| Name | Status | Filename | Description |
| a-squared Anti-Dialer Service (a2AntiDialer) | L | a2service.exe | Related to Related to a-squared Virus protection software. Note: Located in \%Program Files%\a-squared Anti-Dialer\ |
Belgium Identity Card Service (BELGIUM_ID_CARD_SERVICE) | L | Belpic PCSC Service.exe | Belgium Identity Card Middleware from Zetes/CSC |
| Dell Printer Status Database (DLSDB) | L | DLSDBNT.EXE | Related to Dell_Printers Note: Located in C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\ |
| license | L | lic_srv.exe | license |
| LXCCCustomerConnect | L | LXCCserv.exe | Related to Lexmark printers Note: Located in %windir%\System32\spool\DRIVERS\W32X86\3\\LXCCserv.exe |
| Network Windows Service (MSWindows) | X | urdvxc.exe | Added by the W32/Allaple-B WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| pcAnywhere Install Service - Symantec Corporation | L | pca_run.exe | Part of Symantec PCAnywhere |
| Remote Debug Services | X | smsc.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Shell Software Detection (ShellSWDetection) | X | shellsw.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| SolidWorks Licensing Service | L | SolidWorksLicensing.exe | Part of a SolidWorks product |
| Windows Zero Connection (WinZConn) | ? | mswnt.exe | Probable backdoor trojan |
| Wireless Adapter Configurator | L | WirelessDaemon.exe | Related to BT's home hub products |
##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) | L | mDNSResponder.exe | mdnsresponder.exe is a process associated with "Bonjour for Windows" software. It is used by ITunes for music sharing. Note: Located in \%Program Files%\Bonjour\ |
| $sys$aries | X | aries.sys | Added by the SonyBMG_First4DRM
ROOTKIT!
Read the link, rootkit type stealth involved. Thanks Sony. |
| (4 random characters).sys | X | windev(4 random characters).sys | Troj/Dorf-K |
| (Any service name) | O | srvany.exe | This utility allows running Windows NT\2000\XP applications as services.
Can also be used to load Malware. See Explanation
...
Example of how to find the file being loaded with Service name iOpusService
|
| (non-roman characters) | X | sServer.exe | Added by the Troj/Feutel-AB
TROJAN!
Note: This trojan file is found in the Windows or Winnt folder.
|
| (random file name without extension) | X | (random file name).sys | Added by the TROJ_ROOTKIT.AI
TROJAN!
Read the link, rootkit type stealth involved.
|
| (Random Letters) | X | (Random FileName).dll | Troj/Conhook-AG
Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
Installs multiple services. Read link |
| (random name) | X | window.exe | Troj/Hupigon-BS Note: Located in %windir% Read the link, steals information and allows remote access |
| (Random name) | X | avpo.exe | W32/SillyFDC-BA
Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K) |
| (Random) *See description* | X | irjit.dll | Added by the Backdoor.CVM
TROJAN! Note: This trojan file is found in the System or System32 folder. *Check the link for the list of random service names.* |
| (special characters) (myserver) | X | myserver.exe | Added by the Troj/Dropper-BR
TROJAN!
|
| *Microsoft Update | X | wstcl.exe | No from Microsoft. |
| *Microsoft Update | X | wuytc.exe | unknown virus |
| *windows update | X | wsctl.exe | malware virus. possibly "Win32.Rbot.gen" |
| *windows update | X | wuaucrlt.exe | Added by the W32.Spybot.HUR WORM! |
| *wuauclt.exe | X | random | Related to WORM_RBOT.AKU or variant. |
| .CPROGRA (SAP DBTech-.CPROGRA) | L | kernel.exe | Related to SAP_MaxDB The SAP Database System. Note: Located in \%Program Files%\SAPDB\DEPEND\pgm\ |
| .NET Framework Service | X | svchost.exe | "Trojan-PSW.Win32.Sagic.15" Virus |
| .NET Framework Service (.NET Connection Service) | X | svchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ Note The proper location for that operating file is in C:\%WINDIR%\System32 |
.NET Runtime Optimization Service v2.0.50215_X86 (clr_optimization_v2.0.50215_32) | L | mscorsvw.exe | Related to Microsoft_NET_Framework NET Runtime Optimization Service. |
| .NETSecurity | X | netsecurity.exe | Added by a variant of the Rootkit.Haxdoor Note: Located in \%WINDIR%\System32\ |
| 01Apache | L | Apache.exe | Related to Apache web server Note: Located in \%Program Files%\01COM~1\WEBSER~1\ |
| 1784-PCIDS DeviceNet | ? | PcidsService.exe | Appears to be from Rockwell software |
| 1789-SIM Simulator Module (SimModuleService) | ? | SimModuleService.exe | Appears to be from Rockwell software |
| 19E7E238 | X | 19E7E238.EXE | Troj/Agent-ELX |
| 1Google Online Search Service | X | winlugan.exe | Identified as a variant of the Trojan-Downloader.Win32.Winlagons.ak malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| 1Google Online Search Service | X | winlegal.exe | Identified as a variant of the Trojan-Downloader.Win32.Winlagons.an malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| 2D98923D | X | E69C6CEE.exe | Troj/Agent-FYY
Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
Allows others to access the computer |
| 32-bit Installation Host (inst32) | X | inst32.exe | Added by the W32/Chinegan-A WORM! Note: This worm is located in C:\Program Files\Common Files\inst32\ |
| 32-bit Registration Host (reghost32) | X | reghost32.exe | Added by the W32/Rbot-GKR WORM! Note: This worm is located in C:\Program Files\Common Files\System\ |
| 39672EA4 | X | 39672EA4.EXE | Troj/GrayBir-EW |
| 3Com DMI Agent | L | 3CDMINIC.EXE | 3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards |
| 3ComBOOTP | L | 3CBOOTPS.EXE | A 3Com Product
Allows network administrators to remotely manage client PCs on their network by allowing them to deploy an array of desktop management tasks in a pre-OS booting environment.
Note: Located in Drive:\Program Files\3Com\Boot Services |
| 3ComPXE | L | 3CPXES.EXE | A 3Com Product
Allows network administrators to remotely manage client PCs on their network by allowing them to deploy an array of desktop management tasks in a pre-OS booting environment.
Note: Located in Drive:\Program Files\3Com\Boot Services
|
| 3ComTFTP | L | 3CTFTPS.EXE | A 3Com Product
Allows network administrators to remotely manage client PCs on their network by allowing them to deploy an array of desktop management tasks in a pre-OS booting environment.
