CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 4053 entries and growing...
Last updated on 2008-08-02 17:32:28 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    W2K PCtel speaker phoneLpctspk.exeRelated to PCtel services
    W32 Sercure ServiceXwsecur3.exe W32/Sdbot-DAR Note: Located in %windir% Read the link, allows remote access and uses rootkit stealth
    W32TimeXsvchost.exe -k W32TimeAdded by the Fuwudoor TROJAN!
    wacomkeyLwacomkey.exeDriver for Wacom Tablet. Note: Located in system32 folder on XP machines http://www.wacom.com
    WakeMeUp! Service (svcWMU)LWMUSvc.exeRelated to WakeMeUp! advanced alarm clock for computers. Note: Located in C:\Program Files\WakeMeUp\
    wampapacheLhttpd.exeRelated to Apache Software. An Open source database. Note: Located in \%ROOT%\wamp\apache2\bin\
    wampapacheLApache.exeRelated to Related to Oracle_Corp Note: Located in \%ROOT%\xampp\apache\
    wampmysqldLmysqld-nt.exeRelated to Apache Software. An Open source database. Note: Located in \%ROOT%\wamp\mysql\bin\
    WAN Miniport (ATW) Service (WANMiniportService)Lwanmpsvc.exeRelated to America_Online Inc. The AOL suite's connectity relies upon this file heavily, so if AOL is used, this should not be touched.
    Warehouse agent daemon (vwd)LVWD.EXEWarehouse Manager components used with DB2 Databases from IBM
    Warehouse logger (vwlogger)LIWH2LOG.EXEWarehouse Manager components used with DB2 Databases from IBM
    Warehouse server (vwkernel)LIWH2SERV.EXEWarehouse Manager components used with DB2 Databases from IBM
    Washer Security Access (wwSecSvc)LwwSecure.exeRelated to one of the Webroot_Internet_Security programs. The file associated with this service is located in the System32 folder.
    wdcsXwdcs.exeAdded by a variant of the W32/SDBot.AWGW family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\System32\
    WDelMgr20OWDelMgr20.exeSeems to be related to the RecoverLost Data or BackUp MyPC program by StompSoft
    WDNDrive (chgsprt)Xchgsprt.sysAdded by the Troj/Haxspy-A TROJAN!
    Web Live Information MessengerXwebmsn.exeAdded by the W32/Sdbot-CWA WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Web Update Service by PowerProgrammer (WebUpdate)LWebUpdateSvc.exeRelated to POWERPROGRAMMER.CO.UK A user friendly way to look for and download updates via the web to a customer application
    Web Update Wizard Service V4 (WebUpdate4)LWebUpdateSvc4.exeRelated to Web_Update_Wizard from PowerProgrammer Co. The Wizard lets you add 'update over the web' functionality to your applications with literally a single line of code. Note: Located in \%WINDIR%\System32\
    WebDrive Service (WebDriveService)Lwdservice.exeRelated to WebDrive FTP service. Note: Located in C:\Program Files\NetDrive\
    WebPrintXwebprint.exe Troj/Bckdr-QHH
    Webroot Admin Console (WebrootAdminConsole)LWebrootAdminConsole.exeRelated to Webroot_Software
    Webroot Client Service (WebrootEnterpriseClientService)LWebrootClientService.exeRelated to Webroot_Software
    Webroot CommAgent Service (WebrootCommAgentService)LCommAgent.exeRelated to Webroot Software, Inc.http://www.webroot.com/
    Webroot Desktop Firewall network service (WDFNet) Lwdfsvc.exeWebroot Desktop Firewall 5.5 Service
    Webroot Spy Sweeper Engine (svcWRSSSDK)LWRSSSDK.exeRelated to Webroot Spy Sweeper Engine. Located in C:\Program Files\Webroot\Spy Sweeper\
    Webroot Spy Sweeper Engine (WebrootSpySweeperService)LSpySweeper.exeRelated to Webroot Software inc. Spyware protection software. Note: Located in C:\Program Files\Webroot\Spy Sweeper\
    Webroot SpySweeper Service (WebrootSpySweeperService)LSpySweeper.exeRelated to Webroot Software inc. Spyware protection software. Note: Located in C:\Program Files\Webroot\Spy Sweeper\
    Webroot Update Service (WebrootEnterpriseUpdateService)LWebrootUpdateService.exeRelated to Webroot_Software
    WebSeach Toolbar support NT serviceXTBPSSvc.exeRelated to the Neo/Huntbar Toolbar
    Websense CPM Deployment Service
    (WebsenseClientDeployService)
    LWsClientDeployService.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense CPM Report Scheduler (WebsenseCAMReportServer)LBatchQueue.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense CPM Server (WebsenseCAMServer)LCAMServer.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense DBManager Scheduler (DBManagerScheduler)LDBManagerScheduler.exeRelated to Websense_Reporter has three primary components: the Reporter user interface, the Log Server and the Log Database. Note: located in C:\Program Files\Websense Reporter\...
