CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9466.22 of $21422.68
left sidedonated so farneed $11956.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 3876 entries and growing...
Last updated on 2008-05-09 18:10:24 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    Rockwell Directory Server (RNADirectory)LRnaDirServer.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    Rockwell Event Multiplexer (EventClientMultiplexer)LEventClientMultiplexer.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    Rockwell HMI Activity LoggerLRsActivityLogServ.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    Rockwell HMI DiagnosticsLHMIDIAGNOSTICSLSTADAPT.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    Rockwell Tag ServerLTagSrv.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    rofl (rofl)Xrofl.sysAdded by the Troj/RKPort-Fam TROJAN! This is a rootkit!
    Roger Wilco Base StationLrwbs.exeRelated to IGN_Entertainment Inc. Required to operate the Wilco Base Station.
    Rogers Update Manager (RogersUpdateManager)LRogersUpdateManager.exeSearches for updates for the Rogers Yahoo!_Browser Note: Located in \%Program Files%\Rogers\Update Manager\
    RollbackClientServiceLRollbackClnt.exe Horizon DataSys Rollback Rx
    Routing Service (Routing)Xrouting.exeAdded by an unknown Trojan/Backdoor Note: Located in \%WINDIR%\System32\
    Roxio Hard Drive Watcher (RoxWatch)LRoxWatch.exeRelated to Roxio_Inc
    Roxio Hard Drive Watcher 10 (RoxWatch10)LRoxWatch10.exeRelated to Roxio_Inc Easy Media Creator 10. Note: Located in \%Program Files%\Common Files\Roxio Shared\10.0\SharedCOM\
    Roxio Hard Drive Watcher 9 (RoxWatch9)LRoxWatch9.exeRelated to Roxio_Inc
    Roxio UPnP Renderer 10LRoxioUPnPRenderer10.exeRelated to Roxio_Inc Easy Media Creator 10. Note: Located in \%Program Files%\Roxio\Digital Home 10\
    Roxio UPnP Renderer 9LRoxioUPnPRenderer9.exeRelated to Roxio_Inc
    Roxio Upnp Server 10LRoxioUpnpService10.exeRelated to Roxio_Inc Easy Media Creator 10. Note: Located in \%Program Files%\Roxio\Digital Home 10\
    Roxio Upnp Server 9LRoxioUpnpService9.exeRelated to Roxio_Inc
    RoxMediaDBLRoxMediaDB.exeRelated to Roxio_Inc
    RoxMediaDB10LRoxMediaDB10.exeRelated to Roxio_Inc Easy Media Creator 10. Note: Located in \%Program Files%\Common Files\Roxio Shared\10.0\SharedCOM\
    RoxMediaDB9LRoxMediaDB9.exeRelated to Roxio_Inc
    RoxUpnpRenderer (RoxUPnPRenderer)LRoxUpnpRenderer.exeRelated to Roxio_Inc
    RoxUpnpServerLRoxUpnpServer.exeRelated to Roxio_Inc
    RPAServiceLRPAService.exeRelated to Gilat Satellite Networks Ltd. Note: Located in \%Program Files%\GILAT\Internet Page Accelerator\
    RPC Debug Control (RPCDB)Xcsts.exeAdded by the Backdoor.Win32.SdBot.aad as identified by Kaspersky TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    RPC+ Service Provider (RPCSS+)Xrpcss_pl.exeTrojan. - http://www.what-process.com/process-info.aspx?p=rpcss_pl.exe
    RpcRemotesXremote.exeAdded by the W32/Fanbot-J WORM! Note: This worm file is found in the System32 folder. Be sure to check the link on this one. Copies it's self to various folders and file names.
    RSLinxLRSLINX.EXERelated to Rockwell_Automation Inc. FactoryTalk suite
    RSLinx Enterprise (RSLinxNG)LRSLinxNG.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    RtkitXRtkit.exeAdded by the Backdoor.Rtkit TROJAN! Read the link, rootkit type stealth involved.
    rtvscanXrtvscan.exeAdded by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\ This infection should not be confused with the legitimate Note: Note: Located in \%Program Files%\Symantec\SAV\Rtvscan.exe file.
    rudllXrudll.exe Troj/Hupigon-CF Note: Located in %windir% Read the link, allows remote access
    RUMBA AS/400 Shared Folders (Wdworkstation)Lwdnpsvc.exeRelated to RUMBA which provides connectivity from Microsoft Windows desktops to virtually any host system with mission critical reliability. From NetManage Inc. Note: Located in \%WINDIR%\System32\
    Run RunOnceLShipUPS.EXE, RunOnce.exeRelated to UPS WorldShip shipping software
    rundll.exeXmsn93.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    rundll.exeXmsngrsm.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    rundll.exeXrundll.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    rundll32 (rundll32)Xrundll32.exeAdded by the Troj/Feutel-Q TROJAN!
    rundll32.exeXlsass.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\
    RuntimeXruntime.sys Troj/Agent-ECZ Note: Located in %windir%\system32
    RuntimeXruntime.sys Troj/Pushu-Gen Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K) May also have an additional services installed. Read link
    runtime2Xruntim2.sys Troj/DropRk-A Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K)
    RupsdLRupsd.exeRelated to Mega_System Technologies Inc.
    RupsmonLRupsMon.exeRelated to Mega System Technologies, Inc.
    RVS CommCenter (RvsCC)LRVSCC.EXELegit Fax/Digital Answering Machine/Telephony service. Owner Unknown . Located in C:\Program Files\Teledat\WCOM\SYSTEM\
    RVS Installer (RVSINST)LRVSINST.EXELegit Fax/Digital Answering Machine/Telephony service. Owner: RVS Datentechnik GmbH, München. Located in: C:\Program Files\Teledat\WCOM\SYSTEM\
    Rwx (Rwx2005)Xsvhosts.exeAdded by the Troj/Subzero-B Trojan!
    r_serverXservice.exeAdded by the Troj/Remadm-G TROJAN! Note: This is not the legitimate Windows process services.exe (Notice the difference in the spelling.) This trojan file (service.exe) is also found in the System32 folder.
    S3 Graphics Co., Ltd.XVTTrayp.exe W32/Sdbot-DHA Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR% (Vista/XP/WinNT/2K)
    s3contrl (32-bit)XVTTray.exeAdded by a variant of the Backdoor.Win32.SdBot.cep family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\
    SafeBoot Configuration Manager
    (SafeBootConfigurationManager)
    LSBMGRNT.EXERelated to SafeBoot_Configuration Manager. Encryption software. Note: Located in \%Program Files%\SafeBoot\

    Engine Version 2.0 by CastleCops

    spacer spacer