CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9466.22 of $21422.68
left sidedonated so farneed $11956.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 3876 entries and growing...
Last updated on 2008-05-09 18:10:24 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   


    Full List

    NameStatusFilenameDescription
    a-squared Anti-Dialer Service (a2AntiDialer)La2service.exeRelated to Related to a-squared Virus protection software. Note: Located in \%Program Files%\a-squared Anti-Dialer\
    Belgium Identity Card Service
    (BELGIUM_ID_CARD_SERVICE)
    LBelpic PCSC Service.exe Belgium Identity Card Middleware from Zetes/CSC
    Dell Printer Status Database (DLSDB)LDLSDBNT.EXERelated to Dell_Printers Note: Located in C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\
    license Llic_srv.exelicense
    LXCCCustomerConnectLLXCCserv.exeRelated to Lexmark printers Note: Located in %windir%\System32\spool\DRIVERS\W32X86\3\\LXCCserv.exe
    Network Windows Service (MSWindows)Xurdvxc.exeAdded by the W32/Allaple-B WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    pcAnywhere Install Service - Symantec CorporationLpca_run.exe Part of Symantec PCAnywhere
    Remote Debug ServicesXsmsc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Shell Software Detection (ShellSWDetection)Xshellsw.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    SolidWorks Licensing ServiceLSolidWorksLicensing.exe Part of a SolidWorks product
    Windows Zero Connection (WinZConn)?mswnt.exe Probable backdoor trojan
    Wireless Adapter ConfiguratorLWirelessDaemon.exeRelated to BT's home hub products
    ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##
    (Bonjour Service)
    LmDNSResponder.exemdnsresponder.exe is a process associated with "Bonjour for Windows" software. It is used by ITunes for music sharing. Note: Located in \%Program Files%\Bonjour\
    $sys$ariesXaries.sysAdded by the SonyBMG_First4DRM ROOTKIT! Read the link, rootkit type stealth involved. Thanks Sony.
    (4 random characters).sysXwindev(4 random characters).sys Troj/Dorf-K
    (Any service name)Osrvany.exeThis utility allows running Windows NT\2000\XP applications as services. Can also be used to load Malware. See Explanation ... Example of how to find the file being loaded with Service name iOpusService
    (non-roman characters)XsServer.exeAdded by the Troj/Feutel-AB TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    (random file name without extension)X(random file name).sysAdded by the TROJ_ROOTKIT.AI TROJAN! Read the link, rootkit type stealth involved.
    (Random Letters)X(Random FileName).dll Troj/Conhook-AG Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Installs multiple services. Read link
    (random name)Xwindow.exe Troj/Hupigon-BS Note: Located in %windir% Read the link, steals information and allows remote access
    (Random name)Xavpo.exe W32/SillyFDC-BA Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K)
    (Random) *See description*Xirjit.dllAdded by the Backdoor.CVM TROJAN! Note: This trojan file is found in the System or System32 folder. *Check the link for the list of random service names.*
    (special characters) (myserver)Xmyserver.exeAdded by the Troj/Dropper-BR TROJAN!
    *Microsoft UpdateXwstcl.exeNo from Microsoft.
    *Microsoft UpdateXwuytc.exeunknown virus
    *windows updateXwsctl.exemalware virus. possibly "Win32.Rbot.gen"
    *windows updateXwuaucrlt.exeAdded by the W32.Spybot.HUR WORM!
    *wuauclt.exeXrandomRelated to WORM_RBOT.AKU or variant.
    .CPROGRA (SAP DBTech-.CPROGRA)Lkernel.exeRelated to SAP_MaxDB The SAP Database System. Note: Located in \%Program Files%\SAPDB\DEPEND\pgm\
    .NET Framework ServiceXsvchost.exe"Trojan-PSW.Win32.Sagic.15" Virus
    .NET Framework Service (.NET Connection Service)Xsvchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ Note The proper location for that operating file is in C:\%WINDIR%\System32
    .NET Runtime Optimization Service v2.0.50215_X86
    (clr_optimization_v2.0.50215_32)
    Lmscorsvw.exeRelated to Microsoft_NET_Framework NET Runtime Optimization Service.
    .NETSecurityXnetsecurity.exeAdded by a variant of the Rootkit.Haxdoor Note: Located in \%WINDIR%\System32\
    01ApacheLApache.exeRelated to Apache web server Note: Located in \%Program Files%\01COM~1\WEBSER~1\
    1784-PCIDS DeviceNet?PcidsService.exe Appears to be from Rockwell software
    1789-SIM Simulator Module (SimModuleService)?SimModuleService.exe Appears to be from Rockwell software
    19E7E238X19E7E238.EXE Troj/Agent-ELX
    1Google Online Search ServiceXwinlugan.exeIdentified as a variant of the Trojan-Downloader.Win32.Winlagons.ak malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    1Google Online Search ServiceXwinlegal.exeIdentified as a variant of the Trojan-Downloader.Win32.Winlagons.an malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    2D98923DXE69C6CEE.exe Troj/Agent-FYY Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Allows others to access the computer
    32-bit Installation Host (inst32)Xinst32.exeAdded by the W32/Chinegan-A WORM! Note: This worm is located in C:\Program Files\Common Files\inst32\
    32-bit Registration Host (reghost32)Xreghost32.exeAdded by the W32/Rbot-GKR WORM! Note: This worm is located in C:\Program Files\Common Files\System\
    39672EA4X39672EA4.EXE Troj/GrayBir-EW
    3Com DMI AgentL3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
    3ComBOOTPL3CBOOTPS.EXEA 3Com Product Allows network administrators to remotely manage client PCs on their network by allowing them to deploy an array of desktop management tasks in a pre-OS booting environment. Note: Located in Drive:\Program Files\3Com\Boot Services
    3ComPXEL3CPXES.EXEA 3Com Product Allows network administrators to remotely manage client PCs on their network by allowing them to deploy an array of desktop management tasks in a pre-OS booting environment. Note: Located in Drive:\Program Files\3Com\Boot Services
    3ComTFTPL3CTFTPS.EXEA 3Com Product Allows network administrators to remotely manage client PCs on their network by allowing them to deploy an array of desktop management tasks in a pre-OS booting environment. Note: Located in Drive:\Program Files\3Com\Boot Services
    3dkeybdO3dkeybd.exeUnknown... No answers on the net.