Note: Located in Drive:\Program Files\3Com\Boot Services
|
| 3dkeybd | O | 3dkeybd.exe | Unknown... No answers on the net. |
| 3DM | L | 3dmd.exe | Related to 3ware SATA RAID controler. Note: Located in \%Program Files%\3ware\3DM\ |
| 55euf6 | X | 55euf6.sys | Troj/DwnLdr-GWX
Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K)
May install another service a6fyts35 |
| 64Bit architecture emulation (wrmsrvice) | X | WRMSRVICE.SYS | Added by the TROJ_ROOTKIT.AG
TROJAN!
Read the link, rootkit type stealth involved.
|
| 79F5137E | X | DBB6ED81.EXE | W32/SlliyFD-G
Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
Allows others to access the computer |
| 80xFire daemon (80xFire) | X | 80xFire.exe | Added by the W32/Tilebot-BK
WORM!
Note: This worm\trojan file is found in the Windows or Winnt folder.
Read the link, rootkit type stealth involved. |
| 9F9DF57C | X | (random name) | Troj/DwnLdr-GUT |
@%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) | L | wmpnetwk.exe | Related to Windows_Media_Player Network Sharing Service. Note: Located in %ProgramFiles%\Windows Media Player\ |
| @%SystemRoot%system32snmptrap.exe,-3 (SNMPTRAP) | L | snmptrap.exe | Related to MKS_Toolkit In Windows Vista. Note:Located in C:\%WINDIR%\System32 |
| @%SystemRoot%ehomeehstart.dll,-101 (ehstart) | L | svchost.exe | Windows Media Center Service Launcher in the Windows Vista edition |
| @%SystemRoot%system32Alg.exe,-112 (ALG) | L | alg.exe | Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Internet Connection Firewall Note:Located in C:\%WINDIR%\System32 (Vista 64bit) |
| @%systemroot%system32Locator.exe,-2 (RpcLocator) | L | locator.exe | Part of Windows Vista. Note:Located in C:\%WINDIR%\System32 |
| @%SystemRoot%System32netlogon.dll,-102 (Netlogon) | L | lsass.exe | Related to NetLogOn Check the validity of the Passwords on a Vista 64 bit. Note: Located in \%WINDIR%\System32\ |
@%systemroot%system32psbase.dll,-300 (ProtectedStorage) | L | lsass.exe | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| @%SystemRoot%system32qwave.dll,-1 (QWAVE) | L | svchost.exe | Part of Windows Vista. Note:Located in C:\%WINDIR%\System32 |
| @%SystemRoot%system32samsrv.dll,-1 (SamSs) | L | lsass.exe | Part of Windows Vista. Note:Located in C:\%WINDIR%\System32 |
| @%SystemRoot%system32seclogon.dll,-7001 (seclogon) | L | svchost.exe | Part of Windows Vista |
@%Systemroot%system32wbemwmiapsrv.exe,-110 (wmiApSrv) | L | WmiApSrv.exe | Related to Vista 64 bit computer. |
| @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) | L | svchost.exe | Part of Windows Vista |
| @%systemroot%\system32\spoolsv.exe,-1 (Spooler) | L | spoolsv.exe | part of Windows Vista used for Fax and Printing. Note:Located in C:\%WINDIR%\System32 |
| @%SystemRoot%\system32\vds.exe,-100 (vds) | L | vds.exe | Part of Windows Vista Note:Located in C:\%WINDIR%\System32 |
| @%systemroot%\system32\vssvc.exe,-102 (VSS) | L | vssvc.exe | Part of Windows Vista Note:Located in C:\%WINDIR%\System32 |
| @comres.dll,-2797 (MSDTC) | L | msdtc.exe | Part of Windows Vista. Note:Located in C:\%WINDIR%\System32 (Vista/XP/WinNT/2K) |
| @dfsrres.dll,-101 (DFSR) | L | DFSR.exe | Part of Windows Vista 64Bit. Note:Located in C:\%WINDIR%\System32 |
| @keyiso.dll,-100 (KeyIso) | L | lsass.exe | Related to CNG_Key_Isolation_Service Found on Vista 64 bit. |
| a-squared Anti-Malware Service (a2AntiMalware) | L | a2service.exe | Related to Related to a-squared Virus protection Software. Note: Located in \%Program Files%\a-squared Anti-Malware\ |
| a-squared Free Service (a2free) | L | a2service.exe | Related to a-squared free edition, from Emsi Software GmbH |
| a6fyts35 | X | a6fyts35.sys | Troj/DwnLdr-GWX
Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K)
May install another service 55euf6 |
| aaksrv | L | aaksrv.exe | Spydex Advanced Anti keylogger |
| AAMQDispatcher | L | AAMQDispatcherService.exe | Compuware Serversoftware |
ABBYY FineReader 9.0 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) | L | NetworkLicenseServer.exe | Related to ABBYY_FineReader from ABBYY accurate conversion of images into text or searchable PDF for the purpose of categorizing, archiving, searching or integrating with third party content management systems. Note: Located in \%Program Files%\\Common Files\ABBYY\FineReader\9.00\Licensing\PE\ |
| ABCSpell Helper Service | L | ABCSpellService.exe | Spell checker (Ect, ect) for Outlook Express. For more information Click_Here
|
| Abel | X | Abel.exe | Source: http://www.pestpatrol.com/PestInfo/C/Cain.asp |
| abhcop | X | abhcop.sys | Added by the PigSearch
Adware.
Read the link, rootkit type stealth involved. |
| AC | X | acoustic.exe | Added by the SDBOT.CRN
WORM!
Read the link, rootkit type stealth involved.
|
| Ac Profile Manager Service (AcPrfMgrSvc) | L | AcPrfMgrSvc.exe | Related to the Ac_Profile_Manager_Service installed as a part of ThinkPad Access Connections suite on ThinkPad laptops. Note: Located in C:\Program Files\ThinkPad\ConnectUtilities\ |
| AC-DNAME (AC-DNAME) | X | acoustic.exe | Added by the SDBOT.CFN
WORM!
