CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9466.22 of $21422.68
left sidedonated so farneed $11956.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 3876 entries and growing...
Last updated on 2008-05-09 18:10:24 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    systemXHacker.com.cn.exe Troj/GrayBrd-CJ Note: Located in %windir% Read the link, allows remote access
    System Account Center (SysAccCtr)Xsvcpost.exe W32/Oscabot-Q Read the link, allows remote access
    System Commander MBR check?WINMBR.EXE
    System Connect Util Service (FLUtilsSvc)LFLUtilsSvc.exeRelated to Fiberlink's Extend360 TM mobile Note: Located c:\Program Files\Fiberlink\Extend360\
    System Distribution Controller (distribcontrol)Xdisctrl.exeAdded by the W32/Rbot-GAM WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    System Driver Service (systemdriver)Xsysdriver.exeAdded by the W32/Tilebot-GA WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    System EventXSVCH0ST.exesvch0st.exe is a process which is registered as Trojan.Gamqowi This Trojan can allow attackers to access your computer by lowering Internet security settings, thus stealing passwords, Internet banking and personal data.
    System Event DispatcherXsgvrfy32.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Uses a random filename.
    System Event MessagingXsvchost.exeSeems to be viral
    System Event Notification ServiceXlsass.exeAdded by the Troj/Agent-AD TROJAN!
    System Event Service (SystemSet)Xservice.exeDetected by Antivir as TR/Delphi.Downloader.Gen
    System Guard(AdwareKiller)
    (AdwareKillerSysGuardService)
    XSysGuard.exe EAdwareKiller is a rogue antispyware utility that uses false positives to lure the user into buying the product. Note: Located in \%Program Files%\EAdwareKiller\
    System Internal AntiVirus (SVSAV)Xsvsnt.exeAdded by the Worm/Sdbot.40448.22 WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Read the link.
    System Manager Service (SMSC)Xsmsc.exeAdded by the W32/Sdbot-ADY WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    System Managment Controler (SMSCGISVC)Xsmscg.exeAdded by a variant of the Backdoor.Sdbot Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    System Messenger Service (WINSMSC)Xsmsc.exeAdded by the W32/Tilebot-F WORM! Read the link, rootkit type stealth involved.
    System Mld (MldServ)Lsysmlds.exeSee Here
    System Mng Srvc (SMSG)Xsmsg.exeAdded by the W32/Tilebot-AB TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    System OutXsystemout.exeTrojan-Spy.Win32.Delf.du
    System Process Monitor (sysprcm)Xmsnprcss.exeAdded by ServiceThreadHandler.Process TROJAN! Note: located in C:\WINDOWS\System32\
    System Profile Monitor (spm)Lspm.exeRelated to Northern_Michigan_University On-line services. Note: Located in \%ROOT%\
    System Restore ManagerXsymon.exeAdded by the W32/Tilebot-IP WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    System Restore Scheduling Service (srsvc)Xsrsvc.exe W32/Rbot-GHR
    System Restore ServicesXlsiss.exeAdded by the W32/Tilebot-HN WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) disabling the automatic startup of other software.
    System Scheduler (SysSch)Xsvchost.exe W32/DelCyc-A Note:Located in C:\Windows\Offline Web Pages (Win9x/Me), C:\%WINDIR%\Offline Web Pages (Vista/XP/WinNT/2K) Allows remote access
    System Server (System Server)Xsmss.exeAdded by the Troj/Feutel-T TROJAN! Note: This is not the legitimate Windows Process smss.exe. (Which is found in the System32 folder.) This worm/trojan file (smss.exe) is found in the Windows or Winnt folder.
    system server (system server)XMSpass.exeAdded by the Troj/Lineage-BG TROJAN! Note: This trojan file is found in the Windows\help or Winnt\help folder.
    System Service Monitor (servicemon)Xservicemon.exeAdded by the W32/Tilebot-GH WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    System Spooler HostXsyspool.exeAdded by the W32/Sdbot-COV WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache\ (Win9x/Me), C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    System Spooler HostXservices.exeAdded by the W32/Sdbot-COV WORM! Note: This worm\trojan is located in C:\Windows\cursors\mstask\ (Win9x/Me), C:\%WINDIR%\cursors\mstask\ (XP/WinNT/2K) Found also in C:\%WINDIR%\\Media\ringtones\ disabling the automatic startup of other software
    System Startup Service (SvcProc)Xsvcproc.exeIdentified as Trojan.Win32.Stervis.b and usually bundled with nail.exe, a Abetterinternet adware variant. Note: This trojan file is found in the Windows or Winnt folder.
    System Update (SUService)Lsuservice.exeRelated to Levolo System_update Thinkpad from IBM. More Note: Located in c:\program files\lenovo\system update\
    system32 (system32)Xsystem32.exeAdded by the Troj/GrayBird-U TROJAN! Note: This trojan file is found in the Windows or Winnt folder. Note: Also see Troj/Graybird-G
    system32 master (windowsys)Xwindowsys.comAdded by the W32/Sdbot-DIE WORM! Note: located in \%WINDIR%\ Read the link, allows remote access
    systemax32win32 (systemax32)Xsystemax32.exeAdded by a variant of the SDBot.aad family of worms and IRC backdoor Trojans.
    systemboot (systemboot)XSystem.exeAdded by the SDBOT.CDM WORM! Read the link, rootkit type stealth involved.
    SystemManagerXSYSMANAGER.EXEAdded by the SDBOT.CGG WORM! Read the link, rootkit type stealth involved.
    SystemRoot%system32SLsvc.exe,-101 (slsvc) LSLsvc.exe Part of Windows Vista. Note:Located in C:\%WINDIR%\System32
    Systems Management Data Manager (dcstor32)Ldcstor32.exeRelated to Dell Open Management system. http://www.what-process.com/process-info.aspx?p=dcstor32.exe
    Systems Management Event Manager (dcevt32)Ldcevt32.exeRelated to Dell Open Management system. http://www.what-process.com/process-info.aspx?p=dcevt32.exe
    SystemSuite Task ManagerLMXTask.exeRelated to Ontrack Inc.
    sytem32 (sytem32)Xsvost.exeAdded by the Troj/Feutel-Z TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    SzserviceXczsrv.exe W32/Sdbot-DHW Note:Located in C:\Windows\ (Win9x/Me), C:\%WINDIR%\ (Vista/XP/WinNT/2K)
    TabletServiceLTablet.exeRelated to Wacom Technology, Corp.
    TabletServicePenLPen_Tablet.exeRelated to Pen_Tablet from Wacom Tech. Interactive pen displays productivity tools that make using a computer as natural as possible. By using a pen directly on screen, you work more quickly and naturally. Note: Located in \%WINDIR%\System32\
    TabletServiceWacomLWacom_Tablet.exeRelated to Graphics_Tablet from Wacom Technology Co. Drivers. Note: Located in \%WINDIR%\System32\
    Talking Alarm Clock user logon monitorLAlarmMonitor.exeRelated to Cinnamon software inc. http://www.cinnamonsoftware.com/
    Tango Service (TangoService)LTangoService.exeRelated to Efficient Networks by Siemens
    TAO NT Naming Service (TAO_NT_Naming_Service)LNT_Naming_Service.exeRelated to SAP_Business_One gives you the information you need to select and implement business management software. Note: Located in \%Program Files%\SAP\SAP Business One ServerTools\License\
    TapeWareLTWWINSDR.EXERelated to Yosemite_Technologies TapeWare backup system.

    Engine Version 2.0 by CastleCops

    spacer spacer