    Websense DC Agent (WebsenseDCAgent)LXidDcAgent.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense Explorer Report Scheduler
    (WebsenseWFReportServer)
    LExplorerScheduler.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense Filtering Service (Websense EIM Server)LEIMServer.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense Information Service for CPM Explorer
    (WebsenseCPMCommunicationAgent)
    LCAMExplorerServer.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense Information Service for Explorer
    (WebsenseCommunicationAgent)
    LExplorerServer.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense Log Server (WebsenseLogServer)LLogServer.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense Network AgentLNetworkAgent.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense Policy Server (WebsensePolicyServer)LPolicyServer.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense Real-Time Analyzer (WebsenseRealTimeAnalyzer)LRTMServer.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense Report Scheduler (Websense Reporter Scheduler)LWsScheduler.exeRelated to Websense_Reporter has three primary components: the Reporter user interface, the Log Server and the Log Database. Note: located in C:\Program Files\Websense Reporter\...
    Websense Reporter SchedulerLWsScheduler.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\Reporter\
    Websense Usage Monitor (WebsenseUsageMonitor)LUsageMonitor.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    Websense User Service (WebsenseUserService)LUserService.exeRelated to Websence increase web security and employee productivity through internet policy enforcement. Note: Located in C:\Program Files\Websense\bin\
    WebTimeXWebTime.exe Troj/SleepSrv-A
    wfsup(wfsup) (wfsup)Xwfsup.exeAdded by the Bck/Sdbot.HPS as detected by Pandascan TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    WhatsUp Gold SyslogLWUGSyslog.exeRelated to CiscoWorks SNMS server.
    Win Common moduleXservicemp.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Win PPPeXwinser.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Win Tmp Service (Wstmp)Xwstmp.exeAdded by the W32/Sdbot-YS Worm!
    Win UpdateXSYSUPDATE.EXEAdded by the SDBOT.CLA WORM! Note: This worm file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Win Updator ServicesXctfnom.exeRelated to the WootBot Trojan.
    WIN32 (image)Ximage.exeAdded by the W32/Sdbot-AAQ WORM! Read the link, rootkit type stealth involved.
    Win32 Driver (shit)Xsvchosts.exeAdded by the W32/Forbot-FD WORM!
    Win32 FireWire Driver
    (ds80-237-205-33.dedicated.hosteurope.de)
    XCTHELPER32.EXERelated to WootBot TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Win32 Kernel Update (Win32Kernel)Xwin32host.exeAdded by the W32/Tilebot-FE WORM! Note: This worm file is found in the Windows or Winnt folder. Allows a remote intruder to gain access and control over the computer, read the link.
    Win32 Login Service (Win32 Login)Xwin32logon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    Win32 LSA Driver (Windows Lsa Service)Xlsa.exeAdded by the W32/Forbot-FJ WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    win32 socket (win32socket)Xwin325b.exeAdded by the W32/Tilebot-GE WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Win32 SSL Driver (Win32 SSL Driver)Xwinssv.exeAdded by the W32/Forbot-BH WORM!
    Win32 System SpoolXspoolsvc.exeAdded by the W32/Sdbot-RY Spyware Worm! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Win32 Task Manager (Win32Task)Xwintasks32.exeAdded by the W32/Rbot-FPD WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Win32 Update (shit)Xsvchosts.exeAdded by an unidentified TROJAN! of the Sdbot family. C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Win32 Update (Win32Update)Xoswinupdate.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    win32 update service (defiled)Xsvchostt.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Win32 USB2 DriverXsvchosting.exeW32/Forbot.J or SDBOT.HU
    Win32ExportXwinsysplg.exeAdded by the W32/Rbot-FMU WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Win32SlLWin32sl.exeAllows remote management application programs to access a client computer for maintainance purpose. (UNIBLUE)
    WIN32SOUNDXsounddv.exeAdded by the W32/Tilebot-Z WORM! Read the link, rootkit type stealth involved.
    Win32SrXwin32ssr.exeAdded by the W32/Sdbot-AMA WORM!
