Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

KEY:

  • L = Legit, O = Open to Debate, X = Malware/Bad

Name Process Details
X$sys$ariesaries.sysAdded by the SonyBMG_First4DRM ROOTKIT! Read the link rootkit type stealth involved. Thanks Sony.
L%NVSVC.name%nvsvc32.exeNVidia driver
L(AeXNSClientTransport)AeXNSClientTransport.exeRelated to Altiris_eXpress NS Database and SVS (Software Virtualization Services).
O(Any service name)srvany.exeThis utility allows running Windows NT2000XP applications as services. Can also be used to load Malw
X(ASCService)ascserv.exeAluria Spyware Eliminator Spyware remover a rogue program of dubious repute - for more information s
L(AuthSysSvc)SysSvcNt.exeRelated to Cox High Speed Internet Security Suite System Service. Note: Located in C:Program FilesCo
L(BackupExecAgentAccelerator)beremote.exeprocess that belongs to Backup Exec from Veritas http://www.liutilities.com/products/wintaskspro/pro
L(BackupExecDeviceMediaService)pvlsvr.exeRelated to Veritas Backup Exec and offers essential functionality for Backup Exec. http://www.proces
L(BackupExecNotificationServer)nsvr.exeRelated to Veritas Software backup tool.
L(BeatJamMusicStreamingServer)BeatJamHttpService.exeSee_BeatJam BeatJam Music Server Edition.
L(brmfbags)BrmfBAgS.exeRelated to Brother_BidiAgent Service products from Brother Industries. Note: Located in C:WINDOWSSys
L(clr_optimization_v2.0.50215_32)mscorsvw.exeRelated to Microsoft_NET_Framework NET Runtime Optimization Service.
L(CTXCPUUsync)ctxcpuusync.exeRelated to Citrix MetaFrame
L(default))SMAgent.exeSoundMAX Sound Device
L(DJSNETCN)DJSNETCN.exeRelated to Norton/Symantec AntiVirus.
L(ElnkFWPPService)EFWPPS~1.EXERelated to EarthLink_Firewall Process. Note: Located in C:Program FilesEarthLinkProtection Control C
L(ELNKService)ELNKServ.exeRelated to EarthLink_Protection_Control Center Service. Note: Located in C:Program FilesEarthLinkPro
L(FAH@C:+FAH+fah-service+FAH502-Console.exe)FAH502-Console.exeRelated to Stanford University - Folding@home is a distributed client computing effort by Stanford U
L(GenericHidService)HIDSERVICE.exeEnhanced Driver for Keyboards and Windows http://www.microsoft.com/whdc/device/input/w2kbd.mspx
L(https-admserv61)webservd-wdog.exeRelated to Sun_ONE_Web_Server from Sun Microsystems inc. Note: located in C:SunWebServer6.1inhttps
L(IBMCICSTransactionGateway)CTGSERVICE.EXERelated to IBM Corp.
L(ibmsmbus)ibmsmbus.exeRelated to SMBus on IBM computers. SMBus is the System Management Bus defined by Intel® Corporation
L(IBMWAS5Service - server1)wasservice.exeRelated to IBM WebSpere server.
L(LightScribeService)LSSrvc.exeLightScribe related to Hewlett Packard
L(McAfeeAntiSpyware)Msssrv.exeRelated to Network Associates Inc.
L(mi-raysat_3dsmax9_32)raysat_3dsmax9_32server.exeRelated to Autodesk_3ds_Max_9_3D_animation Create rich and complex design visualization. Note: Locat
X(non-roman characters)sServer.exeAdded by the Troj/Feutel-AB TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
L(odClientService)odClientService.exeRelated to Odyssey_Client for Fujitsu Siemens Computers. Note: Located in C:ProgramFujitsu Siemens C
L(OracleFormsServer-Forms60Server-OraForm)ifsrv60.exeRelated to Oracle Corp. Forms server.
L(OWSTimer)OWSTIMER.EXERelated to Microsoft_SharePoint Note: Located in C:Program Filesicrosoft OfficeOffice Files
L(PersonalSecureDriveService)PSDsrvc.EXERelated to Personal_Secure_Drive_Service http://www.infineon.com/ Service from Infineon Technologies
L(PinnacleSys.MediaServer)pmshost.exeRelated to Pinnacle_Systems Inc.
X(ProtectedContentSvc)services.exeAdded by Oscarbot.IV TROJAN! (backdoor ranky) Note: This worm rojan is located in C:%WINDIR%ETC comp
L(PRTG4Service)prtg4.exeRelated to Paessler Router Traffic Grapher - http://www.paessler.com/
X(random file name without extension)(random file name).sysAdded by the TROJ_ROOTKIT.AI TROJAN! Read the link rootkit type stealth involved.
X(Random) *See description*irjit.dllAdded by the Backdoor.CVM TROJAN! Note: This trojan file is found in the System or System32 folder.
L(RNADiagnosticsService)RNADiagnosticsSrv.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
X(rpcsvc)rpcsvc.exeAdded by the W32/Cuebot-I WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%WI
L(slapd-config52)ns-slapd.exeRelated to Sun_One directory server
L(SLEE_503_SERVICE)SLEE503.exeRelated to Steganos live Encryption Engine.
X(special characters) (myserver)myserver.exeAdded by the Troj/Dropper-BR TROJAN!
