CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9466.22 of $21422.68
left sidedonated so farneed $11956.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 3876 entries and growing...
Last updated on 2008-05-09 18:10:24 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    mental ray 3.5 Satellite (64-bit)
    (mi-raysat_3dsmax9_64)
    Lraysat_3dsmax9_64server.exeRelated to Autodesk_3ds_Max_9_3D_animation Create rich and complex design visualization. Note: Located in \%Program Files%\Autodesk\3ds Max 9\mentalray\satellite\
    mental ray 3.5 Satellite for Autodesk VIZ 2008
    (mi-raysat_VIZ2008_32)
    Lraysat_VIZ2008_32server.exeRelated to Autodesk on line game. Note: Located in \%Program Files%\Autodesk\VIZ2008\mentalray\satellite\
    mental ray 3.6 Satellite for Autodesk 3ds Max 2008
    32-bit 32-bit (mi-raysat_3dsMax2008_32)
    Lraysat_3dsMax2008_32server.exeRelated to Autodesk on line game. Note: Located in \%Program Files%\Autodesk\VIZ2008\mentalray\satellite\
    Merak GroupWare Server (MerakCalendar)Lcalendar.exeRelated to Merak_GroupWare from Merak. Note: Located in \%Program Files%\Merak\
    Merak Instant Messaging Server (MerakIM)Lim.exeRelated to Instant_Messaging from Merak. Note: Located in \%Program Files%\Merak\
    Merak Mail Server Control (MerakControl)Lcontrol.exeRelated to Merak_Mail_Server Software. A high performance mail server software suite for Windows or Linux
    Merak Mail Server POP3/IMAP (MerakPOP3)Lpop3.exeRelated to Merak_Mail_Server Software. A high performance mail server software suite for Windows or Linux
    Merak Mail Server SMTP (MerakSMTP)Lsmtp.exeRelated to Merak_Mail_Server Software. A high performance mail server software suite for Windows or Linux
    MERANT XDB Server for NX 3.1Lxsrvnx.exeRelated to SERENA Software, Inc. - http://www.serena.com/
    MespangerXsvchost.exeAdded by a variant of the Trojan-Downloader.Win32.Delf.asz Trojan. Note: Located in \%ROOT%\Recyclers\ This infection should not be confused with the legitimate Note: \%WINDIR%\System32\svchost.exe file.
    Messaging Application Programming Interface (Mapi)Xmapi.exeAdded by the W32/Sdbot-DFC Worm Read the link, allows remote access
    MessanderXsvchost.exeAdded by a variant of the Trojan-Downloader.Win32.Delf.asz Trojan. Note: Located in \%ROOT%\Recyclers\ ,or \%ROOT%\Recyclers\. This infection should not be confused with the legitimate Note: \%WINDIR%\System32\svchost.exe file.
    MessangerXsvchost.exeAdded by a variant of the Trojan-Downloader.Win32.Delf.asz Trojan. Note: Located in \%ROOT%\Recyclers\ This infection should not be confused with the legitimate Note: \%WINDIR%\System32\svchost.exe file.
    MessengerXsvchost.exe -k MessengerAdded by the Fuwudoor TROJAN!
    MessengerXkernel32.exeAdded by the Troj/Kyth-A TROJAN! Note: Replaces any existing services named Messenger.
    MessengerXsys.exeAdded by the Troj/PcClient-H TROJAN! Note: This worm\trojan file is found in the System32 folder.
    MessengerXKB08953265.exeAdded by the Esteems.F TROJAN! Note: Drops multiple files.
    Messenger (Messenger)X(TROJAN FILE NAME)Added by the Trojan.Neasemal TROJAN! Note: This trojan file will be found in the System32 folder and may have one of the following file extensions: .kop or .del or .axs
    Messenger (Messenger)Xhacker.exeAdded by the Troj/PcClient-M TROJAN! Note: This trojan file is found in the System32 and Temp folders.