    Win32Sr (Win32Sr)Xwin32ssr.exeAdded by the W32/Sdbot-AOT WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    WinACD Power Button Service (ACDPowerService)Lacdpower.exeRelated to Compuflex's "TSR-like" product for the Windows environment that automatically reads the amount to dispense from the native Windows teller software
    WinAgents TFTP Service 4 (WinAgentsTftpService4)LTftpService.exeRelated to WinAgents_TFTP services. Note: Located in \%Program Files%\Common Files\WinAgents\
    winauthm (spdauth)XSPDAUTH.EXEAdded by the SDBOT.CFH WORM! Read the link, rootkit type stealth involved.
    WinComSpk Service (SvcWinComSpk)Lwincomspk.exeRelated to Sentry_At_Home Parental Controls software. Note: Located in \%WINDIR%\System32\
    winconfig.exeXsmsss.exeAdded by the W32/Spybot-MP WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    winconfig.exeXSP2PATCH.EXEAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    winconfig.exeXsvcss.exeAdded by the Troj/Agent-MD TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    winconfig.exeXApiWin.exe W32/Sdbot-DEZ
    winconfig.exe (openssh.exe)Xopenssh.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    windbg48Xwindbg48.sys Troj/RKAgen-A Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    windbsXwinxtc.exeAdded by the AGOBOT-WD WORM
    Window (MPRS)Xexplore.exeAdded by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    Window Boot ServicesXlsiss.exeAdded by the W32/Tilebot-HP WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) disabling the automatic startup of other software.
    Window Dispaly SystemXlsays.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    Window Domain Services (windowndns)Xsvchost.exeUnknown malware. This infection should not be confused with the legitimate C:\Windows\System32\svchost.exe file. This malware is Note: located in \%Program Files%\Internet Explorer\
    Window Image Worker (windownetpker)Xsvchost.exeIdentified by Kaspersky Antivirus as a variant of the Trojan.Win32.Delf.amr malware. Note: Located in \%Program Files%\Internet Explorer\ This infection should not be confused with the legitimate \%WINDIR%\System32\svchost.exe file.
    Window LFX ServicesXlxsys.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Window Lssas ServicesXlssys.exeAdded by the Trojan.Downloader-Gen/Win.Process TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Window Net Dns (MyDNS)Xsvchost.exeDetected as Trojan.Win32.Delf.bhp by Kaspersky Note: Located in %programfiles%\Outlook Express or %programfiles%\Internet Explorer - not to be confused with the legitimate svchost.exe located in %windir%\system32
    Window Plugin ServiceXlsscs.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    Window Washer Engine (wwEngineSvc)LWasherSvc.exeRelated to Window_Washer_Engine Wash away all traces of your PC and Internet activity. Note: Located in \%Program Files%\Webroot\Washer\
    windowsXssme.txt Troj/Hupigon-SQ Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K)
    Windows .NET ServiceXnetserv.exe W32/Tilebot-KB Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR% (XP/WinNT/2K) Allows others to access the computer Read links
    Windows 32 Bit (Windows 32 Bit Drivers)XWinVid32.exeAdded by the W32/Tilebot-BH WORM! Note: This worm file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Windows 32-bit PnP Driver (winpnp32)Xwinpnp32.exeAdded by the W32.Wallz WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Accounts Driver (WindowsAccounts)XSVCH0ST.EXE Troj/Agent-NDR
    Windows Active Directory Helper (MSSearchHelper)X(random name).exe Troj/Agent-ELG
    Windows Anti Virus (MSAV32)XMSAV32.EXEAdded by the SDBOT.CMH WORM! Read the link, rootkit type stealth involved.
    Windows Archiver (winarc)Xdevldr.exeAdded by the W32/Prex-J WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Windows Archiver (winarc)Xwindat.exeAdded by the W32/Tilebot-BA WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Windows ASP ServiceXaspsrv.exe W32/SdBot-DGU Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR% (XP/WinNT/2K) Allows others to access the computer
    Windows Auto Update ToolXwault.exeAdded by the W32/Tilebot-JQ WORM! Note: This worm is located in C:\%WINDIR%\ Read the link, allows remote access
    Windows Automatic UpdatesLwindowsautomaticupdates.exeThis Service belongs to the Folding@Home Client which uses your computer's resources on behalf of Stanford University. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems.
    Windows Basis Cont (Windows Basis Cont)XWINFTP32.EXEAdded by the SDBOT.CIU WORM! Read the link, rootkit type stealth involved.
    Windows Bluetooth Tray ApplicationXBTTray.exe W32/Sdbot-DGN Note located in \KaZaA\My Shared Folder\.