    3DML3dmd.exeRelated to 3ware SATA RAID controler. Note: Located in \%Program Files%\3ware\3DM\
    55euf6X55euf6.sys Troj/DwnLdr-GWX Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K) May install another service a6fyts35
    64Bit architecture emulation (wrmsrvice)XWRMSRVICE.SYSAdded by the TROJ_ROOTKIT.AG TROJAN! Read the link, rootkit type stealth involved.
    79F5137EXDBB6ED81.EXE W32/SlliyFD-G Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Allows others to access the computer
    80xFire daemon (80xFire)X80xFire.exeAdded by the W32/Tilebot-BK WORM! Note: This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    9F9DF57CX(random name) Troj/DwnLdr-GUT
    @%ProgramFiles%\Windows Media
    Player\wmpnetwk.exe,-101 (WMPNetworkSvc)
    Lwmpnetwk.exeRelated to Windows_Media_Player Network Sharing Service. Note: Located in %ProgramFiles%\Windows Media Player\
    @%SystemRoot%system32snmptrap.exe,-3 (SNMPTRAP)Lsnmptrap.exeRelated to MKS_Toolkit In Windows Vista. Note:Located in C:\%WINDIR%\System32
    @%SystemRoot%ehomeehstart.dll,-101 (ehstart)Lsvchost.exeWindows Media Center Service Launcher in the Windows Vista edition
    @%SystemRoot%system32Alg.exe,-112 (ALG)Lalg.exeProvides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Internet Connection Firewall Note:Located in C:\%WINDIR%\System32 (Vista 64bit)
    @%systemroot%system32Locator.exe,-2 (RpcLocator)Llocator.exe Part of Windows Vista. Note:Located in C:\%WINDIR%\System32
    @%SystemRoot%System32netlogon.dll,-102 (Netlogon)Llsass.exeRelated to NetLogOn Check the validity of the Passwords on a Vista 64 bit. Note: Located in \%WINDIR%\System32\
    @%systemroot%system32psbase.dll,-300
    (ProtectedStorage)
    Llsass.exe Part of Windows Vista Note:Located in C:\%WINDIR%\System32
    @%SystemRoot%system32qwave.dll,-1 (QWAVE) Lsvchost.exe Part of Windows Vista. Note:Located in C:\%WINDIR%\System32
    @%SystemRoot%system32samsrv.dll,-1 (SamSs) Llsass.exe Part of Windows Vista. Note:Located in C:\%WINDIR%\System32
    @%SystemRoot%system32seclogon.dll,-7001 (seclogon)Lsvchost.exePart of Windows Vista
    @%Systemroot%system32wbemwmiapsrv.exe,-110
    (wmiApSrv)
    LWmiApSrv.exeRelated to Vista 64 bit computer.
    @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart)Lsvchost.exePart of Windows Vista
    @%systemroot%\system32\spoolsv.exe,-1 (Spooler)Lspoolsv.exe part of Windows Vista used for Fax and Printing. Note:Located in C:\%WINDIR%\System32
    @%SystemRoot%\system32\vds.exe,-100 (vds)Lvds.exe Part of Windows Vista Note:Located in C:\%WINDIR%\System32
    @%systemroot%\system32\vssvc.exe,-102 (VSS)Lvssvc.exe Part of Windows Vista Note:Located in C:\%WINDIR%\System32
    @comres.dll,-2797 (MSDTC)Lmsdtc.exe Part of Windows Vista. Note:Located in C:\%WINDIR%\System32 (Vista/XP/WinNT/2K)
    @dfsrres.dll,-101 (DFSR)LDFSR.exePart of Windows Vista 64Bit. Note:Located in C:\%WINDIR%\System32
    @keyiso.dll,-100 (KeyIso)Llsass.exeRelated to CNG_Key_Isolation_Service Found on Vista 64 bit.
    a-squared Anti-Malware Service (a2AntiMalware)La2service.exeRelated to Related to a-squared Virus protection Software. Note: Located in \%Program Files%\a-squared Anti-Malware\
    a-squared Free Service (a2free)La2service.exeRelated to a-squared free edition, from Emsi Software GmbH
    a6fyts35Xa6fyts35.sys Troj/DwnLdr-GWX Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K) May install another service 55euf6
    aaksrvLaaksrv.exeSpydex Advanced Anti keylogger
    AAMQDispatcherLAAMQDispatcherService.exeCompuware Serversoftware
    ABBYY FineReader 9.0 PE Licensing Service
    (ABBYY.Licensing.FineReader.Professional.9.0)
    LNetworkLicenseServer.exeRelated to ABBYY_FineReader from ABBYY accurate conversion of images into text or searchable PDF for the purpose of categorizing, archiving, searching or integrating with third party content management systems. Note: Located in \%Program Files%\\Common Files\ABBYY\FineReader\9.00\Licensing\PE\
    ABCSpell Helper ServiceLABCSpellService.exeSpell checker (Ect, ect) for Outlook Express. For more information Click_Here
    AbelXAbel.exeSource: http://www.pestpatrol.com/PestInfo/C/Cain.asp
    abhcopXabhcop.sysAdded by the PigSearch Adware. Read the link, rootkit type stealth involved.
    ACXacoustic.exeAdded by the SDBOT.CRN WORM! Read the link, rootkit type stealth involved.
    Ac Profile Manager Service (AcPrfMgrSvc)LAcPrfMgrSvc.exeRelated to the Ac_Profile_Manager_Service installed as a part of ThinkPad Access Connections suite on ThinkPad laptops. Note: Located in C:\Program Files\ThinkPad\ConnectUtilities\
    AC-DNAME (AC-DNAME)Xacoustic.exeAdded by the SDBOT.CFN WORM! Read the link, rootkit type stealth involved.
