CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

O23 List of Windows XP/NT services

Currently 4053 entries and growing...
Last updated on 2008-08-02 17:32:28 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    fwnet64 (fwnet)Xfwnet64.exeAdded by Backdoor.SDBot.gen Note: This worm\trojan is located in C:\%WINDIR%\
    FwSRServiceLfwsrservice.exeCheckPoint SecuRemote
    GameConsoleServiceLGameConsoleService.exeRelated to Game_Console_Service on Dell Computers. Note: Located in \%Program Files%\WildTangent\Apps\Dell Game Console\
    gbXibm*****.dll Trojan-PSW:W32/Sinowal.CP Read the link, steals information Note: ***** is a 5 digit random number
    GB-PVR Recording ServiceLgbpvrrecordingservice.exePart of GB-PVR Personal video recorder software
    Gbp Service (GbpSv)LGbpSv.exeRelated to GAS G-Buster Browser Defense" - Brazilian e-commerce and e-banking transaction protection software.
    GbpSvXsvchost.exe Troj/Banker-EFM Read the link, steals information Note: Located in %windir%
    GCALDaemonLwrapper.exeRelated to GCALDaemon offers two-way synchronization between Google Calendar and various iCalendar compatible calendar applications. Note: Located in \%Program Files%\GCALDaemon\bin\
    GCX ServiceXGCXSRVC.EXEAdded by the RBOT.CUE WORM! Read the link, rootkit type stealth involved.
    GEARSecurityLGEARSEC.EXERelated to GEAR software.
    Gene6 FTP ServerLG6FTPSERVER.EXERelated to Gene6 Sarl. http://www.g6ftpserver.com/
    General Network ServiceXwinsocks32.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    General Socket ServiceXSVCHOST.EXE Mal/HckPk-A
    generic host process (svchost)Xsvchost.exeAdded by the W32/Tilebot-BB WORM! Note: This is not the legitimate Windows process svchost.exe (Which is always found in the System32 folder.) This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Generic Host Process (svchost)XSVCHOST.EXEAdded by the SDBOT.CNK WORM! Note: This is not the legitimate Windows process svchost.exe (Which is always found in the System32 folder.) This trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Generic Host Process for Win-32 ServiceXspoolsv.exeAdded by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. This infection should not be confused with the legitimate C:\Windows\System32\spoolsv.exe file. This malware is Note: located in Note: located in \%WINDIR%\
    Generic Host Process for Win-32 ServiceXsvchost.exeAdded by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. This infection should not be confused with the legitimate C:\Windows\System32\svchost.exe file. This malware is Note: located in Note: located in \%WINDIR%\
    Generic Host Process For Win32 Services (Generic Host
    Process)
    Xsvchost.exeAdded by the W32/Tilebot-DM WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    Generic Service for HID Keyboard Input Collections
    (GenericHidService)
    LHIDSERVICE.exeEnhanced Driver for Keyboards and Windows http://www.microsoft.com/whdc/device/input/w2kbd.mspx
    getPlus(R) HelperLgetPlus_HelperSvc.exeAdobe download manager
    getPlus® HelperLgetPlus_HelperSvc.exeRelated to getPlus® _Helper from NOS Microsystems Ltd. A tool that creates customized programs. Note: Located in \%Program Files%\NOS\bin\
    GFI LANguard N.S.S. 7.0 Attendant ServiceLlnssatt.exeRelated to GFI_LANguard_Network Security Scanner from GFi. Note: Located in C:\Program Files\GFI\LANguard Network Security Scanner 7.0\
    GFI LANguard System Integrity Monitor 3 agent serviceLcfservice.exeGFI LANguard System Integrity Monitor is a utility that provides intrusion detection by checking whether files have been changed, added or deleted on a Windows 2000/XP system. Made by GFI_Software_Ltd File location is in the Program Files\GFI\System Integrity Monitor 3 folder.
