CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

O23 List of Windows XP/NT services

Currently 4053 entries and growing...
Last updated on 2008-08-02 17:32:28 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    Microsoft Corporation (Windows Wordpad)Xwordpad.exeAdded by the W32/Tilebot-GL WORM! Note: This worm\trojan is located in C:\%WINDIR%\ This is not Microsoft's wordpad.exe. To make sure check the properties of the file.
    Microsoft Coyshader RuntimeXserv32.exeAdded by the W32/Rbot-GHJ WORM! Note: This worm\trojan is located in C:\%WINDIR%\ Install a rookit. rdriv.sys run a rootkit removal tool
    Microsoft Coyshader RuntimeXservice.exeAdded by the W32/Rbot-GHJ WORM! Note: This worm\trojan is located in C:\%WINDIR%\ Install a rookit. rdriv.sys run a rootkit removal tool
    Microsoft CTF LoaderLctfmon.exeCTF Loader
    Microsoft DHCPA ServiceXmshcp.exeAdded by the W32/Rbot-FNA WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft Digital Identity Service (InfoCard Service)Linfocard.exeRelated to Microsoft_NET_Framework .NET Framework is a development and execution environment that allows different programming languages & libraries to work together seamlessly to create Windows-based applications.
    Microsoft Dir32XDirhost.com W32/IRCBot-YC Note:Located in C:\Windows\System\dllcache (Win9x/Me), C:\%WINDIR%\System32\dllcache (XP/WinNT/2K) Steals information, allows remote access, read the link
    Microsoft Display ServiceXmsds.exe Troj/Spybot-NZ Note: Note:Located in C:\Windows\System\dllcache (Win9x/Me), C:\%WINDIR%\System32\dllcache (XP/WinNT/2K) Allows others to access the computer
    Microsoft Distributed Transaction (MSDT)Xmsdt.exeAdded by the W32/Tilebot-BQ WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Microsoft DLL SystemXsmsc.exeAdded by the W32/Tilebot-FY WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Genuine AdvantageXwinmga.exe Reported as Backdoor.Win32.VanBot.dk Note: Located in \%WINDIR%\system32\dllcache (XP/WinNT/2K)
    Microsoft Genuine Update AdvantageXmswan.exeIdentified as a variant of the Backdoor.Win32.VanBot.dk worm. Note: Located in \%WINDIR%\System32\dllcache\
    Microsoft HDA Protocol (svhda)Xsvhda.exeaDEED BY THE Backdoor.Win32.IRCBot.rr as detected by Kaspersky TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Microsoft IEXIEXPLORE.EXEAdded by the W32/Forbot-AG WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Note: This is not the legitimate Windows Process. (Which is found in the C:\Program Files\Internet Explorer\ folder.) This worm\trojan file is found in the C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32
    Microsoft IIS helperXmsiishlp.exeAdded by the Backdoor.Isen.Rootkit TROJAN! Read the link, rootkit type stealth involved.
    Microsoft Inet ServiceX_svchost.exeAdded by the Troj/Dwnldr-GYS Trojan! Note: Located in \%WINDIR%\System32\ This infection should not be confused with the legitimate \%WINDIR%\System32\svchost.exe file.
    Microsoft information dll service (msidll)Xmsidll.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    Microsoft Internet ExplorerXiexplore.exe W32/Tilebot-JS Read the link, allows remote access
    Microsoft Internet Information Services kernel mode
    driver
    Xmsiisdrv.exeAdded by the Backdoor.Isen.Rootkit TROJAN! Read the link, rootkit type stealth involved.
    Microsoft Java Service (Windows Java Service)Xjusched.exeAdded by an unidentified TROJAN! Note: This trojan is located in C:\%WINDIR%\
    Microsoft Language Service (Windows Language Service)Xalg.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder
    Microsoft Loading ServiceXfiles.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    Microsoft Loading ServiceXloader.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft Loading ServiceXmsdates.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft Logitech WLANXmslw.exeAdded by a variant of the Win32/IRCBot.UG Note: Located in \%WINDIR%\System32\dllcache Note: Use SDFix under supervision.
    Microsoft Logon ServiceXmslogon.exeAdded by the W32.Woredbot.C TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft Logon User Interface Skining (LogonUInterf)Xlogonui.exeDetected by Ewido as Backdoor.SdBot.aad. This worm file is found in the Windows or Winnt folder.
    Microsoft Main Window ServiceXmainwin32.exeAdded by the W32/Spybot-MR WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) disabling autostart for the SharedAccess service deactivates the Microsoft Internet Connection
    Microsoft MediaXrtsecas.exe W32/Rbot-KPH Read the link, allows remote access
    Microsoft MediaXRtsecar.exe W32/Vanebot-AX Read the link, allows remote access
    MicroSoft Media ToolsXMSMEDIA.EXEAdded by the SDBOT.CUH WORM! Note: This worm file is found in the System32 folder. (NT/2000/XP) Read the link, rootkit type stealth involved.
    MicroSoft Media Tools (MicroSoft Media Tools)XMSmedia.exeAdded by the W32/Tilebot-BC WORM! Note: This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Microsoft MSI ServiceXmsi.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft Name ServerXnssrv.exe W32/Tilebot-EK Read the link, allows remote access
    Microsoft Net API (NETAPI)Xmsapi.exeAdded by the W32/Tilebot-HJ WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft NetWork FireWall ServicesXNet_Services.exehttp://www.sophos.com/virusinfo/analyses/w32lovgateaa.html
    Microsoft NetWork FireWall ServicesXNetServices.exehttp://www.sophos.com/virusinfo/analyses/w32lovgateaa.html
    Microsoft Network RPCXmsnetrpc.exeRelated to the Troj/Isen-B
    Microsoft Networks DN (msndn)Xmsndn.exeAdded by the Backdoor.SdBot.AQZ, A.K.A. Ircbot_Gen WORM! Allows a remote intruder to gain access and control over the computer.
    Microsoft New Game 2 (svehost32)Xsvehost32.exeAdded by the W32/Tilebot-I TROJAN! Read the link, rootkit type stealth involved.
    Microsoft NewssXnewhost.exeAdded by an unknown_Trojan Note: Located in \%WINDIR%\System32\dllcache\ Note: Use SDFix under supervision.
    Microsoft Null Development Monitor (msdevnull)Xmsdevnull.exeAdded by the W32/Rbot-AGE Worm! Read the link, rootkit type stealth involved.
    Microsoft Passport Network CyberShotsXcybershots.exeAdded by the W32/Spybot-ND WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) disabling autostart for the SharedAccess service deactivates the Microsoft Internet Connection Firewall (ICF).
    Microsoft Path Finder Service (MSpath)Xmspath.exeAdded by the W32/Sdbot-AEO WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Microsoft Path Finder Service (mspathfinder)XmspathfinderAdded by the W32/Tilebot-AH WORM! Rootkit Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Performance WMI Adapter AddOn (WMIPervAddOn)Xwmiapsv.exeAdded by the Backdoor.Win32.SdBot.aad TROJAN! Reported by Kaspersky More Note: This worm\trojan is located in C:\%WINDIR%\
    Microsoft Print Spooler (WINDRIVER)Xscvhost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft proxysys (proxysys)Xproxysys.exe W32/Tilebot-JC Read the link, allows remote access
    Microsoft PS ServiceX_svchost.exeIdentified as a variant of the TrojanDownloader:Win32/Tipikit.A malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Microsoft register shieldXMrshield.exeAdded by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\

    Engine Version 2.0 by CastleCops

    spacer spacer