Read the link, rootkit type stealth involved.
|
| Accenture Media Viewer (MediaViewer) | L | streamviewerservice.exe | Related to Accenture_Media_Viewer |
| Access Connections Main Service (AcSvc) | L | AcSvc.exe | Related to Lenovo ThinkVantage Access Connections Main Service Module. Note: Located in \%Program Files%\ThinkPad\ConnectUtilities\ |
| Access Utility Service | L | SMBAUtilSvc.exe | Related to Sprint_Mobile_Broadband |
| Acer Media Server | L | MediaServerService.exe | Related to Acer_Media_Server Empowering Technology. Note: Located in \%Program Files%\Acer\Acer eConsole\ |
| ACMService (ACMService) | L | | Added by the ACM SPYWARE! **Note this is a commercial computer monitoring software |
| ACNUSvc | L | acnupdatersvc.exe | Related to Accenture global management consulting, technology services and outsourcing company Note: Located in c:\program files\acnu\ |
| acpidisk | X | acpidisk.sys | Troj/Agent-FXI
Note: Located in %System%\drivers
|
Acronis Backup Server Service (AcronisBackupServerService) | L | backupserver.exe | Related to Acronis_Backup Backup server from Acronis. Note: Located in \%Program Files%\Acronis\BackupServer\ |
| Acronis Group Server (GroupServer) | L | GroupServer.exe | Related to Acronis_Backup Group server from Acronis. Note: Located in \%Program Files%\Acronis\GroupServer\ |
Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) | L | oss_reinstall_svc.exe | Related to Acronis_Disk_Director suite. A disk management functions, partition recovery tool, and boot disk manager. Note: Located in \%Program Files%\Acronis\Acronis Disk Director\ |
| Acronis Scheduler2 Service (AcrSch2Svc) | L | schedul2.exe | Related to Acronis_True_Image creates the exact copy of your hard disk and allows you to instantly restore the entire machine including operating system. Note: Located in C:\Program Files\Common Files\Acronis\Schedule2\ |
| Acronis Scheduler_Helper | X | schedhlp.exe | Added by a variant of the Backdoor.Sdbot Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Acronis Try And Decide Service (TryAndDecideService) | L | TrueImageTryStartService.exe | Related to True_Image Powerful Backup utility. Note: Located in \%Program Files%\Common Files\Acronis\Fomatik\ |
| acrotray (Acrotray) | O | srvany.exe | Microsoft Windows application which allows an executable to be run as a service. If you have installed this service, fine, otherwise investigage. Can be used to load Malware. |
| ActionAgent | L | ActionAgent.exe | Related to ActionAgent, from Dell Computer. "A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation package; provides a simple method for a remote administrator to perform actions on the instrumented client". Note: Located in \%Program Files%\Dell\OpenManage\Client\ |
| ActivCard Authentication Service (ACachSrv) | L | acachsrv.exe | Related to ActivCard Gold Component of ActivCard Gold from ActivIdentity, Inc. Smart cards that function as photo ID, proximity badges for facility access and as digital identification and authentication devices. Note: Located in \%Program Files%\Common Files\ActivCard\ |
| ActivCard Gold Autoregister (acautoreg) | L | acautoreg.exe | Related to ActivCard Gold Component of ActivCard Gold from ActivIdentity, Inc. Smart cards that function as photo ID, proximity badges for facility access and as digital identification and authentication devices. Note: Located in \%Program Files%\Common Files\ActivCard\ |
| ActivCard Gold service (Accoca) | L | accoca.exe | Related to ActivCard Gold Component of ActivCard Gold from ActivIdentity, Inc. Smart cards that function as photo ID, proximity badges for facility access and as digital identification and authentication devices. Note: Located in \%Program Files%\Common Files\ActivCard\ |
| Active Virus Shield (AVP) | L | avp.exe | Related to Active_Virus_Shield from AOL. Note: Located in C:\Program Files\AOL\Active Virus Shield\ |
| activePDF Server (A4ACTIVEPDFSERVER) | L | APSERVER.EXE | Related to active_PDF Server from activePDF, Inc. Provides integrated PDF generation and dynamic PDF conversion. Note: Located in \%WINDIR%\System32\ |
| ActiveSMART Service | L | ASmartService.exe | Related to Active_SMART from Ariolic.com utilizes the S.M.A.R.T. technology to track the status of the computer hard disks. Note: Located in \%Program Files%\Active SMART\ |
| ActiveSMART Service (aomaukbamapi) | X | umlt.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| ActiveXperts Network Monitor (AxsNmSvc) | L | AxsNmSvc.exe | Added by ActiveXperts_Network_Monitor allows administrators to monitor the network for failures and irregularities. Note: Located in C:\Program Files\ActiveXperts\ |
Actuate Process Management Daemon 8 (__AC_PROCESS_MGMT_DAEMON8) | L | pmd8.exe | Actuate_Enterprise Reporting Applications for business intelligence analytic services |
| ACU Configuration Service (ACS) | L | acs.exe | Wireless-USB utility More here |
| Ad-Aware 2007 Service (aawservice) | L | aawservice.exe | Related to Ad-Aware_2007 anti-spyware solution. This program can find and remove spyware and malware from your computer. Note: Located in C:\Program Files\Lavasoft\ |
| Ad-Axis Client | L | aaclient.exe | Related to Lavasof's Ad-Aware SE Enterprise Edition 2005 |
| Adaptador de rendimiento de WMI (WmiApSrv) | L | wmiapsrv.exe | Windows Management Instrumentation Performance Adapter Service Windows XP and 2003. Note: Located in C:\WINDOWS\System32\wbem\wmiapsrv.exe |
| Adaptec I/O Manager Server | L | iomgr.exe | Related to Adaptec product |
| Adaptec RAID Remote Services Agent | L | afaagent.exe | Related to Adaptec, Inc. |
| Adaptec Storage Manager Notifier | L | notify.exe | Related to Adaptec procuct |
| Adaptec Web Server | L | arcpd.exe | Related to Adaptec procuct. |
| AdaptecStorageManagerAgent | L | StorServ.exe | Related to Adaptec Incorporated |
| Adapter Switching (IntelRoam) | L | RoamSvc.exe | Intel Adapter Switching |
| Adaptive Server Anywhere | L | dbsrv7.exe | Related to Sybase_Adaptive_Server Anywhere Network Server. Note: Located in \%ROOT%\sqla7\win32\ |
| AddFiltr | L | AddFiltr.exe | Found on HP computers |
| ADF Installer Service (ADF Installer) | L | AgentSVC.exe | Related to Citrix Installation Manager Service |
| Admin Works Agent X8 (AWService) | L | awServ.exe | Related to AdminWorks from Avocent Corporation. A cost effective IT management software tool for small and medium size businesses. Note: Located in C:\Program Files\Intel\IDU\ |
| Administracióe aplicaciones | L | services.exe | Spanish Windows 2000 applications managing |
| Administrador de cuentas de seguridad | L | lsass.exe | Spanish Windows 2000 security accounts manager |
| Administrador de discos | L | services.exe | Spanish Windows 2000 disks manager |
| Administrador de sesióe Ayuda de escritorio remoto | L | sessmgr.exe | This service manages and controls Remote Assistance |
Administrador de sesión de Ayuda de escritorio remoto (RDSessMgr) | L | sessmgr.exe | Related to Microsoft's remote assistance windows plugin. This allows an end user to call for assistance when a remote assistance network service is in place. This process shouldn't be terminated if the fore-mentioned service is in place on your local area network.