    Windows Bluetooth Tray ApplicationXBTTray.exe W32/Tilebot-KD Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR% (XP/WinNT/2K)
    Windows CDROM Drivers (Microsoft Windows Atapi Drivers)Xatapid.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\
    Windows Client/Server Runtime Server Subsystem (WCSRSS)Xwcsrss.exeAdded by the W32/Tilebot-DA WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Client/Server Runtime Service (csrss)Xcsrss.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\i386\ (Win9x/Me), C:\%WINDIR%\i386\ (XP/WinNT/2K) Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    Windows Confg SystemXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    windows config service (config)Xconfig.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Configuration Backup Service (CfgBackupSvc)Xsvchost.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\CONFIG\ This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    Windows Configuration Loader (Windows Configuration
    Loader)
    XSVCHOST.EXEAdded by the RBOT.BZF WORM! Note: This is not the legitimate Windows process SVCHOST.EXE (Which is always found in the System32 folder.) This worm file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Windows Configuration Manager (ConfigMgr)Xsvchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Connection Extension (WCEisvc)Xwcmsvc.exeAdded by a variant of the SDBot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\Help\
    Windows Control Panel DebuggerXexplorer.exeDetected as W32/Hupigon.gen76 by F-Secure Note: Located in %windir%\debug
    Windows Control Service32 (SVHOST32)Xsvhost32.exeAdded by a variant of the SDBot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\System32\
    Windows Cron ServiceXcrons.exe Troj/Hupigon-SR Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K) Allows remote access. Read the link
    Windows CTF LoaderXctfmon.exe W32/Sdbot-DFS Copies itself to %Windows% directory
    Windows DDE (servet wm)Xservet.exe W32/WoWMovs-A Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows DebuggerXSYSNT.EXEAdded by the RBOT.CEL WORM! Read the link, rootkit type stealth involved.
    Windows Decrypt manager (wincrypt32.exe)Xwincrypt32.exeAdded by the W32/Tilebot-GC WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Windows Defender User InterfaceXMSASCu.exeAdded by the W32/Sdbot-DFW WORM! Note: This worm is located in \%WINDIR%\ Read the link, allows remote access
    Windows Defender User Interface (Windows Defender)XMSASCu.exe W32/Sdbot-DFW Copies itself to %Windows% directory Allows remote access. Read link
    Windows Desktop SecurityOsvcagnt.exeCheck to see if it was installed by the by user. Keylogging and screenshot software see Here Location: C:\Programmer\RDS4\svcagnt.exe
    Windows Desktop Security (dtsagntsvc)Osvcagnt.exeCheck to see if it was installed by the by user. Keylogging and screenshot software see Here Location: C:\Program Files\RDS\svcagnt.exe
    Windows DHCP Client ServiceXdhcp.exe W32/Tilebot-JU Note: Located in %Windows%\dhcp.exe
    Windows DHCP ServiceXsystem.exeAdded by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Windows DHCP Service (WinDHCPsvc)Xrundll32.exe Win32/Agent.ABF Note: rundll32.exe is legitimate but is being used to load the malware file %system%\windhcp.ocx Read the link, collects sensitive information
    Windows DLL Loader (RunDll32)Xrundll32.exeAdded by the Troj/Agent-MD TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) This worm\trojan file is found in the C:\%WINDIR%\dll\ folder.
    Windows DLL SystemXsmsc.exeAdded by the W32/Tilebot-GG WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Disables the automatic startup of other software.
    Windows DLLISPXdllisp.exe W32/Tilebot-JN Read the link, allows remote access
    Windows DNS (Windows DNS)Xrundl32.exeAdded by the Troj/GrayBrd-AG TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    Windows Dos ServiceXdsserv.exe W32/Sdbot-DGT Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR% (XP/WinNT/2K) Allows others to access the computer
    Windows Drivers ConfigsXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Windows Drivers VersionXWinDV.exeAdded by a variant of the SDBot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\
    windows drivers32XWINDRVR32.EXEAdded by the SDBOT.CON WORM! Read the link, rootkit type stealth involved.
    windows drivers32 (windows drivers32)Xwindrvrs32.exeAdded by the W32/Tilebot-AG WORM! Note: This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Windows Event Viewer (EventViewer)Xspoolsmc.exeAn unidentified SDbot variant
    Windows explorerXexplore.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    windows explorer32Xexplorer32.exeAdded by the W32/Sdbot-CVQ WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows File Depictor and Rotator Service For Service
    Pack 2 (Windows File Depictor and Rotator)
    Xsvchost.exe Detected as Backdoor.Win32.SdBot.aad by Kaspersky Note: Located in %windir%\repair
    windows file explorer (explorer)Xssms.exeAdded by the W32/Tilebot-EN WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Windows File Verification Service (wfvs)Xwfvs.exeIdentified as a variant of the Backdoor.Ranky malware. Note: located in \%WINDIR%\System32\
    windows firewall (masry)Xmsgupdater.exeAdded by the W32/Sdbot-ADZ WORM! Note: This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Windows Firewall ServicesXiexplore.exeAdded by a variant of the Sdbot-ABA worm! NOTE: this file is located in the Windows folder, while the legitimate iexplore.exe (the Internet Explorer executable) is found in Program Files\Internet Explorer.