    Messenger Accelerator (Accelerator Tools)Xmdn.exe Troj/Bifrose-UV Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Messenger Sharing Folders USN Journal Reader service
    (usnjsvc)
    Lusnsvc.exeRelated to Messenger_Sharing_Folders_USN_Journal Reader service from Microsoft. Note: Located in C:\Program Files\MSN Messenger\
    Messenger Sharing USN Journal ServiceXusnsv.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    MessssangerXsvchost.exeAdded by a variant of the Trojan-Downloader.Win32.Delf.asz Trojan. Note: Located in \%ROOT%\Recyclers\ This infection should not be confused with the legitimate Note: \%WINDIR%\System32\svchost.exe file.
    MetaFrame COM Server (MFCom)Lmfcom.exeRelated to Citrix MetaFrame
    MFA Security Services (MFASec)Lmfasvc.exeRelated to Sentry_At_Home Parental Controls software. Note: Located in \%WINDIR%\System32\
    MGABGEXELmgabg.exeMatrox BIOS Guard. What does it do and is it required?
    MGACtrlLmgasc.exeRelated to products from Matrox graphics
    MgiSvrLuMgiSvr.exeRelated to Magic-i from ArcSoft A powerful webcam application designed to enhance users' video chat experience. Note: Located in C:\Program Files\ArcSoft\Magic-i 3\
    Micr0s0ft AgentXsxch0st.exeAdded by a variant of the Worm.RBot.UTA family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\dllcache\
    MICR0SOFT SVCH0ST (MS_SVCH0ST)XSVCH0ST.EXEDetected by BitDefender as Trojan.Spy.Agent.PV
    Microsoft AgentXrschost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System\dllcache (Win9x/Me), C:\%WINDIR%\System32\dllcache (XP/WinNT/2K)
    Microsoft AgentXsnchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) More: here
    Microsoft AgentXffchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: Located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft AgentXlpohost.exeAdded by the W32/Sdbot-CWQ WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft AgentXqxchost.exeAdded by the W32/Sdbot-CWP WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft AgentXlkmhost.exe W32/Vanebot-AD Note: Located in %windir%\system32\dllcache Read the link, allows remote access
    Microsoft AgentXxnchost.exeAdded by an unidentified TROJAN! of the Sdbot family.
    Microsoft AgentXppchost.exeAdded by a variant of the W32/Sdbot-CYE WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    Microsoft AgentXsuchost.exe W32/Sdbot-DDD Read the link, allows remote access
    Microsoft AgentXcvchost.exe W32/Sdbot-DFH Read the link, allows remote access
    Microsoft AntiSpyware (Beta 1)LgcasDtServ.exeMicrosoft AntiSpyware Data Service
    Microsoft AntiSpyware (Beta 1)LgcasServ.exe Microsoft AntiSpyware Service
    Microsoft AntiSpyware (Beta 1)LGIANTAntiSpywareMain.exe Microsoft AntiSpyware Main
    Microsoft Apache for Windows (Windows Apache Service)Xwpablin.exeAdded by the W32/Tilebot-IL WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder
    Microsoft ASPI Manager (aspi113210)Xaspi113210.exeAdded by the Troj/Danmec-T TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Modify the hosts file, Terminate AV related processes and services, Steal information. Read the article. Filename is partly random (aspinnnnnn.exe) n representing a number.
    Microsoft ASPI Manager (aspimgr)Xaspimgr.exeDetected as Backdoor.Win32.Agent.aju by Kaspersky
    Microsoft authenticate service (MsaSvc)Xmsasvc.exeAdded by Worm_Ircbot_Gen Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Microsoft Bluetooth Support (BthSupp)Xbthsupp.exeAdded by the W32/Btbot-A WORM!
    Microsoft cache control (MSControlService)XwindowsDetected by NOD32 as Win32/Adware.SecToolbar application Note: Located in %windir%\System32
    Microsoft Client Agent Service (Microsoft Client Agent)Xmsclient.exeAdded by the W32/Tilebot-BP WORM! Note: This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.

    Engine Version 2.0 by CastleCops

    spacer spacer