    Accenture Media Viewer (MediaViewer)Lstreamviewerservice.exeRelated to Accenture_Media_Viewer
    Access Connections Main Service (AcSvc)LAcSvc.exeRelated to Lenovo ThinkVantage Access Connections Main Service Module. Note: Located in \%Program Files%\ThinkPad\ConnectUtilities\
    Access Utility ServiceLSMBAUtilSvc.exeRelated to Sprint_Mobile_Broadband
    Acer Media ServerLMediaServerService.exeRelated to Acer_Media_Server Empowering Technology. Note: Located in \%Program Files%\Acer\Acer eConsole\
    ACMService (ACMService)LAdded by the ACM SPYWARE! **Note this is a commercial computer monitoring software
    ACNUSvcLacnupdatersvc.exeRelated to Accenture global management consulting, technology services and outsourcing company Note: Located in c:\program files\acnu\
    acpidiskXacpidisk.sys Troj/Agent-FXI Note: Located in %System%\drivers
    Acronis Backup Server Service
    (AcronisBackupServerService)
    Lbackupserver.exeRelated to Acronis_Backup Backup server from Acronis. Note: Located in \%Program Files%\Acronis\BackupServer\
    Acronis Group Server (GroupServer)LGroupServer.exeRelated to Acronis_Backup Group server from Acronis. Note: Located in \%Program Files%\Acronis\GroupServer\
    Acronis OS Selector Reinstall Service
    (AcronisOSSReinstallSvc)
    Loss_reinstall_svc.exeRelated to Acronis_Disk_Director suite. A disk management functions, partition recovery tool, and boot disk manager. Note: Located in \%Program Files%\Acronis\Acronis Disk Director\
    Acronis Scheduler2 Service (AcrSch2Svc)Lschedul2.exeRelated to Acronis_True_Image creates the exact copy of your hard disk and allows you to instantly restore the entire machine including operating system. Note: Located in C:\Program Files\Common Files\Acronis\Schedule2\
    Acronis Scheduler_HelperXschedhlp.exeAdded by a variant of the Backdoor.Sdbot Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Acronis Try And Decide Service (TryAndDecideService)LTrueImageTryStartService.exeRelated to True_Image Powerful Backup utility. Note: Located in \%Program Files%\Common Files\Acronis\Fomatik\
    acrotray (Acrotray)Osrvany.exeMicrosoft Windows application which allows an executable to be run as a service. If you have installed this service, fine, otherwise investigage. Can be used to load Malware.
    ActionAgentLActionAgent.exeRelated to ActionAgent, from Dell Computer. "A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation package; provides a simple method for a remote administrator to perform actions on the instrumented client". Note: Located in \%Program Files%\Dell\OpenManage\Client\
    ActivCard Authentication Service (ACachSrv)Lacachsrv.exeRelated to ActivCard Gold Component of ActivCard Gold from ActivIdentity, Inc. Smart cards that function as photo ID, proximity badges for facility access and as digital identification and authentication devices. Note: Located in \%Program Files%\Common Files\ActivCard\
    ActivCard Gold Autoregister (acautoreg)Lacautoreg.exeRelated to ActivCard Gold Component of ActivCard Gold from ActivIdentity, Inc. Smart cards that function as photo ID, proximity badges for facility access and as digital identification and authentication devices. Note: Located in \%Program Files%\Common Files\ActivCard\
    ActivCard Gold service (Accoca)Laccoca.exeRelated to ActivCard Gold Component of ActivCard Gold from ActivIdentity, Inc. Smart cards that function as photo ID, proximity badges for facility access and as digital identification and authentication devices. Note: Located in \%Program Files%\Common Files\ActivCard\
    Active Virus Shield (AVP)Lavp.exeRelated to Active_Virus_Shield from AOL. Note: Located in C:\Program Files\AOL\Active Virus Shield\
    activePDF Server (A4ACTIVEPDFSERVER)LAPSERVER.EXERelated to active_PDF Server from activePDF, Inc. Provides integrated PDF generation and dynamic PDF conversion. Note: Located in \%WINDIR%\System32\
    ActiveSMART ServiceLASmartService.exeRelated to Active_SMART from Ariolic.com utilizes the S.M.A.R.T. technology to track the status of the computer hard disks. Note: Located in \%Program Files%\Active SMART\
    ActiveSMART Service (aomaukbamapi)Xumlt.exeAdded by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename.
    ActiveXperts Network Monitor (AxsNmSvc)LAxsNmSvc.exeAdded by ActiveXperts_Network_Monitor allows administrators to monitor the network for failures and irregularities. Note: Located in C:\Program Files\ActiveXperts\
    Actuate Process Management Daemon 8
    (__AC_PROCESS_MGMT_DAEMON8)
    Lpmd8.exe Actuate_Enterprise Reporting Applications for business intelligence analytic services
    ACU Configuration Service (ACS)Lacs.exeWireless-USB utility More here
    Ad-Aware 2007 Service (aawservice)Laawservice.exeRelated to Ad-Aware_2007 anti-spyware solution. This program can find and remove spyware and malware from your computer. Note: Located in C:\Program Files\Lavasoft\
    Ad-Axis ClientLaaclient.exeRelated to Lavasof's Ad-Aware SE Enterprise Edition 2005
    Adaptador de rendimiento de WMI (WmiApSrv)Lwmiapsrv.exeWindows Management Instrumentation Performance Adapter Service Windows XP and 2003. Note: Located in C:\WINDOWS\System32\wbem\wmiapsrv.exe
    Adaptec I/O Manager ServerLiomgr.exeRelated to Adaptec product
    Adaptec RAID Remote Services AgentLafaagent.exeRelated to Adaptec, Inc.
    Adaptec Storage Manager NotifierLnotify.exeRelated to Adaptec procuct
    Adaptec Web ServerLarcpd.exeRelated to Adaptec procuct.
    AdaptecStorageManagerAgentLStorServ.exeRelated to Adaptec Incorporated
    Adapter Switching (IntelRoam)LRoamSvc.exeIntel Adapter Switching
    Adaptive Server AnywhereLdbsrv7.exeRelated to Sybase_Adaptive_Server Anywhere Network Server. Note: Located in \%ROOT%\sqla7\win32\
    AddFiltrLAddFiltr.exeFound on HP computers
    ADF Installer Service (ADF Installer)LAgentSVC.exeRelated to Citrix Installation Manager Service
    Admin Works Agent X8 (AWService)LawServ.exeRelated to AdminWorks from Avocent Corporation. A cost effective IT management software tool for small and medium size businesses. Note: Located in C:\Program Files\Intel\IDU\
    Administracióe aplicacionesLservices.exeSpanish Windows 2000 applications managing
    Administrador de cuentas de seguridadLlsass.exeSpanish Windows 2000 security accounts manager
    Administrador de discosLservices.exeSpanish Windows 2000 disks manager
    Administrador de sesióe Ayuda de escritorio remotoLsessmgr.exeThis service manages and controls Remote Assistance
    Administrador de sesión de Ayuda de escritorio remoto
    (RDSessMgr)
    Lsessmgr.exeRelated to Microsoft's remote assistance windows plugin. This allows an end user to call for assistance when a remote assistance network service is in place. This process shouldn't be terminated if the fore-mentioned service is in place on your local area network.