    Windows Genuine Advantage Registration Service (net32a)Xnet32a.exeAdded by the Backdoor.IRCBot.st Identified by ewido. WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Genuine Advantage Registration Service (wgareg)Xwgareg.exeAdded by the Win32/Cuebot.J WORM! Exploits the MS06-040 Windows vulnerability. Note: File located in the System or System32 folder.
    Windows Genuine Advantage Validation (wgav)Xwgav.exeAdded by a variant of Win32/IRCBot.OO as reported by NOD32 TROJAN! Note: located in C:\WINDOWS\system32\wgav.exe
    Windows Genuine Advantage Validation Monitor (wgavm)Xwgavm.exeAdded by the W32/Cuebot-M WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Disables the automatic startup of other software, deactivates the Microsoft Internet Connection Firewall (ICF).
    Windows Genuine Advantage Validation Notification
    (wgavn)
    Xwgavn.exeAdded by the W32/Cuebot-K WORM! Located in the Windows or Winnt\System32 folder.
    Windows HelpXwinhlep.exe Troj/Hupigon-SM Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR% (XP/WinNT/2K)
    Windows Help (shit)Xmailinfo.exeAdded by the W32/Forbot-FK WORM!
    Windows Host Services (DLLHOST32)Xdllhost.exeAdded by the W32/Tilebot-IH WORM! Note: This worm\trojan is located in C:\%WINDIR%\System\ folder.
    Windows Host Services (ExplorerSvc)Xexplorer.exeIdentified as a variant of the Net-Worm.Win32.Kolabc.aeh worm. Note: located in \%WINDIR%\system\ Note This infection should not be confused with the legitimate C:\Windows\explorer.exe file.
    Windows Host Services (WINHOST32)Xservices.exeAppears to be an SDbot variant. Note: Located in %windir%\system
    Windows Hosts PluginXspoolcv.exeAdded by A variant of the SDBot.aad family of worms and IRC backdoor Trojans.
    windows hostsrv (dllhstsrv)Xdllhstsrv.exeAdded by a variant of the BACKDOOR.IRC.BOT Note: This worm\trojan is located in \%WINDIR%\
    Windows HWinfo Loader (Windows HWinfo Loader)Xiexplre.exeAdded by the W32/Rbot-ALS WORM!
    Windows IMAP ShellXimaped.exeAdded by the Backdoor.SDBot.F7B46034 TROJAN! Reported by BitDefender
    Windows Input Service (wiisvc)Xwibsvc.exeAdded by a variant of the Backdoor.Win32.SdBot.bzc family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\System\
    Windows Ins (WindowsDown)Xservet.exe W32/SillyFD-AB Read the link, steals information
    Windows InstallerLMsiExec.exeexecutable program of the Windows Installer
    Windows Installer ManagerXwinins.exe W32/Sdbot-DHP Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K) Read the link, Turns off anti-virus applications, Allows others to access the computer
    Windows InstallService (WindowsDown)Xservet.exe W32/SillyFDC-AI Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Read the link, steals information
    Windows Instrument Driver (WMID)Xinstdrv.exe W32/SdBot-CZV Note: Located in %windir% Read the link, security settings are changed
    Windows Internet Connection Sharing Service (Windows
    Internet Connection Sharing)
    Xmsfav32.exeAdded by a variant of the SDBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\dllcache\
    Windows Internet Control (Windows Internet)Xinternet.exeAdded by the WORM_SDBOT.ABT WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Internet ServiceXiexplore.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\ (Win9x/Me), C:\%WINDIR%\ (XP/WinNT/2K) Note: This is not the legitimate Windows Process which is normally found in C:\Program Files\Internet Explorer\
    Windows Internet/Server (Internet)Xwinlogo.exeAdded by the Troj/GrayBrd-AC TROJAN! Note: This trojan file is found in the System\RavExt (95/98/ME) or System32\RavExt (NT/2000/XP) folder.
    Windows KernelXsvchost.exeAdded by the HackerDefender SDBot TROJAN! ROOTKIT INFECTION Note: This worm\trojan is located in C:\Windows\ Not to be mistaken with svchost.exe which is part of Microsoft an located in C:\WINDOWS\System32\.
