CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

O23 List of Windows XP/NT services

Currently 4053 entries and growing...
Last updated on 2008-08-02 17:32:28 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    NTCHARGELwinlogon.exeRelated to Microsoft Internet Information Services (IIS).
    NTFS Crypto Technology (NTFSCrypt)Xntfscrypt.exeAdded by the W32/Spybot-NC WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    NTFS File Location Service (NTFSFLS)Xntfsloc.exeAdded by the W32/Sdbot-CSG WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    NTFSprotect (ntfsdiscman)Xntfsprotect.exeAdded by the SDBOT.CCF WORM! Read the link, rootkit type stealth involved.
    ntldr.sysXntldr.sys Troj/SpamToo-AQ Creates the file %Root%
    Ntlm_Drive_Connect (Ntlm_Drive_Connect)XTimerU.sysAdded by the Tuimer TROJAN!
    NTLOADXntsrv.exeIdentified as Win32.Iroffer.b by Kasperksy. Note: Located in \%WINDIR%\System32\dllcache\win32\
    NTLOADXwinlogon.exeOther files in the same directory identified as Win32.Iroffer.b by Kaspersky
    ntmssvcXsvchost.exe -k ntmssvcAdded by the Fuwudoor TROJAN!
    ntmssvcXSysPkOs.dll Troj/BkDoor-A Troj/BkDoor-A may overwrite registry entries, to enable it to run as a service. Read link
    NTP (Network Time Protocol)Xwinlogon.exeAdded by the Troj/Jtram-D TROJAN! Note: This trojan file is found in the System32\Client folder.
    NTRU Hybrid TSS v1.05 TCSD (tcsd_win32.exe)Ltcsd_win32.exeRelated to NTRU_Cryptosystems Inc. Provider a public key cryptography system (PKCS)
    NTRU Hybrid TSS v2.0.7 TCS (tcsd_win32.exe)Ltcsd_win32.exeRelated to NTRU_Cryptosystems Inc. Provider a public key cryptography system (PKCS) Note: Located in \%Program Files%\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.7\bin\
    NTSec(ntsec) (NTSec)Xntsec.exeIdentified as Trojan-Dropper.VB.22 by VBA32 Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) This should not be confused with Keylog_Ardamax A program may have legitimate uses in contexts where an authorized administrator has knowingly installed this application. Located in %Documents and Settings% \Start Menu\Programs\Ardamax Keylogger. If you did not install this program remove it.
    NTSecureOsrvany1234.exeUnknown owner: Location C:\WINDOWS\system32\srvany1234.exe
    NTSVCMGRXwinlogon.exeIdentified as Win32.Iroffer.b by Kasperksy. Note: Located in \%WINDIR%\System32\dllcache\win32\ Note: This is not the legitimate Windows Process which is found in \%WINDIR%\System32\ folder.
    NTSVCMGRXntsrv.exeIdentified as Win32.Iroffer.b by Kasperksy. Note: Located in \%WINDIR%\System32\dllcache\win32\
    NTsyslogLntsyslog.exeRelated to Open_Source_Technology Group. An application logging functionality.
    nTune Service (nTuneService)LnTuneService.exeRelated to NVIDIA Access Manager. Note: Located in C:\Program Files\NVIDIA Corporation\nTune\
    NTVDMXntvdm.exe W32/Tilebot-JZ Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR%(XP/WinNT/2K) Used in DOS attacks, Allows others to access the computer Please read information on link
    NuTCRACKER KernelLnutkserv.exeRelated to openUTM from Fujitsu Siemens Computers
    NuTCRACKER ServiceLnutsrv4.exeRelated to Rational Rose, MKS Toolkit for Enterprise Developers