    Administrador de utilidadesLUtilMan.exeSpanish Windows 2000 utility manager
    AdminWorks Agent X6 (AWService)LadmServ.exeRelated to Avocent, http://www.embedded.avocent.com/ Embedded Software and Solutions Division. Note: Located in %ROOT%:\Acer\Empowering Technology\
    Adobe Active File Monitor (AdobeActiveFileMonitor)LPhotoshopElementsFileAgent.exeRelated to Adobe Photoshop Elements. A popular graphics rendering tool. Note: Located in \%Program Files%\Adobe\Photoshop Elements 3.0\
    Adobe Active File Monitor V5
    (AdobeActiveFileMonitor5.0)
    LPhotoshopElementsFileAgent.exeRelated to Adobe Photoshop Elements. A popular graphics rendering tool. Note: Located in \%Program Files%\Adobe\Photoshop Elements 5.0\
    Adobe LM ServiceLAdobelmsvc.exeRequired for PhotoshopCS
    Adobe Plugins ReaderXsvshost.exeAdded by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\
    Adobe Update Manager (Adobe3M)Xmshss.exeAdded by the Troj/Wollf-B TROJAN! Note: This worm\trojan file is found in the System32 folder.
    Adobe Version Cue CS2LVersionCueCS2.exeRelated to Adobe Products
    Adobe Version Cue CS3LVersionCueCS3.exeRelated to Adobe_Version_Cue CS3. Note: Located in \%Program Files%\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\
    AdobeVersionCueLVersionCue.exeAdobe related
    ADSM Service (ADSMService)LADSMSrv.exeRelated to ASUS_Data_Security_Manager on ASUSTeK Computer. Note: Located in \%Program Files%\ASUS\ASUS Data Security Manager\
    ADSServiceLADSSER~1.EXERelated to Aluria_Active_Defense_Shield Service. An EarthLink Co. Note: Located in C:\Program Files\EarthLink\Protection Control Center\
    Advanced Networking Service (audieqaao)Xlmguv.exeAdded by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename.
    Advanced Networking Service (hnmsvc)Lhnm_svc.exeRelated to Advanced_Networking_Service from Dell. Note: Located in %\Program Files%\Dell Network Assistant\
    Advantage Database Server (Advantage)LADS.EXERelated to Extended Systems' Advantage_Database_Server
    AEClientHostServiceLAEClientHostService.exeRelated to GE_Fanuc_Automation enable you to act in real-time to optimize productivity and increase profitability. Note: located in C:\Program Files\GE Fanuc\Alarm Viewer\Host\
    Aelita DMW Migration AgentLVmover.exeRelated to Quest_Domain Migration Wizard Note: Located in C:\%WINDIR%\System32\
    AEServLAEServEx.exeRelated to Anti-Executable from Faronics Corporation. Provides total system control, restricting the user's ability to run or install any new executable program. Note: Located in \%WINDIR%\System32\
    AFinding Service (AFinding)Xafinding.exe AFinding.Process
    Age of Empires III: The WarChiefsXageofempires.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\dllcache\ (Win9x/Me), C:\%WINDIR%\dllcache\ (XP/WinNT/2K)
    Agente de directivas IPSECLlsass.exeSpanish Windows 2000 IPSEC policy agent
    Agere Modem Call Progress Audio (AgereModemAudio)Lagrsmsvc.exeRelated to Agere_Modem Call Progress Audio. (Now owned by LSI Corp.) Note: Located in C:\Windows\system32\
    Agere Service (AgrSrvce)LAgrSrvce.exeRelated to Proxim_Corp Client manager software associated with the ORiNOCO wireless LAN card.
    AhnLab Task SchedulerLAhnsdsv.exeRelated to AhnLab Task Scheduler from AhnLab, Inc. Note: Located in \%Program Files%\AhnLab\Smart Update Utility\
    AIM (AIM)Xaim.exeAdded by the W32/Rbot-AGC or W32/Sdbot-BFX WORM! Read the link, rootkit type stealth involved.
    Aim Version 6 (Aimv6)Xaim6.exeIdentified as the Rbot.cgu infection. This infection is part of the family of worms and IRC backdoors. Note: This worm is located in C:\WINDOWS\Cursors\
    aim.exXIEXPLORER.EXEAdded by the SDBOT.COW WORM! Read the link, rootkit type stealth involved.
    Airgo Networks NIC Service (ANISERVICE)LaniServ.exeRelated to Airgo_Networks NIC Service Note: Located in \%WINDIR%\System32\
    ALaunch Service (ALaunchService)LALaunchSvc.exeFound on Acer laptops. Note: Located in \%ROOT%\Acer\ALaunch\
    AlerterLsvchost.exeNotifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start.
    AlfaCleanerServiceXACServer.exe AlfaCleaner is now a stealth install using exploits on unpatched systems. Seen alongside RazeSpyware. This program tends to be installed with other known Smitfraud infections.
    ALGEXHacker.com.cn.exe Troj/GrayBr-CP Read the link, allows remote access
    algsXalgs.exeAdded by the W32.Linkbot.M Note: Located in \%WINDIR%\System32\
    Almacenamiento protegidoLservices.exeSpanish Windows 2000 protected storage
    Altera JTAG Server (JTAGServer)LJTAGServer.exeRelated to Altera Quartus II Software. Note: Located in C:\altera\quartus50\bin\
    Alternative User Input Services (Ctfmon)Xctfmon.exeAdded by the W32/Tilebot-JR WORM! Note: This worm is located in C:\%WINDIR%\ Note This is not the cftmon.exe normally found in C:\WINDOWS\System32\
    Altiris Agent (AeXNSClient)LAeXNSAgent.exeRelated to Alteris services. http://www.altiris.com
    Altiris Carbon Copy (CarbonCopy32)Lccsrvc.exeRelated to Alteris services. http://www.altiris.com
    Altiris Client Service (AClient)LACLIENT.exeRelated to Altiris, Inc.
