CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9466.22 of $21422.68
left sidedonated so farneed $11956.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 3876 entries and growing...
Last updated on 2008-05-09 18:10:24 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    RdnaoFlSvcLnaofsvc.exeRelated to Naomi an advanced internet filtering program.
    rdriv (rdriv)Xrdriv.sysAdded by the Troj/Rootkit-W TROJAN! Read the link, rootkit type stealth involved.
    ReaConverter scheduler service (rcp_service)Lrcp_scheduler.exeRelated to ReaConverter image editing features make the Lite edition a perfect choice for home users. Note: Located in \%Program Files%\ReaConverter 5.0 Pro\
    Realplus (Realplus)Xsserver.exeAdded by the Troj/Paltus-A TROJAN! Note: This trojan file is found in the System32 folder.
    Reflection Line Printer DaemonLlpdserv.exeRelated to http://www.wrq.com/
    Reflection ServersLrninetd.exeRelated to http://www.wrq.com/
    Reflection TimeSyncLrtsserv.exeRelated to WRQ, Inc. http://www.wrq.com/products/reflection/
    regdefendLregdefend.sysSee Ghostsecurity Location: C:\Program Files\RegDefend\regdefend.sys
    Regedits Helpers (Windows Regedits Help)Xiesetup.exe Troj/Hupigon-KX Note: Located in %windir%\help
    Regedits Helps (Windows Regedit Helps)Xiesetup.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\iis] (Win9x/Me), C:\%WINDIR%\System32\iis\ (XP/WinNT/2K) More here
    Register DLL DriverXregdll.exeAdded by the W32/Sdbot-CXB WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Register ManagerXregent.exeAdded by the W32/Sdbot-DFJ WORM! Note: This worm is located in \%WINDIR%\ Read the link, allows remote access.
    Registration Host (reghost)Xreghost.exe Added by the W32/Rbot-GKS WORM! Note: This worm is located in C:\Program Files\Common Files\System\
    Registro de sucesos (Eventlog)Lservices.exeSpanish Windows 2000 event logger
    Registros y alertas de rendimiento (SysmonLog)Lsmlogsvc.exeSpanish Windows 2000 performance logs and alerts
    Registry Editor (Regedit)Xregedit.exeAdded by the W32/Codbot-U TROJAN! Note: This is not the regedit application that comes with Windows. (Which is located in the Windows folder) This trojan file is located in the System or System32 folder.
    Registry Management Service (RegManServ)LRegManServ.exeRelated to Complete_PC_Care from WinCleaner. Note: Located in C:\Program Files\Advanced Registry Doctor\
    Registry Manager Service (MS Registry Service)XMSRMS32.exeAdded by the W32/Rbot-AKP WORM!
    RegServiceLRegService.exeRelated to Intel Corp. http://www.intel.com/network/connectivity/trans/xircom.htm
    RegSrvcLRegSrvc.exeIntel PROset
    regstrmonXregstrmon.exeAddeD by the WORM_RBOT.ADA WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    RelevantKnowledgeXrlservice.exeAdded by the Marketscore.RelevantKnowledge ADWARE! Note: Located in \%WINDIR%\System32\
    remon (remon)Xremon.sysAdded by the Troj/RKFu-A TROJAN! Read the link, rootkit type stealth involved.
    Remote Acces (WindowsDown)Xservet.exe Troj/Dloadr-AYT
    Remote Acces (WindowsFix)Xservet.exe W32/Sekap-A Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Allows remote access
    Remote Access Controller 4 (RAC) (racsvc)Lracsvc.exeRelated to Dell Open Manage NT Utilities program that allows remote access and control of a computer. This is a common program for hackers to install on a computer, so if it is installed, and you did not install it, it should be removed.
    Remote Account Manager (ramtsvc)Xrasmvc.exeAdded by an Unknown malware Note: Located in \%WINDIR%\System32\mui\
    Remote Administrator Service (r_server)Xsystemram.exeAdded by the Troj/Radnag-B Trojan!
    Remote Administrator Service (r_server)Xr_server.exeAdded by the Troj/Remadm-J TROJAN! Note: This trojan file is found in Program Files\real\RealOne Player\lang folder.
    Remote Administrator Service (r_server)Or_server.exeRelated to r_server.exe part of a remote administrator application that allows a user to work on one or more remote computers. The application contains features such as File Transfer, NT security and Telnet. Note: Located in \%WINDIR%\System32\ If you did not installed this server it is suggested that your remove it
    Remote Break ManagerXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Desktop Help Session Manager (RDSessMgr)Lsessmgr.exeRelated to Microsoft's remote assistance windows plugin. This allows an end user to call for assistance when a remote assistance network service is in place. This process shouldn't be terminated if the fore-mentioned service is in place on your local area network.
    Remote Displays ServiceXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Help Session Manager (Rasautol)Xntsokele.exe W32/Fujacks-AP Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Allows others to access the computer
    Remote HID Service (LvHidSvc)Olvhidsvc.exeRemote access service by Philips Inc. Legitimate, but remote access could be considered dangerous unless monitored carefully.
    Remote management (Novell WUser Agent)Lwuser32.exeRelated to Novel, Inc.
    Remote Map ManagerXlssc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Media PlayerXlsscs.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Neon ServicesXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote NetBIOS ManagerXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote NTstat ServicesXsvshost.exeAdded A variant of the Backdoor.Sdbot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Packet Capture Protocol v.0 (experimental)
    (rpcapd)
    Lrpcapd.exeRelated to Winpcap (Windows Packet Capture Library)
    Remote Print Spooler (RPSGV)Xgcsvc.exeAdded by a variant of the Win32.SdBot.aad a TROJAN! identified by F-Secure. Note: This trojan is located in C:\%WINDIR%\
    Remote Procadure Call (RPC) (RpeSs) Xsvchost.exe Troj/Hupigo-UN Read the link, steals information Note: Located in %windir%
    Remote Procedure Call (RPC) Client (RpcClient)Xrpcclient.exeAdded by the W32/Codbot-L WORM!
    Remote Procedure Call (RPC) HelperXrandomCoolWebSearch malware
    Remote Procedure Call (RPC) Helper ( 6Q'8)Xipjp32.exeAdded by the Trojan.Win32.Agent.bi TROJAN! Note: located in \%WINDIR%\
    Remote Procedure Call (RPC) Locator (Locator)Xrpclocator.exeAdded by the W32/Codbot-Q WORM!
    Remote Procedure Call (RPC) Monitoring (Rpcmon)XRpcmon.exeAdded by the W32/Codbot-T WORM!
    Remote Procedure Call (RPC) Net (Rpcnet)LRpcnet.exeRelated to Laptop_Retriever

    Engine Version 2.0 by CastleCops

    spacer spacer