    Windows Kernel (Windows Kernel)Xsvchost.exeAdded by the W32/Rbot-ANO WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Windows Kernel ServerXwkserver.exeAdded by a variant of the SDBot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\System32\
    Windows Kernel ServiceXkasvc.exeAdded by a variant of the BACKDOOR.IRC.BOT Note: This worm\trojan is located in \%WINDIR%\
    Windows Kernel ServicesXwinlogon.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ Do not remove the C:\WINDOWS\system32\winlogon.exe which is located in the \system32 folder.
    Windows Kernel System ServiceXwkssvc.exeAdded by the W32.Spybot.YXX WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Windows LAN Service Manager?svchost.exeUnknow origin
    Windows Live Setup Service (WLSetupSvc)LWLSetupSvc.exeRelated to Windows_Live_Writer a desktop application that makes it easier to compose compelling blog posts. Note: Located in C:\Program Files\Windows Live Writer\
    Windows LogXnvsvcd.exeAdded by the BackDoor-CXT TROJAN! Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows logic ServiceXlogic.exe W32/Tilebot-JV Read the link, allows remote access
    Windows Login (len)Xlmss.exeAdded by the W32/Agobot-JA WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    windows logonXwinlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    Windows Logon Process Service (MSWinLogonProcService)Xwinlogon.exeAdded by a variant of the Win32/Procin family of TROJAN! Note: Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) This trojan file is found in C:\%WINDIR%\.
    Windows lsass Service (lsass)Xlsass.exeAdded by the W32/Rbot-AGD WORM! Located in C:\WINDOWS\lsass.exe (9X\XP) or C:\Winnt\lsass.exe (NT\2000) Note: C:\WINDOWS\System32\lsass.exe is a Windows system file. Read the link, rootkit type stealth involved.
    windows mail serviceXmail.exeAdded by A variant of the SDBot.aad family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\
    Windows Mail Services (WindowsMailSrv)XWinMailSrv.exe Troj/Hupigo-VY
    Windows Maintenance XWINMAINT.EXE Mal/Heuri-D Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR% (XP/WinNT/2K)
    Windows Management (Windows Management)Xsvchost.exeAdded by the Troj/Feutel-AN WORM! Note: This is not the legitimate Windows process(Which is always found in the System32 folder). This worm/trojan file is found in the Windows or Winnt folder.
    Windows Management Construct (winmgmc)Xwinmgc.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    Windows Management Instrument Driver Includes
    (WMIDriverInc)
    Xwmiprvse.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. Note: This is not the legitimate Windows Process. (Which is found in the System32\wbem\ folder.)
    Windows Management InstrumentationLWinMgmt.exeused by system administrators to create Windows management scripts
    Windows Management PrintSystem (spoo1sv)Xspoo1sv.exeIdentified as a variant of the AdWare.Win32.Agent.aad malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows Management ServiceXdm***.exeRelated to wareout, detected by Antivir as TR/Dldr.DNSChanger.Gen
    Windows Management Services (wmserv)Xsvcmain.exe Troj/Agent-ECW Note: Located in %windir%\system32
    Windows Management Updater (WinManUpdater)Xsmss.exeAdded by the Troj/Kaos-E TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    Windows Manager ServiceXManager.exe W32/Tilebot-KE Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR% (XP/WinNT/2K)
    Windows Media Connect (WMC) (WmcCds)Lmswmccds.exePart of windows media connect, allows universal plug and play devices to be used by windows media player
    Windows Media Connect (WMC) Helper (WmcCdsLs)Lmswmcls.exePart of windows media connect, allows universal plug and play devices to be used by windows media player
    Windows Media Connect Service (WMConnectCDS)Lwmccds.exeRelated to Windows_Media_Connect Service v2. Windows Media Connect is a Microsoft technology which enables Digital Media Receivers to play music, video, or photos that are stored on a Windows XP PC. Note: located in C:\Program Files\Windows Media Connect 2\
    Windows Media Player Network Sharing Service
    (WMPNetworkSvc)
    Lwmpnetwk.exe Related to Windows_Media_Player Network Sharing Service. Note: Located in %ProgramFiles%\Windows Media Player\
    Windows Media Sharing (WMSsvc)Xwmsvc.exeAdded by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Windows MessengerXmsnmsgr.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This is not the legitimate Windows Process. (Which is found in the C:\Program Files\MSN Messenger\ folder.) This worm\trojan file is found in the Windows or Winnt folder.