    Altiris eXpress NS Client (AeXNSClient)LAeXNSClient.exeRelated to Altiris_eXpress NS Database and SVS (Software Virtualization Services).
    Altiris eXpress NS Client Transport
    (AeXNSClientTransport)
    LAeXNSClientTransport.exeRelated to Altiris_eXpress NS Database and SVS (Software Virtualization Services).
    Aluria Message Service (MsgSrvService)LAluriaMsgSrv.exe Aluria security center
    Aluria Security Center Spyware Eliminator Service
    (ASCService)
    Xascserv.exeAluria Spyware Eliminator "Spyware remover" a rogue program of dubious repute - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for "Alura"
    Aluria Spyware Eliminator ServiceOASEServ.exeAluria Spyware Eliminator
    AL_ADSServiceXAL_ADSService.exeAluria Spyware Eliminator "Spyware remover" a rogue program of dubious repute - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for "Alura"
    Amadeus Automatic UpdateLAutoUpdate.exeRelated to Amadeus powerful front office travel management tool. Note: Located in C:\Program Files\Automatic Update\
    Amazon Unbox Video Service (ADVService)LADVWindowsClientService.exeRelated to Amazon_Unbox_Video_Service Note: Located in \%Program Files%\Amazon\Amazon Unbox Video\
    Amazon Unbox Video Service (ia8yaepyjabon)Xvwevpugztu.exeAdded by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename.
    AMD PowerNow! . Technology Service (GemServ)LGemServ.exeRelated to Advanced Micro Devices, Inc. - http://www.amd.com/
    Ampi32 (wdfmgr)Xmsvcrt.exeAdded by the W32/Tilebot-Q WORM! Note: This worm file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    Analysis Server (MSSQLSERVER) (MSSQLServerOLAPService)Lmsmdsrv.exeRelated to Microsoft_SQL_server suite.
    Andrea ADI Filters Service (AEADIFilters)LAEADISRV.EXERelated to Andrea_ADI Filters Service from Andrea Electronics Corp. Note: Located in \%WINDIR%\system32\
    Andrea RT Filters Service (AERTFilters)LAERTSrv.exeRelated to Andrea_RT_Filters Service from Andrea Electronics Corp. Active Noise Cancellation Microphone Headsets. Note: Located in \%WINDIR%\System32\
    Andrea ST Filters Service (AESTFilters)Laestsrv.exeRelated to ST_Filters from Andrea Electronics Corp. Note: located in \%WINDIR%\system32\
    ANIWZCSd Service (ANIWZCSdService)LANIWZCSdS.exeRelated to Alpha_Networks
    Ansys JobManager Service V11 (JobManagerService110)LJobManagerService.exeRelated to Ansys_JobManager from ANSYS, Inc. Note: Located in \%Program Files%\ANSYS Inc\v110\RSM\bin\
    Ansys ScriptHost Service V11 (ScriptHostService110)LScriptHostService.exeRelated to Ansys_ScriptHost from ANSYS, Inc. Note: Located in \%Program Files%\ANSYS Inc\v110\RSM\bin\
    AntiSpyUltra (Zonelaps)Xvsmom.exeAdded by the W32/Tilebot-E WORM! Read the link, rootkit type stealth involved.
    AntiSpyware Scanning Engine (AntiSpywareSrv) XAntiSpyware.srv.exe AntiSpywareApp - a Rogue Security Program
    AntiVir PersonalEdition Classic Guard (AntiVirService)Lavguard.exe Part of Antivir
    AntiVir PersonalEdition Classic Scheduler
    (AntiVirScheduler)
    Lsched.exeRelated to AntiVir Premium Security Suite for the internet. Note: Located in \%Program Files%\AntiVir PersonalEdition Classic\
    AntiVir PersonalEdition Classic Service
    (AntiVirService)
    Lavguard.exeAntiVir antivirus
    AntiVir Scheduler (AntiVirScheduler)Lsched.exeRelated to AntiVir antivirus program.
    AntiVir ServiceLAVGUARD.EXEAntiVir antivirus
    AntiVir UpdateLAVWUPSRV.EXEAntiVir Antivirus
    antivirus32Xantivirus32.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    antivirusdllXwinmsgslive.exeAdded by the W32/Sdbot-CXQ WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. Modifies some FTP files, read the link
    ANTS Profiler serviceLRedGate.Profiler.Service.exeRelated to Red Gate Software Ltd
    AnyClick Service (AnySVC)LAnySVC.exeRelated to Network_Access_Control from UNETsystem Co. Program that controls the internal clients’ access to networks through high-level authentication and policy enforcement in order to prevent the spread of viruses and worms. Note: Located in \%Program Files%\Unetsystem\AnyClick\
    AnyPoint Service - Intel CorporationLAPSERVER.EXEBelongs to Intel_Anypoint home networking system
    AnySensLAnySens.exeRelated to Network_Access_Control from UNETsystem Co. Program that controls the internal clients’ access to networks through high-level authentication and policy enforcement in order to prevent the spread of viruses and worms. Note: Located in \%Program Files%\Unetsystem\AnyClick\
    AOL Anti-Spyware Service (AOL-AntiSpySvc)Xaolspy.exeAdded by a variant of the Backdoor.Win32.Rbot.cgu TROJAN! Note: This worm\trojan is located in C:\WINDOWS\pchealth\
    AOL Anti-Spyware Service (AOL-AntiSpy_Serv)Xaolspy.exeAdded by a variant of the Backdoor.Win32.Rbot.cgu TROJAN! Note: This worm\trojan is located in C:\WINDOWS\repair\
    AOL Anti-Spyware Service (AOLSpyWareRem)Xaolspy.exeAdded by a variant of the Backdoor.Win32.Rbot.cgu TROJAN! Note: This worm\trojan is located in C:\WINDOWS\Debug\
    AOL Antivirus Update Service (aolavupd)Laolavupd.exeRelated to AOL Antivirus Update Service.
