CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9466.22 of $21422.68
left sidedonated so farneed $11956.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 3876 entries and growing...
Last updated on 2008-05-09 18:10:24 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    msieupdater (Microsoft IE Updater)Xupdate44105609.exeRelated to a variant of the Malware.IFN.dropper family. Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Note: filename is random in the format of update(Random Number).exe
    MSIEUpdater_1 (Microsoft IE Updater_1)Xie_updater1.exeIdentified as Downloader.Small.eop or Downloader.Murlo.fa Note: This worm is located in %userprofile%\
    MSIEUpdater_2 (Microsoft IE Updater_2)Xie_updater.exeAdded by a variant of the Troj/Bckdr-QGB TROJAN! Note: This worm\trojan is located in %userprofile%\
    MSInfo Framework Service (MSInfoFrv)XMSInfnd.exe Troj/Hupigon-FU Read the link, allows remote access
    MsInfo Service (MsInfo)XMsInfo.exe Small.H Note: Located in C:\RECYCLER\MsInfo\ Read the link, allows remote access
    msinit (Microsoft Scheduling Agent)Xmsinit.exeAdded by the W32/Tilebot-BJ WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    MSI_WLAN_ServiceLWLAN_Service.exePart of Microstar's WLan card. File found in the C:\Program Files\MicroStar\WLANUtility folder.
    mslogon (Microsoft System Logon Manager)Xmslogon.exeReported as Trojan-Dropper.Win32.Delf.ng by Kaspersky Anti-Virus. Note: This file is found in the Windows or Winnt folder.
    MsLS32 (MsLS32)XMsLS32.exeAdded by the W32/Tilebot-BS WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    MsLX32 (MsLX32)XMsLX32.exeAdded by the W32/Sdbot-AFS WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    MSMAPDEVICEXMSMAPDEVICE.SYSAdded by the TROJ_ROOTKIT.AK TROJAN! Read the link, rootkit type stealth involved.
    msmbios (Microsoft System Management BIOS Driver)Xmssmbios.exeAdded by the W32/Tilebot-AI TROJAN! Note: This trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    MSMPSVCLMSMPSVC.exeRelated to Windows_OneCare_Live from Microsoft
    MSN Clean MessengerXmsnmsgr.exe W32/Rbot-GJZ Read the link, allows remote access
    MSN RAVXmsnrav.exe W32/Sdbot-DGO Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Turns off anti-virus applications Allows others to access the computer Read the link
    Msn Service (MSNSVC)Xmsnsrv.exeAdded by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    msnntlpXmsnntlp.exe W32/Tilebot-JI Read the link, allows remote access
    MSQMXXmsqmx.sys Troj/StartP-BEH
    MSR CollectorLmsrCollector.exeRelated to Black White Box, Inc. Now owned by Vericept Corp. A Risk Management Platform
    msriv1 (msriv1)Xmsriv1.sysAdded by the Troj/Rootkit-W TROJAN! Read the link, rootkit type stealth involved.
    msscmc43Xmsscmc43.exeAdded by the W32/Spybot-NB WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    MsServiceXproxy.exeIdentified as Win32:Delf-IZD by Avast Note: Located in \%WINDIR%\System\
    MSSQL (MSSQL2K6)Xsqlsrv.exeAdded by the SDBOT.CNY or MYTOB.NC WORM! Read the link, rootkit type stealth involved.
    MSSQLServerADHelperLsqladhlp.exeRelated to Microsoft SQL Server 2000 desktop engine.
    MSSvc CRSS (CRSS)XMSSvc.EXEReported by Ewido security suite as Backdoor.SdBot.nj
    MSSysIntervXwinself.exeAdded by a variant of the Trojan-Downloader.Win32.Small.ufd TROJAN! Note: located in \%WINDIR%\ Note: Use SDFix under supervision.
    mst Defrag Service (mstDfrgS)LmstDfrgS.exeRelated to mst_Defrag
    MSTCSXMSTCS.EXEReported as Backdoor.Iroffer TROJAN! by What-process.com
    mstdel32 (mstdel32)Xmstdel32.exeAdded by the W32/Tilebot-BE WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MsUpdXmsupd4.exeAdded by the Lodmedud TROJAN!
    MsUpdXmsupd5.exeAdded by the Lodmedud TROJAN!
    MsUpdXmsupd6.exeAdded by the Lodmedud TROJAN!
    MSUpdate (Microsoft Update Service for 2005)Xmsupdate24.exeAdded by the W32/Tilebot-H WORM!
    msupdatefs (Microsoft Updater FileSystem)Xupdate13428241.exeRelated to a variant of the Malware.IFN.dropper family. Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Note: filename is random in the format of update(Random Number).exe
    msupdatefss (Microsoft Updater FileSystems)Xupdate62523833.exeRelated to a variant of the Malware.IFN.dropper family. Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Note: filename is random in the format of update(Random Number).exe
    msupdates (Microsoft Message Service XP)Xwin32chk.exeAdded by a variant of the Backdoor.Win32.SdBot.aad family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\
    msvbnXmsvbn.exeAdded by the Backdoor.Win32.SdBot.auv TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    msvnc (msvnc)Xmsvnc.sysAdded by the TROJ_ROOTKIT.M TROJAN! Read the link, rootkit type stealth involved.
    msvrcs(msvrcs) (msvrcs)Xmsvrcs.exeAdded by the W32/Sdbot-CRX WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    MtRepair1XMtRepair1.exe Mirar
    MtRepair2XMtRepair2.exe Mirar
    muamgrd.exeXmuamgrd.exeAdded by a variant of the AGOBOT.GEN WORM! Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Multi-user Cleanup ServiceLntmulti.exeRelated to IBM Lotus Note software.
    MWAgentLMWASER.EXERelated to MicroWorld Technologies Inc. - Antivirus & Content Security suite. Note: Located in C:\Program Files\Common Files\MicroWorld\Agent\
    MWSarcpktLMWSEtherpkt.exeRelated to Gateway Ticketing Systems, Inc. http://www.gatewayticketing.com/
    MWSejcapLMWSejcap.exeRelated to Gateway Ticketing Systems, Inc. http://www.gatewayticketing.com/
    MWSpollserverLPollServer.exeRelated to Gateway Ticketing Systems, Inc. http://www.gatewayticketing.com/
    MWSschedLsutmsced.exeRelated to Gateway Ticketing Systems, Inc. http://www.gatewayticketing.com/
    MWSTickLMWSTick.exeRelated to Gateway Ticketing Systems, Inc. http://www.gatewayticketing.com/
    MXS(mxs) (MXS)Xmxs.exeAdded by the W32/Sdbot-CTT WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)

    Engine Version 2.0 by CastleCops

    spacer spacer