|
| Administrador de utilidades | L | UtilMan.exe | Spanish Windows 2000 utility manager |
| AdminWorks Agent X6 (AWService) | L | admServ.exe | Related to Avocent, http://www.embedded.avocent.com/ Embedded Software and Solutions Division. Note: Located in %ROOT%:\Acer\Empowering Technology\ |
| Adobe Active File Monitor (AdobeActiveFileMonitor) | L | PhotoshopElementsFileAgent.exe | Related to Adobe Photoshop Elements. A popular graphics rendering tool. Note: Located in \%Program Files%\Adobe\Photoshop Elements 3.0\ |
Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) | L | PhotoshopElementsFileAgent.exe | Related to Adobe Photoshop Elements. A popular graphics rendering tool. Note: Located in \%Program Files%\Adobe\Photoshop Elements 5.0\ |
| Adobe LM Service | L | Adobelmsvc.exe | Required for PhotoshopCS |
| Adobe Plugins Reader | X | svshost.exe | Added by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\ |
| Adobe Update Manager (Adobe3M) | X | mshss.exe | Added by the Troj/Wollf-B
TROJAN!
Note: This worm\trojan file is found in the System32 folder. |
| Adobe Version Cue CS2 | L | VersionCueCS2.exe | Related to Adobe Products |
| Adobe Version Cue CS3 | L | VersionCueCS3.exe | Related to Adobe_Version_Cue CS3. Note: Located in \%Program Files%\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\ |
| AdobeVersionCue | L | VersionCue.exe | Adobe related |
| ADSM Service (ADSMService) | L | ADSMSrv.exe | Related to ASUS_Data_Security_Manager on ASUSTeK Computer. Note: Located in \%Program Files%\ASUS\ASUS Data Security Manager\ |
| ADSService | L | ADSSER~1.EXE | Related to Aluria_Active_Defense_Shield Service. An EarthLink Co. Note: Located in C:\Program Files\EarthLink\Protection Control Center\ |
| Advanced Networking Service (audieqaao) | X | lmguv.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| Advanced Networking Service (hnmsvc) | L | hnm_svc.exe | Related to Advanced_Networking_Service from Dell. Note: Located in %\Program Files%\Dell Network Assistant\ |
| Advantage Database Server (Advantage) | L | ADS.EXE | Related to Extended Systems' Advantage_Database_Server |
| AEClientHostService | L | AEClientHostService.exe | Related to GE_Fanuc_Automation enable you to act in real-time to optimize productivity and increase profitability. Note: located in C:\Program Files\GE Fanuc\Alarm Viewer\Host\ |
| Aelita DMW Migration Agent | L | Vmover.exe | Related to Quest_Domain Migration Wizard Note: Located in C:\%WINDIR%\System32\ |
| AEServ | L | AEServEx.exe | Related to Anti-Executable from Faronics Corporation. Provides total system control, restricting the user's ability to run or install any new executable program. Note: Located in \%WINDIR%\System32\ |
| AFinding Service (AFinding) | X | afinding.exe | AFinding.Process |
| Age of Empires III: The WarChiefs | X | ageofempires.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\dllcache\ (Win9x/Me), C:\%WINDIR%\dllcache\ (XP/WinNT/2K) |
| Agente de directivas IPSEC | L | lsass.exe | Spanish Windows 2000 IPSEC policy agent |
| Agere Modem Call Progress Audio (AgereModemAudio) | L | agrsmsvc.exe | Related to Agere_Modem Call Progress Audio. (Now owned by LSI Corp.) Note: Located in C:\Windows\system32\ |
| Agere Service (AgrSrvce) | L | AgrSrvce.exe | Related to Proxim_Corp Client manager software associated with the ORiNOCO wireless LAN card. |
| AhnLab Task Scheduler | L | Ahnsdsv.exe | Related to AhnLab Task Scheduler from AhnLab, Inc. Note: Located in \%Program Files%\AhnLab\Smart Update Utility\ |
| AIM (AIM) | X | aim.exe | Added by the W32/Rbot-AGC
or W32/Sdbot-BFX
WORM!
Read the link, rootkit type stealth involved.
|
| Aim Version 6 (Aimv6) | X | aim6.exe | Identified as the Rbot.cgu infection. This infection is part of the family of worms and IRC backdoors. Note: This worm is located in C:\WINDOWS\Cursors\ |
| aim.ex | X | IEXPLORER.EXE | Added by the SDBOT.COW
WORM!
Read the link, rootkit type stealth involved.