    AOL Configuration Utility (AOL_CONF)Xaolconf.exeAdded by a variant of the Backdoor.Win32.SdBot.aad family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\Media\
    AOL Connectivity Service (AOL ACS)LAOLAcsd.exeOwner: America Online. Description: AOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Also shown as AOL Connectivity Service (AOL ACS).
    AOL Connectivity Service (AOL ACS)Lacsd.exeAOL related
    AOL Debug Service (SVC_Debug)Xaoldebugs.exeAdded by a variant of the Backdoor.Win32.Rbot.cgu TROJAN! Note: This worm\trojan is located in C:\WINDOWS\Cursors\
    AOL Hosting Service (AOL_Hosting)Xaolhost.exeAdded by a variant of the SdBot.aad family of worms and IRC backdoor Trojans. Note: This trojan is located in C:\WINDOWS\AppPatch\
    AOL Smart Update Service (AOL-Updatr)Xaolupd.exeVariant of Rbot.cgu
    aol software (Aol Software)Xsmss.exeAdded by the W32/Tilebot-FM WORM! Note: This is not the legitimate Windows process (Which is always found in the System32 folder). This worm file is found in the Windows or Winnt folder. Allows a remote intruder to gain access and control over the computer, read the link.
    AOL Spy Watch (AOL-SPY_Watch)Xaolsw.exeAdded by a variant of the Backdoor.Win32.SdBot.aad family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\Media\
    AOL Spyware Protection Service (AOLService)Laolserv.exeRelated to AOL
    AOL Spyware Removal Agent (AOL-Spy_Ware)Xaolspysw.exeAdded by a variant of the SdBot.aad family of worms and IRC backdoor Trojans. Note: This trojan is located in C:\WINDOWS\Web\
    AOL TopSpeed Monitor (AOL TopSpeedMonitor)Laoltsmon.exeAOL Topspeed
    ApacheLApache.exeApache Web Server Software
    Apache Tomcat (Tomcat6)Ltomcat6.exeRelated to Apache_tomcat
    Apache Tomcat SQSService (SQSService)Ltomcat5.exeRelated to Apache_Tomcat Note: Located in \%ROOT%\USER\Programs\tomcat\bin\
    Apache2LApache.exeApache Web Server
    Apache2Triad Apache2 Service (Apache2)Lhttpd.exeRelated to Apache2Triad Software. An Open source database. Note: Located in \%ROOT%\apache2triad\\bin\
    Apache2Triad Apache2 Service with SSL (Apache2SSL)Lhttpd.exeRelated to Apache2Triad Software. An Open source database. Note: Located in \%ROOT%\apache2triad\bin\
    Apache2Triad MySql Service (MySql)Lmysqld.exeRelated to Apache2Triad Software. An Open source database. Note: Located in \%ROOT%\apache2triad\mysql\bin\
    Apache2Triad PostgreSQL Service (PgSql)Lpg_ctl.exeRelated to Apache2Triad Software. An Open source database. Note: Located in \%ROOT%\apache2triad\pgsql\bin\
    Apache2Triad SlimFTPd Server (SlimFTPd)LSlimFTPd.exeRelated to Apache2Triad Software. An Open source database. Note: Located in \%ROOT%\apache2triad\ftp\
    Apache2Triad Xmail Service (XMail)LXMail.exeRelated to Apache2Triad Software. An Open source database. Note: Located in \%ROOT%\apache2triad\mail\bin\
    APACS+ NIM32 (NIM32)LNim32.exeRelated to Siemens Energy & Automation Platform. Note: located in C:\Program Files\ProcessSuite\NIM\
    APC PBE ServerLpbeserver.exeAPC PowerChute Business Edition Server (For UPS)
    APC UPS ServiceLmainserv.exeRelated to American Power Conversion Corporation
    AppExpress ClientLece.exeRelated to Endeavros Technology, Inc and Microsoft_Encarta
    Apple Mobile DeviceLAppleMobileDeviceService.exeAdded by iTunes 7.3 to interface with Apple mobile devices. Allows iTunes to interact with iPhone when connected to the computer.
    AppleTalk Messenger (ATMsg)LATMsg.exeRelated to AppleTalk_Messenger Now owned by Pure Networks, Inc. PC MACLAN will permit the transfer of data from PC to Mac. Note: Located in \%Program Files%\Miramar\PC MACLAN\
    Application Experience (AeLookupSvc)Laelupsvc.dll Part of Windows Vista Note:Located in C:\%WINDIR%\System32
    Application Information (AeLookupSvc)Lappinfo.dll Part of Windows Vista Note:Located in C:\%WINDIR%\System32
    Application Layer Gateway (Application Gateway Service)XWeRecl.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. More here
    Application Layer Gateway Manager (AppLayerGatewayMgr)Xalg.exeAdded by W32/Tilebot-EU WORM!, Note: not to be confused with see_Here located in C:\Windows\System32\ this infection is locate in C:\Windows\
    Application Layer Gateway Service (ALG)Lalg.exeProvides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Internet Connection Firewall Note:Located in C:\%WINDIR%\System32 (Vista /XP/WinNT/2K)
    Application Layer Gateway ServicesXalg.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\
    Application Layer Gateway System (ALGS)Xalgsys.exeAdded by the W32/Rbot-DDF WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Application Layer ServiceXweRecv.exeAdded by the SystemPoser TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Application Layer Service (algserv)Xalgserv.exe Troj/Agent-ECW Note: Located in %windir%\system32
    Application Layer Service Control (applilserv)Xapplayer.ex W32/Rbot-GHL Note: Located in %windir%\system32 Read the link, allows remote access
    Application Management (AppMgmt)Lappmgmts.dllPart of Windows Vista Note:Located in C:\%WINDIR%\System32
    Application State Service (AppSvc)Xapsvc.exeAdded by the W32/Rbot-FWW WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    AppMgmtXsvchost.exe -k AppMgmtAdded by the Fuwudoor TROJAN!