    Windows MS Update 32 (Win32)Xsucker.exeAdded by the W32/Forbot-GJ WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    WINDOWS MSI Installer Application (LD-MSIEXEC_Inst)Xmsiexec.exeAdded A variant of the RBot.cgu family of worms and IRC backdoor Trojans. Note: Located in C:\Windows\AppPatch\
    Windows MSNXwmsnlivexp.exeAdded by the W32/Sdbot-CXR WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. Modifies some FTP files, read the link
    windows mssqlXmssql.exeAdded by the W32/Tilebot-HZ WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Windows NetBalance MonitorXmsnbm32.exeIdentified as Trojan.Win32.AntiAV.y TROJAN! Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows NetDDe (shit)Xwrmana32.exeAdded by the W32.Mytob.IM WORM!
    Windows Netlib Service (CSRS)Xnetlib32.exeAdded by the W32/Tilebot-IG WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    windows network (system)Xsystem.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Network ControllerXWinGmt.exeW32/Sdbot-MG trojan
    Windows Network Latency Controller (nlc)Xsp2vc.exe ( or 1.tmp, nlc.exe)Added by a Generic_Password_Stealers TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Network Log (Windows Network Log Manage) XNetlog.exe Detected as Backdoor.Win32.Hupigon.el i by Kaspersky
    Windows Network Mapping Service (NetMap)Xsvchost.exeAdded by an unidentified TROJAN! of the Sdbot family. This worm\trojan is located in C:\%WINDIR%\system\ folder. Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    Windows Network Security Management Service (nsms)Xnsms.exeAdded by the Troj/Ranck-ET TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Network Security Service (lsass)Xlsass.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    Windows Network Security Service (wnss)Xwnss.exeIdentified as a variant of the Backdoor.Win32.Agent.dvq backdoor Trojan. Note: Located in \%WINDIR%\System32\
    Windows Network SerializeXmswns32.exeIdentified as the Win32:Small-BKI/Worm/Agent.40960 malware. Note: located in \%WINDIR%\System32\
    Windows Network Services (SvcHost32)Xsvchost32.exeAdded by a variant of the Backdoor.Win32.SdBot.bhk family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\System32\
    Windows Networking Agent (Windows Networking Agent)Xmsuls.exeAdded by the Troj/Kwoo-A TROJAN! Note: This worm\trojan file is found in the System32 folder.
    Windows NetworksXinetsock.exeAdded by an unidentified malware Note: Located in \%Program Files%\NetMeeting\
    Windows NTXwinlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    Windows NT applicationXwinlogon.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    Windows NT Logon Application (WINLOGON)Xwinlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    Windows NT Session ManagerLsmss.exeMicrosoft Windows NT Session Manager
    Windows NT Session Manager (SMSS)Xsmss.exeAdded by the Backdoor.IRCBot.rh as identified by ewido. Note: This worm\trojan is located in C:\%WINDIR%\ Not to be confused by the legitimate smss.exe found in C:\%WINDIR%\System32\
    Windows NT Session Manager (WINNTSMSS)Xsmss.exe TR/Crypt.ULPM.Gen Note: Located in %Windir%\System
    Windows NT Session ManagersXsmss.exeAdded by the W32/Sdbot-CPN WORM! Note: This worm\trojan is located in C:\%WINDIR%\ Note: not to be confused by the legit file smss.exe in the C:\%WINDIR%\System32 folder.
    Windows NZDB ServiceXnzbd.exe W32/Sdbot-DGJ Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR% (XP/WinNT/2K)
    Windows Object ManagerXsmss.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing service. Located in C:\WINDOWS\smss.exe (9X\XP) or C:\Winnt\smss.exe (NT\2000) Note C:\WINDOWS\System32\smss.exe is a Windows system file.
    Windows Object ManagerXlsass.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing service. Located in C:\WINDOWS\lsass.exe (9X\XP) or C:\Winnt\lsass.exe (NT\2000) Note C:\WINDOWS\System32\lsass.exe is a Windows system file.
    Windows Object ManagerXcsrss.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing service. Located in C:\WINDOWS\csrss.exe (9X\XP) or C:\Winnt\csrss.exe (NT\2000) Note C:\WINDOWS\System32\csrss.exe is a Windows system file.
    Windows Object ManagerXservices.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing service. Located in C:\WINDOWS\services.exe (9X\XP) or C:\Winnt\services.exe (NT\2000) Note C:\WINDOWS\System32\services.exe is a Windows system file.
    Windows Object ManagerXwinlogon.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing service. Located in C:\WINDOWS\winlogon.exe (9X\XP) or C:\Winnt\winlogon.exe (NT\2000) Note C:\WINDOWS\System32\winlogon.exe is a Windows system file.