|
| Airgo Networks NIC Service (ANISERVICE) | L | aniServ.exe | Related to Airgo_Networks NIC Service Note: Located in \%WINDIR%\System32\ |
| ALaunch Service (ALaunchService) | L | ALaunchSvc.exe | Found on Acer laptops. Note: Located in \%ROOT%\Acer\ALaunch\ |
| Alerter | L | svchost.exe | Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start. |
| AlfaCleanerService | X | ACServer.exe | AlfaCleaner is now a stealth install using exploits on unpatched systems. Seen alongside RazeSpyware. This program tends to be installed with other known Smitfraud infections. |
| ALGE | X | Hacker.com.cn.exe | Troj/GrayBr-CP Read the link, allows remote access |
| algs | X | algs.exe | Added by the W32.Linkbot.M Note: Located in \%WINDIR%\System32\ |
| Almacenamiento protegido | L | services.exe | Spanish Windows 2000 protected storage |
| Altera JTAG Server (JTAGServer) | L | JTAGServer.exe | Related to Altera Quartus II Software. Note: Located in C:\altera\quartus50\bin\ |
| Alternative User Input Services (Ctfmon) | X | ctfmon.exe | Added by the W32/Tilebot-JR WORM! Note: This worm is located in C:\%WINDIR%\ Note This is not the cftmon.exe normally found in C:\WINDOWS\System32\ |
| Altiris Agent (AeXNSClient) | L | AeXNSAgent.exe | Related to Alteris services. http://www.altiris.com |
| Altiris Carbon Copy (CarbonCopy32) | L | ccsrvc.exe | Related to Alteris services. http://www.altiris.com |
| Altiris Client Service (AClient) | L | ACLIENT.exe | Related to Altiris, Inc. |
| Altiris eXpress NS Client (AeXNSClient) | L | AeXNSClient.exe | Related to Altiris_eXpress NS Database and SVS (Software Virtualization Services). |
Altiris eXpress NS Client Transport (AeXNSClientTransport) | L | AeXNSClientTransport.exe | Related to Altiris_eXpress NS Database and SVS (Software Virtualization Services). |
| Aluria Message Service (MsgSrvService) | L | AluriaMsgSrv.exe | Aluria security center |
Aluria Security Center Spyware Eliminator Service (ASCService) | X | ascserv.exe | Aluria Spyware Eliminator "Spyware remover" a rogue program of dubious repute - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for "Alura" |
| Aluria Spyware Eliminator Service | O | ASEServ.exe | Aluria Spyware Eliminator |
| AL_ADSService | X | AL_ADSService.exe | Aluria Spyware Eliminator "Spyware remover" a rogue program of dubious repute - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for "Alura" |
| Amadeus Automatic Update | L | AutoUpdate.exe | Related to Amadeus powerful front office travel management tool. Note: Located in C:\Program Files\Automatic Update\ |
| Amazon Unbox Video Service (ADVService) | L | ADVWindowsClientService.exe | Related to Amazon_Unbox_Video_Service Note: Located in \%Program Files%\Amazon\Amazon Unbox Video\ |
| Amazon Unbox Video Service (ia8yaepyjabon) | X | vwevpugztu.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| AMD PowerNow! . Technology Service (GemServ) | L | GemServ.exe | Related to Advanced Micro Devices, Inc. - http://www.amd.com/ |
| Ampi32 (wdfmgr) | X | msvcrt.exe | Added by the W32/Tilebot-Q
WORM!
Note: This worm file is found in the Windows or Winnt folder.
Read the link, rootkit type stealth involved.
|
| Analysis Server (MSSQLSERVER) (MSSQLServerOLAPService) | L | msmdsrv.exe | Related to Microsoft_SQL_server
suite.
|
| Andrea ADI Filters Service (AEADIFilters) | L | AEADISRV.EXE | Related to Andrea_ADI Filters Service from Andrea Electronics Corp. Note: Located in \%WINDIR%\system32\ |
| Andrea RT Filters Service (AERTFilters) | L | AERTSrv.exe | Related to Andrea_RT_Filters Service from Andrea Electronics Corp. Active Noise Cancellation Microphone Headsets. Note: Located in \%WINDIR%\System32\ |
| Andrea ST Filters Service (AESTFilters) | L | aestsrv.exe | Related to ST_Filters from Andrea Electronics Corp. Note: located in \%WINDIR%\system32\ |
| ANIWZCSd Service (ANIWZCSdService) | L | ANIWZCSdS.exe | Related to Alpha_Networks |
| Ansys JobManager Service V11 (JobManagerService110) | L | JobManagerService.exe | Related to Ansys_JobManager from ANSYS, Inc. Note: Located in \%Program Files%\ANSYS Inc\v110\RSM\bin\ |
| Ansys ScriptHost Service V11 (ScriptHostService110) | L | ScriptHostService.exe | Related to Ansys_ScriptHost from ANSYS, Inc. Note: Located in \%Program Files%\ANSYS Inc\v110\RSM\bin\ |
| AntiSpyUltra (Zonelaps) | X | vsmom.exe | Added by the W32/Tilebot-E
WORM!
Read the link, rootkit type stealth involved.
|
| AntiSpyware Scanning Engine (AntiSpywareSrv) | X | AntiSpyware.srv.exe | AntiSpywareApp - a Rogue Security Program |
| AntiVir PersonalEdition Classic Guard (AntiVirService) | L | avguard.exe | Part of Antivir |
AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) | L | sched.exe | Related to AntiVir Premium Security Suite for the internet. Note: Located in \%Program Files%\AntiVir PersonalEdition Classic\ |
AntiVir PersonalEdition Classic Service (AntiVirService) | L | avguard.exe | AntiVir antivirus |
| AntiVir Scheduler (AntiVirScheduler) | L | sched.exe | Related to AntiVir antivirus program. |
| AntiVir Service | L | AVGUARD.EXE | AntiVir antivirus |
| AntiVir Update | L | AVWUPSRV.EXE | AntiVir Antivirus |
| antivirus32 | X | antivirus32.exe | Added by an unidentified TROJAN! Note: of the Win32/Rbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. |
| antivirusdll | X | winmsgslive.exe | Added by the W32/Sdbot-CXQ WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. Modifies some FTP files, read the link |
| ANTS Profiler service | L | RedGate.Profiler.Service.exe | Related to Red Gate Software Ltd |
| AnyClick Service (AnySVC) | L | AnySVC.exe | Related to Network_Access_Control from UNETsystem Co. Program that controls the internal clients’ access to networks through high-level authentication and policy enforcement in order to prevent the spread of viruses and worms. Note: Located in \%Program Files%\Unetsystem\AnyClick\ |
| AnyPoint Service - Intel Corporation | L | APSERVER.EXE | Belongs to Intel_Anypoint home networking system |
| AnySens | L | AnySens.exe | Related to Network_Access_Control from UNETsystem Co. Program that controls the internal clients’ access to networks through high-level authentication and policy enforcement in order to prevent the spread of viruses and worms. Note: Located in \%Program Files%\Unetsystem\AnyClick\ |
| AOL Anti-Spyware Service (AOL-AntiSpySvc) | X | aolspy.exe | Added by a variant of the Backdoor.Win32.Rbot.cgu TROJAN! Note: This worm\trojan is located in C:\WINDOWS\pchealth\ |
| AOL Anti-Spyware Service (AOL-AntiSpy_Serv) | X | aolspy.exe | Added by a variant of the Backdoor.Win32.Rbot.cgu TROJAN! Note: This worm\trojan is located in C:\WINDOWS\repair\ |
| AOL Anti-Spyware Service (AOLSpyWareRem) | X | aolspy.exe | Added by a variant of the Backdoor.Win32.Rbot.cgu TROJAN!
