CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9466.22 of $21422.68
left sidedonated so farneed $11956.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 3876 entries and growing...
Last updated on 2008-05-09 18:10:24 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    U.S. Robotics Wireless LAN Service (wltrysvc)LWLTRYSVC.EXERelated to wireless networking for U.S. Robotics wireless network cards. Note: Located in \%WINDIR%\System32\
    UDP Sub Packet Classifier (UDPSPC)XMSUDPSPC.EXEAdded by the SDBOT.CBF WORM! Read the link, rootkit type stealth involved.
    UDS Environment Manager 5.0.14Lnodemgr.exeRelated to Forte_4GL_System from Sun Microsystems, Inc.
    UDS Environment Manager 5.1.3Lnodemgr.exeRelated to Forte_4GL_System from Sun Microsystems, Inc.
    UDS Repository Manager 5.0.14Lrpserver.exeRelated to Forte_4GL_System from Sun Microsystems, Inc.
    UDS Repository Manager 5.1.3Lrpserver.exeRelated to Forte_4GL_System from Sun Microsystems, Inc.
    UFD Command Service (UFDSVC)Lufdsvc.exeUSB flash drive driver
    Ulead Burning HelperLULCDRSvr.exeUlead DVD Burning Service
    Ulead Burning Helper (UleadBurningHelper)LULCDRSvr.exeRelated to Ulead_DVD_workshop allows the writing to DVD and CD media.
    Unicenter Message Queuing Server (CA-MessageQueuing)Lcam.exeRelated to Computer Associates, Inc.
    Unicenter Remote Control Host (rcHost)LrcHost.exeRelated to Unicenter_Remote_Control_Host From Computer Associates Note: Located in C:\BA_MGMT\TNGRCO\RCO60\
    Unicenter Software Delivery (SDService)LSDSERV.EXERelated to Unicenter Asset Management by Computer_Associates
    Unicenter_LocaliseOsrvany.exeMicrosoft Windows application which allows an executable to be run as a service. If you have installed this service, fine, otherwise investigage. Can be used to load Malware.
    Uninterruptible Power Supply (UPS)Lups.exepower management application from APC PowerChute.
    Universal Plug and Play Device Configuration (UPnP
    Configuration)
    Xupnp.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located C:\%WINDIR%\System32\
    Universal Printer NT ServiceXupnt.exe W32/Rbot-GKP
    Universal Serial Bus Control Protocol (pnpext)Xsmrs.exeAdded by the Troj/Bdoor-JD TROJAN!
    Unknown?wisptis.exe
    Unknown ownerLwtxregds.exepart of development software for microprocessors.
    Uno Installer (UnoInstallerService)LUnoInst.exeRelated to M-Audio_Uno device which is a gateway between usb and midi cables. Note: Located in \%Program Files%\M-Audio Uno\
    UnrealIRCdLwircd.exeRelated to UnrealIRCd
    updatesXservices.exeAdded by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\win32\ (XP/WinNT/2K)
    UpgradeToolTFTPService (crmtftp)Lcrmtftp.exeRelated to CiscoWorks_Small_Network_Management Note: Located in \%Program Files%\CISCOS~1\UPGRAD~1\
    UPnPDevServiceXupnpmngr.exeAdded by the Troj/Small-DMW TROJAN! Note: This worm\trojan is located in C:\Program Files\Common Files\PnpManager\
    UPnPServiceLUPnPService.exeRelated to UPnPService from Magix_AG Note: Located in \%Program Files%\Common Files\MAGIX Shared\UPnPService\
    UPSXups32.exe -vAdded by the W32/Mofei-H WORM!
    UPS - APC PowerChute plus (UPS)Lups.exepower management application from APC PowerChute.
    UPS - UPSentry Service (UPSentry_Smart)Lupsd.exeRelated ro Belkin_Bulldog Plus control software for the UPS (Uninterrupted Power Supply) via a serial or USB link. Note: Located in C:\Program Files\Belkin Bulldog Plus\
    UPS Service (CyberPowerUPS)Lupssrv.exeCyber Power PowerPanelPlus software. "In the event of a power outage, PowerPanelPlus Software automatically saves and closes all open files, and then shuts down the computer system in an intelligent and orderly manner."
    UPSMONServiceLUPSMON_Service.ExeRelated to UPSMON Power Management Software. Made by Powercom_USA This file is found in the Program Files\UPSMON folder.
    US30ServiceLUS30Service.exeRelated to Everstrike Software. Folder protection tool.
    USB DeviceXwin32usb.exehttp://www.sophos.com/virusinfo/analyses/w32forbotbq.html
    USB sks2drvr (sks2drvr)Xsks2drvr.sysAdded by the Backdoor.Haxdoor.G TROJAN! Note: This trojan file should be found in the System32 folder. The file sksdll.dll will be found with this one. Read the link, rootkit type stealth involved.
    USB sksDRVR2 (sksdrvr2)Xsksdrvr2.sysAdded by the Troj/Haxdoor-AL TROJAN! Note: This trojan file is found in the System32 folder.
    USBDeviceServiceLUSBDeviceService.exeRelated to USBDeviceService Module belongs to Sonic MyDVD or Sonic MyDVD LE. Note: Located in \%Program Files%\Sonic\DigitalMedia LE v7\MyDVD LE\
    USBest Service Zero (UTSCSI)LUTSCSI.EXERelated to USBest PQI Card Drive (USB). Note: Located in C:\%WINDIR%\System32 (XP/WinNT/2K)
    USBMateLusbmate.exeRelated to Belkin_USB products. Note: located in C:\Program Files\Belkin\Belkin Power Management Software\
    USBTest (USBTest)XUSBTest.sysAdded by the Troj/RKPort-Fam TROJAN! Note: This trojan file is found in the System32\drivers folder. Dropped by Troj/Lecna-D and Troj/Lecna-F Read the link, rootkit type stealth involved.
    USEndpointLTuner.exeRelated to Marimba_US_Endpoint solutions. Now owned by BMC Software, Inc. Note: Located in \%Program Files%\Marimba\Marimba US EndPoint Tuner\
    User Initialization (usrinit32)Xuserinit.exeAdded by the IRC/BackDoor.SdBot2.QV as detected by Avast AVG. TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ folder. Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.)
    User Mode Driver-ManagerXwdfmgrr.exeAdded by the W32/Sdbot-ZN WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    User Profile Hive Cleanup (UPHClean)Luphclean.exe uphclean.exe is a process belonging to Microsoft's User profile cleanup service. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems.
    user32Xuser32.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision.
    Userinit Logon Verification (UsrInitVerif)Xuserinit.exeAdded by the W32/Tilebot-EV WORM! Located in the Windows or Winnt folder.
    Users service for disk management requests (Logical
    Disk Manager Users Service)
    Xchkdsk32.exe Troj/Telemot-C Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K)
    UStorage Server ServiceLUStorSrv.exeRelated to OTi Imation Disk Manager II
    Utilità di pianificazione di LiveUpdate automaticoLALUSchedulerSvc.exeRelated to to the Symantec LiveUpdate service which updates your Symantec products periodically.
    uxtbsu94Xuxtbsu94.sys Troj/Agent-FYV Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K)
    uytghytrfdewzXmnso.exe Troj/PWS-ANX Note:Located in %Temp%
    uytghytrfdewzX(random characters).sys Troj/Lineag-AI Note: Located in %Temp%

    Engine Version 2.0 by CastleCops

    spacer spacer