    AppnNodeLappnnode.exeRelated to IBM_Server Note: Located in C:\WINDOWS\system32\Drivers\
    ARC Plugin (ARCPLUG)Xarci.exeAdded by the W32/Tilebot-HB WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Steal information from Protected Storage
    ArcaBit NetMonitor (ABNetMon)LNetMonSV.exe ArcaVir an AntiVirus software from Poland. A procuct of ArcaBit Sp. z o.o
    ArchestrA Logger (aaLogger)LaaLogger.exeRelated to ArchestrA Software architecture for the integration of your automation systems.
    ARcltsrvLARCLTSRV.EXECryptography software by Algorithmic Research Ltd.
    Ares Chatroom server (AresChatServer)LchatServer.exeRelated to the Ares P2P software
    Argos Billing DialogLWorkstationMonitor.exeRelated to Argos_Billing_Dialog from Sepialine inc. Print Monitor. Note: Located in c:\Program Files\Sepialine\Argos Print Monitor\
    ArGoSoft Mail Server PlusLmailservernt.exeRelated to ArGo Software Design Mail Server
    Array SSL VPN Service 3,0,1,9
    (ArraySSL_VPN_Service3,0,1,9)
    Larr_srvs3,0,1,9.exeRelated to SSL_VPN SSL VPN Secure Access Gateways from Array Networks. Anytime, anywhere secure access. Note: Located in C:\Program Files\Array Networks\Array SSL VPN\3,0,1,9\
    Array SSL VPN Service 8,1,0,307
    (ArraySSL_VPN_Service8.1.0.307)
    Larr_srvs.exeRelated to Array_SSL_VPN from Array Networks, Inc. Service. Note: Located in \%Program Files%\Array Networks\Common\8,1,0,307\
    Array Utility Service 4,0,1,3
    (Array_Utility_Service4,0,1,3)
    Larr_isrv4,0,1,3.exeRelated to SSL_VPN SSL VPN Secure Access Gateways from Array Networks. Anytime, anywhere secure access. Note: Located in C:\Program Files\Array Networks\Common\4,0,1,3\
    Array Utility Service 8,1,0,307
    (Array_Utility_Service8.1.0.307)
    Larr_isrv.exeRelated to Array_SSL_VPN from Array Networks, Inc. Service. Note: Located in \%Program Files%\Array Networks\Common\8,1,0,307\
    Ascent Capture ServiceLacsvc.exeRelated to Kofax Image Products.
    ASF AgentLASFAgent.exe Intel Alert Standard Format Console - asfagent.exe is a part of a systems management suite bundled with other applications, mainly Dell's OpenManage.
    Ashampoo AntiSpyWare 2 Service (AASW2_Service)LAntiSpyWareService.exeRelated to Ashampoo_AntiSpyWare Note: Located in \%ROOT%\Ashampoo AntiSpyWare 2\
    AshampooDefragServiceLaDefragService.exeRelated to Ashampoo Magic Defrag Utility
    asKernelLASKERNEL.EXERelated to Aluria_Software's - Aluria Security Center Note: Located in Center. C:\PROGRA~1\ALURIA~2\
    ASLDR Service (ASLDRService)LASLDRSrv.exeRelated to ATK_Hotkey on ASUSTeK Computer. Note: Located in \%Program Files%\ATK Hotkey\
    ASMAgentLASMAgent.exeRelated to ASAP_eSMART Smart Asset Management tool.
    ASNFTP daemon (ASNFTPD)XAsnFtpd.exeAdded by the W32/Tilebot-BD WORM! Note: This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved.
    ASP.NET (State Service)ASP.NET.exe Troj/GrayBir-EC Note: Located in %windir% Read the link allows remote access
    ASP.NET State Service (aspnet_state)Laspnet_state.exeRelated to Microsoft Windows Operating System and is the ASP State Service.
    Asset Insight Client (AICLIENT)LAiclient.EXEAsset Insight from Tangram - http://castlecops.com/s1883-AICLIENT_EXE.html
    Asset Management Agent (AmoAgent)LUMCSTUB.EXERelated to Unicenter Asset Management by Computer_Associates
    Asset Management DaemonLdtsslsrv.exeDisplay configuration software used by several manufacturers under differing names such as Image Tune or EZTune etc... Note: located in C:\Program Files\...
    Asset Management SW Meter Agent (SWMSVC)LSWMSvc.exeRelated to Asset_Management from Computer Associates. Note: Located in \%Program Files%\\CA\Unicenter Asset Management\Agents\
    AST Service (astcc)Lastsrv.exe Nalpeiron Trusted Activation This service exists if an application protected with PRO-Tector is installed Note:C:\%WINDIR%\System32 (XP/WinNT/2K)
    Asus Motherboard Utility (Asus)Xasus.exeAdded by the WORM_SPYBOT.IY WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    ASUSKeyboardServiceLasuskbservice.exeAdded by ASUS_Keyboard Service and provides additional configuration options for these devices. Note: located in C:\%WINDIR%\
    ASWLSVCLASWLSVC.exeRelate to the ASUS_Wireless_LAN_Card_Services
    Asynchronous Load Balance (ySvcHst)Xsrvnst.exeAdded by ServiceThreadHandler.Process TROJAN! Note: located in C:\WINDOWS\System32\
    Asynchronous UPnP Support ServicesXUPnPSvc.dll Troj/PWS-ANB Read the link, steals information
    AT Host ServiceLatnthost.exeRelated to WebEx
    AT&T Internet Security Suite AT&T Firewall (RP_FWS)LFws.exeRelated to Internet_Security_Suite from AT&T Note: Located in \%Program Files%\\AT&T\AT&T Internet Security Suite\
    AT&T Internet Security Suite Service (RPSUpdaterR)LrpsupdaterR.exeRelated to Internet_Security_Suite from AT&T Note: Located in \%Program Files%\AT&T\AT&T Internet Security Suite\
    Atheros Configuration Service (ACS)Lacs.exerelated to Atheros Wireless LAN
    Ati External Event UtilityLAti2evxx.exeATI Video Card Control Panel
    Ati HotKey (audieqaab)Xlmgua.exeAdded by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename.