    Windows OneCare Live (winss)Lwinss.exePart of Windows OneCare Live
    Windows Overlay ComponentsX(Random).exeReported as the Trojan-Dropper.Win32.Agent.tb TROJAN! by Kaspersky Anti-Virus. Note: This trojan file is located in the Windows or Winnt folder. For more information on Trojan Droppers Click_Here
    Windows Packet Driver (packet)Xpacket.exeAdded by the Troj/Hwbot-C TROJAN! Note: This trojan file is found in the System32 folder.
    Windows PE DebuggerXlviss.exeAdded by the W32/Sdbot-COT WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Disables the automatic startup of other software.
    Windows Plug and Play (WinPPn)Xwpnsvc.exeAdded by a variant of the W32/SDBot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\Help\
    Windows Plugin ApplicationXsvshost.exeIdentified as Backdoor.Win32.SdBot.awe Note: This worm\trojan is located in C:\WINDOWS\system32\ More here Read the link, allows remote access
    Windows Presentation Foundation Font Cache 3.0.0.0
    (FontCache3.0.0.0)
    LPresentationFontCache.exeRelated to Microsoft_Framwork Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. Note: located in \%WINDIR%\Microsoft.Net\Framework\v3.0\WPF\
    Windows Process ManagerXspoolsc.exe W32/Tilebot-JM
    Windows Process Moniter (Windows Process Moniter)Xwinmon.exeAdded by the SDBOT.BYV WORM! Also drops winmon.sys which is a root kit. Note: This worm file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Windows Process SevicesXprsc32.exe W32/Spybot-NR Read the link, allows remote access
    Windows Process Viewer (The Windows Process Viewer)Xwinlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    Windows Product Activation (wpa)Xwpa.exeAdded by the W32.Esbot.B WORM!
    Windows Produre Call (MSRPC)Xmsrpc.exeAdded by the W32/Sdbot-AEI WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Windows Protected Content Restoration Service
    (ProtectedContentSvc)
    Xservices.exeAdded by Oscarbot.IV TROJAN! (backdoor ranky) Note: This worm\trojan is located in C:\%WINDIR%\ETC\ compromise user confidentiality This is not a legitimate Windows Process found in C:\%WINDIR%\SYSTEM32.
    Windows Protocol Deployment Manager (PDM)X1.tmpAdded by a variant of the Backdoor.Ranky family. TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) The filename (Random Name).tmp
    Windows Recovery Monitor (wrepmon) Xwrepmon.exeDetected as W32/NewMalware-Rootkit-I-based!Maximus by F-Prot
    Windows Reg ServiceXlsyss.exeAdded by the W32/Tilebot-HH WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Register ControlXregister.exeAdded by the W32/Tilebot-GO WORM! Note: This worm\trojan is located in C:\%WINDIR%
    Windows Remote ManagerXlsiss.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Remote Procedure Call Monitoring Service
    (rpcsvc)
    Xrpcsvc.exeAdded by the W32/Cuebot-I WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) disabling the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF).
    Windows Restore ServiceXspoolcs.exeAdded by the Downloader-SpoolCS/Symon.Process TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows RPC Services (winrpc)Xwinrpc.exeAdded by the W32.Spybot.ACDM WORM! Note: This worm file is found in the Windows or Winnt folder.
    Windows Secure ServiceXsecsrv.exe W32/Sdbot-DGP Note: Located in C:\Windows
    Windows Secure Update (WinSecUp)XWinSecUp.exeAdded by the W32/Rbot-GCD WORM! Note: Located in \%Program Files%\Common Files\System\
    Windows Security CenterXwinmgr.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32 Note: Use SDFix under supervision.
    Windows Security Drivers (csrs)Xcsrss.exeAdded by an unknown TROJAN!, Note: This has nothing to do with Microsoft Windows Update and this is not the legitimate Windows Process csrss.exe. (Which is found in the System32 folder.) This trojan file (csrss.exe) is found in the Windows or Winnt folder
    Windows Security Drivers (csrs)Xsvchost.exeAdded by an unknown TROJAN!, Note: This has nothing to do with Microsoft Windows Update and this is not the legitimate Windows Process svchost.exe. (Which is found in the System32 folder.) This trojan file (svchost.exe) is found in the Windows or Winnt folder
    Windows Security ManagerXvcmon.exeAdded by the W32/Tilebot-IC WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Windows Security UpdateXsecupd.exehttp://www.sophos.com/virusinfo/analyses/trojsepucb.html
    Windows Server Client Verification Service (wscvs)Xwscvs.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: Located in \%WINDIR%\System32\
    Windows Server IP Verification Service (WSIVS)Xwsivs.exeAdded by the Backdoor.Ranky backdoor Trojan. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Windows Server Management ServiceXnetsvc.exeAdded by an unidentified TROJ