    GFI Network Server Monitor 7.0 attendant service (GFI
    NSM 7 Attendant)
    Lnsm_attendant.exeRelated to Diskeeper Disk defragmental tool, and much more. Note: Located in \%Program Files%\GFI\Network Server Monitor 7\
    GFI Network Server Monitor 7.0 engine (GFI NSM 7
    Engine)
    Lnsm_engine.exeRelated to Diskeeper Disk defragmental tool, and much more. Note: Located in \%Program Files%\GFI\Network Server Monitor 7\
    GhostStartServiceLGHOSTS~2.EXERelated to Norton. GHOSTSTARTSERVICE is the background support task/service for Ghost for Windows.
    Giga Pocket Hardware DetectorLshwserv.exeSony computers
    Gilat host software update serviceLGSU.exeRelated to Gilat_Satellite Networks Ltd. Note: Located in \%Program Files%\Gilat\GSU\
    Gilat IBQoS AgentLibqossvc.exeRelated to Gilat_Satellite Networks Ltd. Note: Located in \%Program Files%\Gilat\IBQoS\
    Gilat Network Agent ServiceLNetAgent.exeRelated to Gilat_Satellite Networks Ltd. Note: Located in \%Program Files%\Gilat\
    Gilat Quality Measurement ServiceLQMS.exeRelated to Gilat_Satellite Networks Ltd. Note: Located in \%Program Files%\Gilat\QMS\
    Gizmo VoIP Service (Gizmo Plugin)LGizmoPlugin.exeRelated to Gizmo_VoIP Service from SIPphone, Inc. makes telephone calling as easy as instant messaging. Note: Located in \%Program Files%\GizmoPlugin\
    gldrXgldr.exeTrojan Related
    GoBack Polling Service (GBPoll)LGBPoll.exeSeems to be Roxio GoBack related
    Google Online Search ServiceXwinlagons.exeIdentified by Bitdefender as a variant of the Trojan.Downloader.Small.AAJM Trojan. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Google Online Search Service - 2ndXwinlast.exeIdentified as a variant Trojan-Downloader.Win32.Winlagons.aq Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Google Online ServicesXie_updates3r.exeIdentified as a variant of the TrojanDownloader:Win32/Tipikit.C malware. Note: Located in \%userprofile%\ Note: Use SDFix under supervision.
    Google Update Service (gupdate)LGoogleUpdate.exeRelated to Google_Updater_Service Note: Located in \%Program Files%\Google\Update\1.0.97.0\
    Google Updater Service (gusvc)LGoogleUpdaterService.exeRelated to Google_Updater_Service Note: Located in C:\Program Files\Google\Common\Google Updater\
    GoogleDesktopManagerLGoogleDesktopManager.exeRelated to Google_Desktop_Manager Note: Located in C:\Program Files\Google\Google Desktop Search\
    GoogleDesktopManagerLGoogleDesktop.exeRelated to google desktop
    Googles Onlines Search ServicesXwnslogan.exeIdentified as a variant of the Trojan-Downloader.Win32.Winlagons.an malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    GoToAssistLg2aservice.exeRelated to GoToAssist from Citrix Systems. Redefines the way support, consulting and IT professionals deliver technical help to customers. Note: Located in \%Program Files%\Citrix\GoToAssist\480\
    GoToMyPCLg2svc.exeRelated to Citrix Online
    GoverLAN Service (GOVsrv)LGOVsrv.EXEOwner:PJ Technologies Inc. See_Here
    Gray (Pigeon)XScrsss.exeAdded by the Troj/GrayBrd-AM TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    GrayPigeonServerXin.exeAdded by a variant of the Troj/GrayBrd-AP TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    GrayPigeonServerXG_Server2006.exeAdded by the Troj/Graybrd-EI TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ folder. More: delete this file also G_Server2006Key.DLL
    GrayPigeon_Hacker.com.cnXwinlogoin.exeAdded by the Troj/GrayBrd-BA TROJAN! Added by an unknown malware. Note: This worm\trojan is located in C:\%WINDIR%\TEMP\ folder.
    Gray_Pigeon (GrayPigeon)X.exeAdded by the Troj/GrayBrd-EH TROJAN! Note: This worm\trojan file is found in the Program Files folder.

    Engine Version 2.0 by CastleCops

    spacer spacer