backdoor.SdBot.bem by AVG-antispyware
    Microsoft Validation ServiceXwmiprsv.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\%WINDIR%\
    Microsoft Virtual Private Network (MS Virtual Private
    Network)
    XMSVPN32.exeAdded by the W32/Rbot-AIO WORM!
    Microsoft Vista Updater SystemXnvcsc23.exeAdded by a variant of the BACKDOOR.IRC.BOT Note: This worm\trojan is located in \%WINDIR%\
    Microsoft Visual BasicXMSVCRT.exeAdded by a variant of the RBOT family of IRC Backdoor trojan. Note: Located in \%WINDIR%\System\ Note: Use SDFix under supervision.
    Microsoft Visual Studio (W32MVS)Xw32mvs.exeIdentified by VBA32 as a variant of the Backdoor.Win32.Agent.cjo malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft VPS ServiceXmsvps.exeAdded by the W32/Rbot-FNI WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) disables the automatic startup of other software
    Microsoft Webserver (Microsoft Webserver)XMicrosoft Webserver.exeAdded by the Troj/Hupigon-FU TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    Microsoft Windows (Microsoft Windows)Xsystem.exeAdded by the W32/Rbot-AMQ WORM! Note: This worm file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Microsoft Windows Avantage Service (Windows Avantage)Xavantage32.exeAdded by the W32/Tilebot-HE WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. disables the automatic startup of other software.
    Microsoft Windows BDA ServiceXsvhba.exeAdded by the W32/Vanebot-P WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) disables the automatic startup of other software
    Microsoft Windows DMR Service (Windows DMR Service)Xdmrproc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ More here
    Microsoft windows FTPdXupdtftpini.exeAdded by the W32/Rbot-FUS WORM! Note: This worm\trojan is located in C:\Windows\dllcache\ (Win9x/Me), C:\%WINDIR%\dllcache\ (XP/WinNT/2K) More] here
    Microsoft Windows HDA ServiceXsvhda.exeAdded by the W32/IRCBot-SL WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft Windows HelpFile (Windows Helpfile)Xservices.exeAdded by the W32/Tilebot-FQ WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. disabling the automatic startup of other software
    Microsoft Windows Internet Connections Manager (net32b)Xnet32b.exeAdded by the W32/Cuebot-N WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Deactivates the Microsoft Internet Connection Firewall (ICF).
    Microsoft Windows Man Service (Windows Man Service)Xwinmgr.exeAdded by the W32/Sdbot-DTL WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Microsoft Windows Protection (Windows Protection
    Service)
    Xwinlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Microsoft Windows Software Update Service (mswsus)Xmswsus.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Windows Spool Service (Windows Spool Service)Xwdfmgr.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ Not to be mistaken with wdfmgr.exe which is part of Microsoft Windows Media Player and located in, C:\WINDOWS\System32\.
    Microsoft Windows Spool Service (Windows Spool Service)Xservices.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) This worm\trojan file is found in the Windows or Winnt folder.
    Microsoft Windows Spooler Service (Windows Spooler
    Service)
    Xwinlogon.exeAdded by the W32/Tilebot-FR WORM!Note: This is not the legitimate Windows process (Which is always found in the System32 folder). This worm file is found in the Windows or Winnt folder. Allows a remote intruder to gain access and control over the computer, read the link.
    Microsoft Windows Spooler Service (Windows Spooler
    Service)
    Xservices.exeAdded by the W32/Tilebot-FW WORM! Note: This is not the legitimate Windows process (Which is always found in the System32 folder). This worm file is found in the Windows or Winnt folder. Allows a remote intruder to gain access and control over the computer, read the link.
    Microsoft Windows SQL Service Xwinesql.exe Win32/IRCBot.UG
    Microsoft Windows System32Xwinservs.exeAdded by the W32/Tilebot-GU WORM! Note: This worm\trojan is located in C:\%WINDIR% Also been identified with the filename: winsysdir.exe
    Microsoft Windows System32Xwindll32.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\
    Microsoft Windows TCP ProtocolXwintcps.exeAdded by the W32/Sdbot-DIY WORM! Note: Located in \%WINDIR%\System32\dllcache\ Note: Use SDFix under supervision.
    Microsoft Windows UpdateXwuautcl.exe Troj/Spybot-NQ Read the link, allows remote access
    Microsoft Windows Update (Microsoft Update)Xscvvhost.exeAdded by the W32/Forbot-FH WORM!
    Microsoft Windows Update (Microsoft Windows Update)Xmsconfig32.exeAdded by the W32/Tilebot-P WORM! Read the link, rootkit type stealth involved.
    Microsoft Windows Update (msupdate)Xcsrss.exeAdded by an unknown TROJAN!, Note: This has nothing to do with Microsoft Windows Update and this is not the legitimate Windows Process csrss.exe. (Which is found in the System32 folder.) This trojan file (csrss.exe) is found in the Windows or Winnt folder.
    Microsoft Windows Validation Service (Windows
    Validation Service)
    Xdevldr32.exeAdded by a variant of the WIN32.RBOT WORM! - Note - do NOT confuse with the legitimate Creative Labs devldr32.exe file. Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    MicroSoft Windowz Update (MsFtUpd)XMsFtUpdateXP.exeAdded by the W32/Tilebot-BL WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Microsoft WMI Performance Adapter AddOn (WMIPerAddOn)