CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9466.22 of $21422.68
left sidedonated so farneed $11956.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 3876 entries and growing...
Last updated on 2008-05-09 18:10:24 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    Remote Procedure Call (RPC) Relocator (RpcRelocator)Xrelocater.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    Remote Procedure Call (RPC) Remote (RpcRemotes)Xremote.exeAdded by the W32/Mytob-EW WORM! or Troj/Agent-FB TROJAN! Note: This worm\trojan file is found in the System32 folder.
    Remote Procedure Call (RPC) Service (RpcSssvc)XRpcSs.exeAdded by the W32/Cuebot-J WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Note: The file RpcSs.exe is also a good Microsoft file. Before deleting check the propriatiry of the file.
    Remote Procedure Call (RPC) Subsystem (RPCS)Xrpcss.exe W32/Tilebot-JF Read the link, allows remote access
    Remote Procedure Call System (RPCS)XWin.exe Troj/Dropper-PT Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Procedure Call System(RPCS) (RpcS)XRpcs.exeAdded by the Troj/QQRob-ABS TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    Remote Procedure Call System(RPCS) (RpcSe)XRpcse.exeAdded by the Troj/Mdrop-BMK TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Procedure Call System(RPCSss) (RpcSss)XRpcSss.exeAdded by the Troj/QQRob-ACI TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Procedure Call System(RPCSU) (RpcSu)XRpcsu.exeAdded by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    Remote Procedure Call System(RPCSx) (RpcSx)XRpcsx.exeAdded by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    Remote Process KillerORKillSrv.exeThe Windows NT Resource Kits, both NT4 and Windows 2000 Professional, include a remote kill process commandline utility rkill.exe . To be able to kill a process or processes running on a remote server, you must have admin privileges and the rkillsrv.exe service must be installed and running. If this service was not installed by you or an LAN Admin. remove it. Note: Located in \%WINDIR%\System32\
    Remote Reader MachineXssmc.exeAdded by the Backdoor.SdBot.avk as detected by ewido. More here
    Remote Record Service (RemoteRecord)Lremoterecordclient.exeRelated to MSN_TV Note: Located in c:\program files\microsoft corporation\msn remote record service\
    Remote Republic ServicesXsvshost.exeAdded by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\
    Remote Run ServicesXsvshost.exeAdded by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\
    Remote Services Manager (RSMSS)X(Trojan file name)Added by the Troj/Bckdr-BBK TROJAN!
    Remote Solver for COSMOSFloWorks 2006LStandAloneSlv.exeRelated to COSMOS_FloWorks From COSMOS. CAD program. Note: Located in C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\
    Remote Storage (Rmtstrg)Xtaskmgr.exeAdded by the Troj/Spy-UN TOJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K) Read the link, monitors websites visited and report them to a remote site
    Remote Storage (RS) (Rmtstrg2)Xtaskmgr.exeAdded by a varian the Troj/Spy-UN TOJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K) Read the link, monitors websites visited and report them to a remote site
    Remote Task Manager service (RTM)LRTMService.exeRelated to Remote_Task_Manager remote control suite. Note: Located in C:\Program Files\Remote Task Manager\
    Remote TCP ServicesXvcmon.exeAdded by the W32/Tilebot-HX WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) disabling the automatic startup of other software.
    Remote TCPI ServicesXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Terminal (RemoteTerminal)Xmscp.exeAdded by the Backdoor.Win32.SdBot.aad TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Time PlugerXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Transfer ManagerXsvshost.exe W32/Rbot-GQR Read the link, allows remote access
    Remote Windows ServicesXvcmon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    RemoteControlService.exeLRemoteControlService.exeRelated to ITE_Remote_Control Service from ITE Tech. Inc. Note: Located in \%WINDIR%\System32\
    Remotely Possible/32 (RP32Service)Lrp32serv.exeRelated to Avalan now owned by Computer Associates International, Inc. http://ca.com/products/
    RemotelyAnywhereLRemotelyAnywhere.exeRelated to RemotelyAnywhere Made by 3am Labs Inc. This file should be found in the Program Files\RemotelyAnywhere folder.
    RemotelyAnywhere Maintenance Service (RAMaint)LRaMaint.exeRelated to RemotelyAnywhere Made by 3am Labs Inc. This file should be found in the Program Files\RemotelyAnywhere folder.
    RemoteRegBckXregsvc.exeAdded by Backdoor.Win32.SdBot.aad as identified by Kaspersky. TROJAN! Note: located in C:\WINDOWS\. Not to be confused with the Original Microsoft file in C:\WINDOWS\system32\
    Removale Sorage (RemovaleSorage)XG_Server.exeAdded by the Troj/Feutel-AT TROJAN! Note: This trojan file is found in the System32 folder.
    Required Service DriversXmicront.exeAdded by the W32/Rbot-ABD WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) terminate threads and processes read the information
    Reset 5Osrvany.exeUnknown owner: Location C:\Windows\System32\srvany.exe In this case srvany.exe is loading resetservice.exe as a service. May be found in the company of O20 - Winlogon Notify: reset5 - C:\WINDOWS\SYSTEM32\reset5.dll Windows XP Product Activation Bypass So as to avoid the registration process on boot-up. Typically used on a pirated Operating System.
    Resource Manager Mail (ResourceManagerMail)LMailService.exeRelated to Citrix Systems, Inc.
    restore (restore)Xrestore.exeAdded by the SDBOT.CFD WORM! Read the link, rootkit type stealth involved.
    Retrospect ClientLRemotSvc.exeRelated to Dantz Development Corporation
    Retrospect Express HD Launcher (RetroExpLauncher)Lretrorun.exeRelated to Dantz Development Corporation
    Retrospect Express HD Restore Helper (RetroExp Helper)Lrthlpsvc.exeRelated to Dantz Development Corporation
    Retrospect HelperLrthlpsvc.exeRelated to Dantz Development Corporation
    Retrospect Launcher (RetroLauncher)Lretrorun.exeRelated to Dantz Development Corporation
    Retrospect WD Service (RetroWDSvc)Lwdsvc.exeRelated to Dantz Development Corporation
    Reuters XMS Sync (RXMSSync)Lrxmssync.exeRelated to Reuters_XMS_Sync routers. Note: Located in http://www.routers.com/
    RevUDFServiceLRevUDF.exeRelated to Iomega_Corp provider of a number of backup data solutions
    Rio MSC Manager (RioMSC)LRioMSC.exeRelated to Digital Networks North America.
    Rising Personal Firewall Service (RfwService)Lrfwsrv.exeRelated to Rising_Personal_Firewall, Rising Personal Firewall from Beijing Rising Tech., Corp. service. Note: Located in \%Program Files%\rising\rfw\
    Rll enhanced drive (mfm)Xmsrll.exeAdded by the Troj/Jtram-E TROJAN! Note: This trojan file is found in the System32\mfm folder.
    RoamMgrLRoamMgr.exeIntel PROset
    Rockwell Application Services (RsvcHost)LRsvcHost.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    Rockwell Directory Multiplexer (RNADirMultiplexor)LRNADirMultiplexor.exeRelated to Rockwell_Automation Inc. FactoryTalk suite

    Engine Version 2.0 by CastleCops

    spacer spacer