    Ati HotKey PollerLAti2evxx.exeATI Video Card Control Panel
    ATI SmartLati2sgag.exeATI Video Card Control Panel
    ATI WebPAM (ATIWebPAM)LWrapper.exeRelated to ATI_Array ATI WebPAM&hl=en&ct=clnk&cd=2&gl=ca&lr=lang_en|lang_fr Management Software. Note: Located in \%Program Files%\ATI\WebPAM\jetty\extra\win32\
    ATIintergrated (ATIintergrated)Xatigraphics.exeAdded by the SDBOT.CRX WORM! Read the link, rootkit type stealth involved.
    ATK Keyboard Service (ATKKeyboardService)LATKKBService.exeRelated to ASUSTeK_Computer Inc. ASUS Keyboards and provides additional configuration options for these devices.
    ATKGFNEX Service (ATKGFNEXSrv)LGFNEXSrv.exeRelated to ATKGFNEX Service on ASUSTeK Computer. Note: Located in \%Program Files%\ATKGFNEX\
    Audio Adapter (VGADown)Xavp.exe Troj/Maran-AV Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR% (XP/WinNT/2K)
    AuthFwLAuthFw.exeRelated to Authentium_Firewall by Authentium, Inc. Note: Located in \%Program Files%\Authentium\Firewall SDK\
    Auto HotKey PollerXwinpol.exeAdded by a variant of the W32/Malware Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Auto Logon Service (AutoLogon)Lautologonsvc.exeRelated to Macro_Scheduler from MJT Net Ltd. Save time and increase productivity by automating frequent tasks.
    AutoComplete ServiceLautocomp.exeTracks Eraser Pro
    AutoComplete Service (Autocomplete)Ldelautocomp.exeRelated to Tracks_Eraser_Pro from Acesoft. Note: Located in C:\Program Files\Acesoft\Tracks Eraser Pro\
    Autodata Limited License ServiceLADCDLicSvc.exeRelated to Autodata Limited
    Autodesk Data Management Job DispatchLConnectivity.WindowsService.JobDispatch.exeRelated to Autodesk_Data_Management Web Server. Note: Located in C:\Program Files\Autodesk\Data Management Server 5\Server\Dispatch\
    Autodesk EDM ServerLConnectivity.EDMWS.Server.exeRelated to Autodesk_Data_Management Web Server. Note: Located in C:\Program Files\Autodesk\Data Management Server 5\Server\Webserver\
    Autodesk Licensing ServiceLAdskScSrv.exeRelated to Autodesk, Inc.
    Autodesk MapGuide® Server 6.3 (MapServer6.3)LMapServer.exeRelated to Autodesk Inc.
    Autodesk Network Licensing ServiceLAdskNetSrv.exeRelated to Autodesk_Network Licensing service. Note: Located in C:\Program Files\Common Files\Autodesk Shared\Service\
    Automaattinen LiveUpdate-ajastustoimintoLALUSchedulerSvc.exeRelated to to the Symantec LiveUpdate service which updates your Symantec products periodically.
    AutoMate 5 (AutoMate5)LAutoMate5Svc.exeRelated to Automate from Network Automation, Inc. A Task Service. Note: Located in C:\Program Files\automate\
    AutoMate 6 (AutoMate6)LAMTS.exeRelated to AutoMate from Network Automation. Tools necessary to completely automate business processes. Note: Located in C:\Program Files\AutoMate 6\
    Automatic LiveUpdate SchedulerLALUSchedulerSvc.exeRelated to to the Symantec LiveUpdate service which updates your Symantec products periodically.
    Automatic Update Service (Automatic Update)Xwuapi.exeAdded by the W32/Codbot-AC WORM! Note: This worm\trojan file is found in the System32 folder.
    automatic updates for Microsoft WindowsXwuauclt.exe W32/Sdbot-DFD Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Allows remote access. Makes multiple system changes. Read links for additional information
    Automatisches LiveUpdateLALUSchedulerSvc.exeRelated to to the Symantec LiveUpdate service which updates your Symantec products periodically.
    AutoStore (autostore)Lbatch.exeRelated to NSi's AutoStore from Notable Solutions, Inc. Capture documents and securely saving the content in your business applications.
    AutoUpdate (Windows Server AutoUpdate) XWinupdate.exe Troj/GrayBrd-CF Note: Located in %windir%\system32 Read the link, allows remote access and logs keystrokes
    AutoUpdateDLAutoUpdateD.exeRelated to Xcelera_Echo_Lab_Management Medical services from Philips.
    Av Update Monitor (AvSvcMonitor)LAvMonitor.exe Avast
    avast! AntivirusLashServ.exeRelated to Avast AntiVirus
    avast! iAVS4 Control Service (aswUpdSv)LaswUpdSv.exeRelated to Avast AntiVirus
    avast! iAVS4 Mirror HTTP Server (aswHTTPMirror)Lhttpd.exeRelated to Avast! anti-virus software. Note: Located in \%Program Files%\Alwil Software\Management Tools\mirror\
    avast! Mail ScannerLashMaiSv.exeRelated to Avast AntiVirus
    avast! Management ServerLavEngine.exeRelated to Avast! anti-virus software. Note: Located in \%Program Files%\Alwil Software\Management Tools\mirror\
    avast! Web ScannerLashWebSv.exeRelated to AWIL Software http://www.avast.com/
    Avast32 Start as Service?avserver.exeseems to belong to Avast anti-virus software
    AVCore (SrvMain)Xavservice.exeAs of yet Unknown Worm, Trojan or Malware. The file (avservice.exe) is found in the Documents and Settings\All Users\Application Data folder.
    Aventail Connect (As32Svc)Las32svc.exeRelated to Aventail_Corp
    Aventail VPN Client (NgVpnMgr)Lngvpnmgr.exeRelated to VPN_Tunnel Manager from Aventail Corporation. Note: Located in \%WINDIR%\System32\
    Aventail VPN Client (qqhuouaeu8auaraa)Xrojkxz.exeAdded by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename.
    AVG Anti-Spyware GuardLguard.exe AVG Anti-virus product.
    AVG E-mail Scanner (AVGEMS)Lavgemc.exeRelated to AVG anti-virus
    AVG Firewall (AVGFwSrv)Lavgfwsrv.exeRelated to AVG_Firewall Note: located in C:\PROGRA~1\Grisoft\AVG7\
    AVG6 Service (AvgServ)Lavgserv.exeAVG 6 Anti virus