    NuTCRACKERServiceLnutsrv4.exeRelated to MKS from DataFocus Inc. Toolkit for Enterprise Developers.
    NvCplScanXmsc32.exeRelated to the W32/FORBOT-DD
    NvCplScanXnvsc32.exeanother example, added by Forbot_ET.
    NvedavtLousbehci.sysRelated to OrangeWare Corp.
    nvidGUIv (nvidGUIv2)XNVIDGUIV.EXEAdded by the SDBOT.CTQ WORM! Read the link, rootkit type stealth involved.
    NVIDIA Display Driver Service (NVSvc)Lnvsvc32.exeRelated to NVIDIA drivers.
    NVIDIA Display Driver Service (Omega 1.6693) (P)
    (NVSvc)
    Lnvsvc32.exeRelated to NVIDIA, http://www.nvidia.com/ drivers.
    NVIDIA Display Service (NVIDIA Display Driver Service)XNvds.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\%WINDIR%\ folder
    NVIDIA Driver Helper Service (NVSvc)Lnvsvc32.exeRelated to NVIDIA drivers. Note: Located in \%WINDIR%\System32\
    NVIDIA Driver Serviceˇˇ (NVSv )Xsvchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\
    Nvidia Graphic Displacement (nvideoGUI)Xnvideogui.exeAdded by the SDBOT.CQD WORM! Read the link, rootkit type stealth involved.
    NVIDIA PVR Schedule Monitor (nvpvrmon)Lnvpvrmon.exeRelated to NVIDIA ForceWare driver. Note: Located in C:\Program Files\NVIDIA Corporation\ForceWare\Multimedia\NVPVR\
    nvsec(nvsec) (NvSec)Xnvsec.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here
    nvsvc32.exeXwmisp.exeAdded by the Backdoor_Win32_SdBot_aad WORM! - Reported by KASPERSKY ON-LINE SCANNER
    O&O CleverCache Agent (OOCleverCacheAgent)Looccag.exeRelated to O&O_Software Products. Located in folder: \OO Software\CleverCache\
    O&O ComponentInstaller AgentLoocinst.exeRelated to O&O software Protection Software
    O&O DefragLoodag.exewww.oo-software.com
    O&O Defrag 2000 (OOD2000)LOOD2000.exePart of O&O Defrag
    O23 - Service: AOL Anti-Spyware Service
    (AOL_SpywareServ)
    Xaolspy.exeAdded by a variant of the Backdoor.Win32.Rbot.cgu TROJAN! Note: This worm\trojan is located in C:\WINDOWS\web\
    O23 - Service: OradevReports [localrepserver]
    (OracleReportServer-localrepserver)
    Lrwserver.exeRelated to Oracle products
    O2Micro Flash Memory (O2Flash)Lo2flash.exeRelated to O2Micro_Flash Memory Card. Note: Located in C:\WINDOWS\system32\
    Odyssey Client for Fujitsu Siemens Computers
    (odClientService)
    LodClientService.exeRelated to Odyssey_Client for Fujitsu Siemens Computers. Note: Located in C:\Program\Fujitsu Siemens Computers\Odyssey Client for Fujitsu Siemens Computers\
    OESH (Office Source Engine Help)XProgram.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C: folder.
    Office Server Extensions Notification Service
    (OWSTimer)
    LOWSTIMER.EXERelated to Microsoft_SharePoint Note: Located in C:\Program Files\icrosoft Office\Office\ Files\
    Office Source Engine (ose)LOSE.EXEMicrosoft Office Source Engine
    OfficeScan NT Listener (tmlisten)Ltmlisten.exeRelated to Trend_Micro RealTime Scan Antivirus application. Note: Located in \%Program Files%\Trend Micro\OfficeScan Client\
    OfficeScan NT Proxy Service (TmProxy)Ltmproxy.exeRelated to Trend Micro Inc.
    OfficeScanNT Listener (tmlisten)Ltmlisten.exeRelated to Trend_Micro RealTime Scan Antivirus application. Note: Located in \%Program Files%\Trend Micro\OfficeScan Client\

    Engine Version 2.0 by CastleCops

    spacer spacer