Note: This worm\trojan is located in C:\WINDOWS\Debug\ |
| AOL Antivirus Update Service (aolavupd) | L | aolavupd.exe | Related to AOL Antivirus Update Service. |
| AOL Configuration Utility (AOL_CONF) | X | aolconf.exe | Added by a variant of the Backdoor.Win32.SdBot.aad family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\Media\ |
| AOL Connectivity Service (AOL ACS) | L | AOLAcsd.exe | Owner: America Online. Description: AOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online.
Also shown as AOL Connectivity Service (AOL ACS). |
| AOL Connectivity Service (AOL ACS) | L | acsd.exe | AOL related |
| AOL Debug Service (SVC_Debug) | X | aoldebugs.exe | Added by a variant of the Backdoor.Win32.Rbot.cgu TROJAN!
Note: This worm\trojan is located in C:\WINDOWS\Cursors\ |
| AOL Hosting Service (AOL_Hosting) | X | aolhost.exe | Added by a variant of the SdBot.aad family of worms and IRC backdoor Trojans. Note: This trojan is located in C:\WINDOWS\AppPatch\ |
| AOL Smart Update Service (AOL-Updatr) | X | aolupd.exe | Variant of Rbot.cgu |
| aol software (Aol Software) | X | smss.exe | Added by the W32/Tilebot-FM
WORM! Note: This is not the legitimate Windows process (Which is always found in the System32 folder). This worm file is found in the Windows or Winnt folder. Allows a remote intruder to gain access and control over the computer, read the link.
|
| AOL Spy Watch (AOL-SPY_Watch) | X | aolsw.exe | Added by a variant of the Backdoor.Win32.SdBot.aad family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\Media\ |
| AOL Spyware Protection Service (AOLService) | L | aolserv.exe | Related to AOL |
| AOL Spyware Removal Agent (AOL-Spy_Ware) | X | aolspysw.exe | Added by a variant of the SdBot.aad family of worms and IRC backdoor Trojans. Note: This trojan is located in C:\WINDOWS\Web\ |
| AOL TopSpeed Monitor (AOL TopSpeedMonitor) | L | aoltsmon.exe | AOL Topspeed |
| Apache | L | Apache.exe | Apache Web Server Software |
| Apache Tomcat (Tomcat6) | L | tomcat6.exe | Related to Apache_tomcat |
| Apache Tomcat SQSService (SQSService) | L | tomcat5.exe | Related to Apache_Tomcat Note: Located in \%ROOT%\USER\Programs\tomcat\bin\ |
| Apache2 | L | Apache.exe | Apache Web Server |
| Apache2Triad Apache2 Service (Apache2) | L | httpd.exe | Related to Apache2Triad Software. An Open source database. Note: Located in \%ROOT%\apache2triad\\bin\ |
| Apache2Triad Apache2 Service with SSL (Apache2SSL) | L | httpd.exe | Related to Apache2Triad Software. An Open source database. Note: Located in \%ROOT%\apache2triad\bin\ |
| Apache2Triad MySql Service (MySql) | L | mysqld.exe | Related to Apache2Triad Software. An Open source database. Note: Located in \%ROOT%\apache2triad\mysql\bin\ |
| Apache2Triad PostgreSQL Service (PgSql) | L | pg_ctl.exe | Related to Apache2Triad Software. An Open source database. Note: Located in \%ROOT%\apache2triad\pgsql\bin\ |
| Apache2Triad SlimFTPd Server (SlimFTPd) | L | SlimFTPd.exe | Related to Apache2Triad Software. An Open source database. Note: Located in \%ROOT%\apache2triad\ftp\ |
| Apache2Triad Xmail Service (XMail) | L | XMail.exe | Related to Apache2Triad Software. An Open source database. Note: Located in \%ROOT%\apache2triad\mail\bin\ |
| APACS+ NIM32 (NIM32) | L | Nim32.exe | Related to Siemens Energy & Automation Platform. Note: located in C:\Program Files\ProcessSuite\NIM\ |
| APC PBE Server | L | pbeserver.exe | APC PowerChute Business Edition Server (For UPS) |
| APC UPS Service | L | mainserv.exe | Related to American Power Conversion Corporation |
| AppExpress Client | L | ece.exe | Related to Endeavros Technology, Inc and Microsoft_Encarta
|
| Apple Mobile Device | L | AppleMobileDeviceService.exe | Added by iTunes 7.3 to interface with Apple mobile devices. Allows iTunes to interact with iPhone when connected to the computer. |
| AppleTalk Messenger (ATMsg) | L | ATMsg.exe | Related to AppleTalk_Messenger Now owned by Pure Networks, Inc. PC MACLAN will permit the transfer of data from PC to Mac. Note: Located in \%Program Files%\Miramar\PC MACLAN\ |
| Application Experience (AeLookupSvc) | L | aelupsvc.dll | Part of Windows Vista Note:Located in C:\%WINDIR%\System32 |
| Application Information (AeLookupSvc) | L | appinfo.dll | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| Application Layer Gateway (Application Gateway Service) | X | WeRecl.exe | Added by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. More here |
| Application Layer Gateway Manager (AppLayerGatewayMgr) | X | alg.exe | Added by W32/Tilebot-EU WORM!, Note: not to be confused with see_Here located in C:\Windows\System32\ this infection is locate in C:\Windows\ |
| Application Layer Gateway Service (ALG) | L | alg.exe | Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Internet Connection Firewall Note:Located in C:\%WINDIR%\System32 (Vista /XP/WinNT/2K) |
| Application Layer Gateway Services | X | alg.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ |
| Application Layer Gateway System (ALGS) | X | algsys.exe | Added by the W32/Rbot-DDF WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Application Layer Service | X | weRecv.exe | Added by the SystemPoser TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ folder. |
| Application Layer Service (algserv) | X | algserv.exe | Troj/Agent-ECW Note: Located in %windir%\system32 |
| Application Layer Service Control (applilserv) | X | applayer.ex | W32/Rbot-GHL Note: Located in %windir%\system32 Read the link, allows remote access |
| Application Management (AppMgmt) | L | appmgmts.dll | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| Application State Service (AppSvc) | X | apsvc.exe | Added by the W32/Rbot-FWW WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| AppMgmt | X | svchost.exe -k AppMgmt | Added by the Fuwudoor TROJAN! |
| AppnNode | L | appnnode.exe | Related to IBM_Server Note: Located in C:\WINDOWS\system32\Drivers\ |
| ARC Plugin (ARCPLUG) | X | arci.exe | Added by the W32/Tilebot-HB WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Steal information from Protected Storage |
| ArcaBit NetMonitor (ABNetMon) | L | NetMonSV.exe | ArcaVir an AntiVirus software from Poland. A procuct of ArcaBit Sp. z o.o |
| ArchestrA Logger (aaLogger) | L | aaLogger.exe | Related to ArchestrA Software architecture for the integration of your automation systems. |
| ARcltsrv | L | ARCLTSRV.EXE | Cryptography software by Algorithmic Research Ltd. |
| Ares Chatroom server (AresChatServer) | L | chatServer.exe | Related to the Ares P2P software |
| Argos Billing Dialog | L | WorkstationMonitor.exe | Related to Argos_Billing_Dialog from Sepialine inc. Print Monitor. Note: Located in c:\Program Files\Sepialine\Argos Print Monitor\ |
| ArGoSoft Mail Server Plus | L | mailservernt.exe | Related to ArGo Software Design Mail Server |
Array SSL VPN Service 3,0,1,9 (ArraySSL_VPN_Service3,0,1,9) | L | arr_srvs3,0,1,9.exe | Related to SSL_VPN SSL VPN Secure Access Gateways from Array Networks. Anytime, anywhere secure access. Note: Located in C:\Program Files\Array Networks\Array SSL VPN\3,0,1,9\ |
Array SSL VPN Service 8,1,0,307 (ArraySSL_VPN_Service8.1.0.307) | L | arr_srvs.exe | Related to Array_SSL_VPN from Array Networks, Inc. Service. Note: Located in \%Program Files%\Array Networks\Common\8,1,0,307\ |
Array Utility Service 4,0,1,3 (Array_Utility_Service4,0,1,3) | L | arr_isrv4,0,1,3.exe | Related to SSL_VPN SSL VPN Secure Access Gateways from Array Networks. Anytime, anywhere secure access. Note: Located in C:\Program Files\Array Networks\Common\4,0,1,3\ |
Array Utility Service 8,1,0,307 (Array_Utility_Service8.1.0.307) | L | arr_isrv.exe | Related to Array_SSL_VPN from Array Networks, Inc. Service. Note: Located in \%Program Files%\Array Networks\Common\8,1,0,307\ |
| Ascent Capture Service | L | acsvc.exe | Related to Kofax Image Products. |
| ASF Agent | L | ASFAgent.exe | Intel Alert Standard Format Console - asfagent.exe is a part of a systems management suite bundled with other applications, mainly Dell's OpenManage. |
| Ashampoo AntiSpyWare 2 Service (AASW2_Service) | L | AntiSpyWareService.exe | Related to Ashampoo_AntiSpyWare Note: Located in \%ROOT%\Ashampoo AntiSpyWare 2\ |
| AshampooDefragService | L | aDefragService.exe | Related to Ashampoo Magic Defrag Utility |
| asKernel | L | ASKERNEL.EXE | Related to Aluria_Software's - Aluria Security Center Note: Located in Center. C:\PROGRA~1\ALURIA~2\ |
| ASLDR Service (ASLDRService) | L | ASLDRSrv.exe | Related to ATK_Hotkey on ASUSTeK Computer. Note: Located in \%Program Files%\ATK Hotkey\ |
| ASMAgent | L | ASMAgent.exe | Related to ASAP_eSMART Smart Asset Management tool. |
| ASNFTP daemon (ASNFTPD) | X | AsnFtpd.exe | Added by the W32/Tilebot-BD
WORM!
Note: This worm\trojan file is found in the Windows or Winnt folder.
Read the link, rootkit type stealth involved. |
| ASP.NET (State Service) | | ASP.NET.exe | Troj/GrayBir-EC Note: Located in %windir% Read the link allows remote access |
| ASP.NET State Service (aspnet_state) | L | aspnet_state.exe | Related to Microsoft Windows Operating System and is the ASP State Service. |
| Asset Insight Client (AICLIENT) | L | Aiclient.EXE | Asset Insight from Tangram - http://castlecops.com/s1883-AICLIENT_EXE.html |
| Asset Management Agent (AmoAgent) | L | UMCSTUB.EXE | Related to Unicenter Asset Management by Computer_Associates |
| Asset Management Daemon | L | dtsslsrv.exe | Display configuration software used by several manufacturers under differing names such as Image Tune or EZTune etc...
Note: located in C:\Program Files\... |
| Asset Management SW Meter Agent (SWMSVC) | L | SWMSvc.exe | Related to Asset_Management from Computer Associates. Note: Located in \%Program Files%\\CA\Unicenter Asset Management\Agents\ |
| AST Service (astcc) | L | astsrv.exe | Nalpeiron Trusted Activation This service exists if an application protected with PRO-Tector is installed
Note:C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Asus Motherboard Utility (Asus) | X | asus.exe | Added by the WORM_SPYBOT.IY WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. |
| ASUSKeyboardService | L | asuskbservice.exe | Added by ASUS_Keyboard Service and provides additional configuration options for these devices. Note: located in C:\%WINDIR%\ |
| ASWLSVC | L | ASWLSVC.exe | Relate to the ASUS_Wireless_LAN_Card_Services |
| Asynchronous Load Balance (ySvcHst) | X | srvnst.exe | Added by ServiceThreadHandler.Process TROJAN! Note: located in C:\WINDOWS\System32\ |
| Asynchronous UPnP Support Services | X | UPnPSvc.dll | Troj/PWS-ANB Read the link, steals information |
| AT Host Service | L | atnthost.exe | Related to WebEx |
| AT&T Internet Security Suite AT&T Firewall (RP_FWS) | L | Fws.exe | Related to Internet_Security_Suite from AT&T Note: Located in \%Program Files%\\AT&T\AT&T Internet Security Suite\ |
| AT&T Internet Security Suite Service (RPSUpdaterR) | L | rpsupdaterR.exe | Related to Internet_Security_Suite from AT&T Note: Located in \%Program Files%\AT&T\AT&T Internet Security Suite\ |
| Atheros Configuration Service (ACS) | L | acs.exe | related to Atheros Wireless LAN |
| Ati External Event Utility | L | Ati2evxx.exe | ATI Video Card Control Panel |
| Ati HotKey (audieqaab) | X | lmgua.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| Ati HotKey Poller | L | Ati2evxx.exe | ATI Video Card Control Panel |
| ATI Smart | L | ati2sgag.exe | ATI Video Card Control Panel |
| ATI WebPAM (ATIWebPAM) | L | Wrapper.exe | Related to ATI_Array ATI WebPAM&hl=en&ct=clnk&cd=2&gl=ca&lr=lang_en|lang_fr Management Software. Note: Located in \%Program Files%\ATI\WebPAM\jetty\extra\win32\ |
| ATIintergrated (ATIintergrated) | X | atigraphics.exe | Added by the SDBOT.CRX
WORM!
Read the link, rootkit type stealth involved.
|
| ATK Keyboard Service (ATKKeyboardService) | L | ATKKBService.exe | Related to ASUSTeK_Computer Inc. ASUS Keyboards and provides additional configuration options for these devices. |
| ATKGFNEX Service (ATKGFNEXSrv) | L | GFNEXSrv.exe | Related to ATKGFNEX Service on ASUSTeK Computer. Note: Located in \%Program Files%\ATKGFNEX\ |
| Audio Adapter (VGADown) | X | avp.exe | Troj/Maran-AV
Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR% (XP/WinNT/2K) |
| AuthFw | L | AuthFw.exe | Related to Authentium_Firewall by Authentium, Inc. Note: Located in \%Program Files%\Authentium\Firewall SDK\ |
| Auto HotKey Poller | X | winpol.exe | Added by a variant of the W32/Malware Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Auto Logon Service (AutoLogon) | L | autologonsvc.exe | Related to Macro_Scheduler from MJT Net Ltd. Save time and increase productivity by automating frequent tasks. |
| AutoComplete Service | L | autocomp.exe | Tracks Eraser Pro |
| AutoComplete Service (Autocomplete) | L | delautocomp.exe | Related to Tracks_Eraser_Pro from Acesoft. Note: Located in C:\Program Files\Acesoft\Tracks Eraser Pro\ |
| Autodata Limited License Service | L | ADCDLicSvc.exe | Related to Autodata Limited |
| Autodesk Data Management Job Dispatch | L | Connectivity.WindowsService.JobDispatch.exe | Related to Autodesk_Data_Management Web Server. Note: Located in C:\Program Files\Autodesk\Data Management Server 5\Server\Dispatch\ |
| Autodesk EDM Server | L | Connectivity.EDMWS.Server.exe | Related to Autodesk_Data_Management Web Server. Note: Located in C:\Program Files\Autodesk\Data Management Server 5\Server\Webserver\ |
| Autodesk Licensing Service | L | AdskScSrv.exe | Related to Autodesk, Inc. |
| Autodesk MapGuide® Server 6.3 (MapServer6.3) | L | MapServer.exe | Related to Autodesk Inc. |
| Autodesk Network Licensing Service | L | AdskNetSrv.exe | Related to Autodesk_Network Licensing service. Note: Located in C:\Program Files\Common Files\Autodesk Shared\Service\ |
| Automaattinen LiveUpdate-ajastustoiminto | L | ALUSchedulerSvc.exe | Related to to the Symantec LiveUpdate service which updates your Symantec products periodically. |
| AutoMate 5 (AutoMate5) | L | AutoMate5Svc.exe | Related to Automate from Network Automation, Inc. A Task Service. Note: Located in C:\Program Files\automate\ |
| AutoMate 6 (AutoMate6) | L | AMTS.exe | Related to AutoMate from Network Automation. Tools necessary to completely automate business processes. Note: Located in C:\Program Files\AutoMate 6\ |
| Automatic LiveUpdate Scheduler | L | ALUSchedulerSvc.exe | Related to to the Symantec LiveUpdate service which updates your Symantec products periodically. |
| Automatic Update Service (Automatic Update) | X | wuapi.exe | Added by the W32/Codbot-AC
WORM!
Note: This worm\trojan file is found in the System32 folder.
|
| automatic updates for Microsoft Windows | X | wuauclt.exe | W32/Sdbot-DFD
Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
Allows remote access. Makes multiple system changes. Read links for additional information |
| Automatisches LiveUpdate | L | ALUSchedulerSvc.exe | Related to to the Symantec LiveUpdate service which updates your Symantec products periodically. |
| AutoStore (autostore) | L | batch.exe | Related to NSi's AutoStore from Notable Solutions, Inc. Capture documents and securely saving the content in your business applications. |
| AutoUpdate (Windows Server AutoUpdate) | X | Winupdate.exe | Troj/GrayBrd-CF Note: Located in %windir%\system32 Read the link, allows remote access and logs keystrokes |
| AutoUpdateD | L | AutoUpdateD.exe | Related to Xcelera_Echo_Lab_Management Medical services from Philips. |
| Av Update Monitor (AvSvcMonitor) | L | AvMonitor.exe | Avast
|
| avast! Antivirus | L | ashServ.exe | Related to Avast AntiVirus |
| avast! iAVS4 Control Service (aswUpdSv) | L | aswUpdSv.exe | Related to Avast AntiVirus |
| avast! iAVS4 Mirror HTTP Server (aswHTTPMirror) | L | httpd.exe | Related to Avast! anti-virus software. Note: Located in \%Program Files%\Alwil Software\Management Tools\mirror\ |
| avast! Mail Scanner | L | ashMaiSv.exe | Related to Avast AntiVirus |
| avast! Management Server | L | avEngine.exe | Related to Avast! anti-virus software. Note: Located in \%Program Files%\Alwil Software\Management Tools\mirror\ |
| avast! Web Scanner | L | ashWebSv.exe | Related to AWIL Software
http://www.avast.com/
|
| Avast32 Start as Service | ? | avserver.exe | seems to belong to Avast anti-virus software |
| AVCore (SrvMain) | X | avservice.exe | As of yet Unknown Worm, Trojan or Malware. The file (avservice.exe) is found in the Documents and Settings\All Users\Application Data folder. |
| Aventail Connect (As32Svc) | L | as32svc.exe | Related to Aventail_Corp |
| Aventail VPN Client (NgVpnMgr) | L | ngvpnmgr.exe | Related to VPN_Tunnel Manager from Aventail Corporation. Note: Located in \%WINDIR%\System32\ |
| Aventail VPN Client (qqhuouaeu8auaraa) | X | rojkxz.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| AVG Anti-Spyware Guard | L | guard.exe | AVG
Anti-virus product. |
| AVG E-mail Scanner (AVGEMS) | L | avgemc.exe | Related to AVG anti-virus |
| AVG Firewall (AVGFwSrv) | L | avgfwsrv.exe | Related to AVG_Firewall Note: located in C:\PROGRA~1\Grisoft\AVG7\ |
| AVG6 Service (AvgServ) | L | avgserv.exe | AVG 6 Anti virus |
|