L(trlokom_rmhsvc)RMHSvc.exeRelated to Trlokom_Central_Management provides security management capabilities to help meet applica
X(wgavn)wgavn.exeAdded by the W32/Cuebot-K WORM! Located in the Windows or WinntSystem32 folder.
X(WMIDriverInc)wmiprvse.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
L(__AC_PROCESS_MGMT_DAEMON8)pmd8.exeActuate_Enterprise Reporting Applications for business intelligence analytic services
X*Microsoft Updatewuytc.exeunknown virus
X*Microsoft Updatewstcl.exeNo from Microsoft.
X*windows updatewuaucrlt.exeAdded by the W32.Spybot.HUR WORM!
X*windows updatewsctl.exemalware virus. possibly Win32.Rbot.gen
X*wuauclt.exerandomRelated to WORM_RBOT.AKU or variant.
X.NET Framework Servicesvchost.exeTrojan-PSW.Win32.Sagic.15 Virus
X.NET Framework Service (.NET Connection Service)svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
.NET Runtime Optimization Service v2.0.50215_X86
L3Com DMI Agent3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
O3dkeybd3dkeybd.exeUnknown... No answers on the net.
X64Bit architecture emulation (wrmsrvice)WRMSRVICE.SYSAdded by the TROJ_ROOTKIT.AG TROJAN! Read the link rootkit type stealth involved.
X80xFire daemon (80xFire)80xFire.exeAdded by the W32/Tilebot-BK WORM! Note: This worm rojan file is found in the Windows or Winnt folder
Laaksrvaaksrv.exeSpydex Advanced Anti keylogger
LAAMQDispatcherAAMQDispatcherService.exeCompuware Serversoftware
LABCSpell Helper ServiceABCSpellService.exeSpell checker (Ect ect) for Outlook Express. For more information Click_Here
XAbelAbel.exeSource: http://www.pestpatrol.com/PestInfo/C/Cain.asp
Xabhcopabhcop.sysAdded by the PigSearch Adware. Read the link rootkit type stealth involved.
XACacoustic.exeAdded by the SDBOT.CRN WORM! Read the link rootkit type stealth involved.
LAc Profile Manager Service (AcPrfMgrSvc)AcPrfMgrSvc.exeRelated to the Ac_Profile_Manager_Service installed as a part of ThinkPad Access Connections suite o
XAC-DNAME (AC-DNAME)acoustic.exeAdded by the SDBOT.CFN WORM! Read the link rootkit type stealth involved.
LAccenture Media Viewer (MediaViewer)streamviewerservice.exeRelated to Accenture_Media_Viewer
OAccess Remote PC Service 4.3rpcsetup.exeAccess_Remote_PC www.access-remote-pc.com remote access software. Legitimate but remote access could
LACMService (ACMService)Added by the ACM SPYWARE! **Note this is a commercial computer monitoring software
LACNUSvcacnupdatersvc.exeRelated to Accenture global management consulting technology services and outsourcing company Note:
LAcronis Scheduler2 Serviceschedul2.exehttp://www.acronis.com/homecomputing/products/trueimage/
LActiveXperts Network Monitor (AxsNmSvc)AxsNmSvc.exeAdded by ActiveXperts_Network_Monitor allows administrators to monitor the network for failures and
Actuate Process Management Daemon 8
LAd-Axis Clientaaclient.exeRelated to Lavasof's Ad-Aware SE Enterprise Edition 2005
LAdaptador de rendimiento de WMIwmiapsrv.exeWindows Management Instrumentation Performance Adapter Service Windows XP and 2003. Note: Located in
LAdaptec I/O Manager Serveriomgr.exeRelated to Adaptec product
LAdaptec RAID Remote Services Agentafaagent.exeRelated to Adaptec Inc.
LAdaptec Storage Manager Notifiernotify.exeRelated to Adaptec procuct
LAdaptec Web Serverarcpd.exeRelated to Adaptec procuct.
LAdaptecStorageManagerAgentStorServ.exeRelated to Adaptec Incorporated
LAdapter SwitchingRoamSvc.exeIntel Adapter Switching
LADF Installer Service (ADF Installer)AgentSVC.exeRelated to Citrix Installation Manager Service
LAdministracióe aplicacionesservices.exeSpanish Windows 2000 applications managing
LAdministrador de cuentas de seguridadlsass.exeSpanish Windows 2000 security accounts manager
LAdministrador de discosservices.exeSpanish Windows 2000 disks manager
LAdministrador de sesióe Ayuda de escritorio remotosessmgr.exeThis service manages and controls Remote Assistance
LAdministrador de utilidadesUtilMan.exeSpanish Windows 2000 utility manager
LAdobe Active File MonitorPhotoshopElementsFileAgent.exeRelated to Adobe photoshop.
LAdobe LM ServiceAdobelmsvc.exeRequired for PhotoshopCS
XAdobe Update Manager (Adobe3M)mshss.exeAdded by the Troj/Wollf-B TROJAN! Note: This worm rojan file is found in the System32 folder.
LAdobe Version Cue CS2VersionCueCS2.exeRelated to Adobe Products
LAdobeVersionCueVersionCue.exeAdobe related
LADSServiceADSSER~1.EXERelated to Aluria_Active_Defense_Shield Service. An EarthLink Co. Note: Located in C:Program FilesEa
LAdvantage Database ServerADS.EXERelated to Extended Systems' Advantage_Database_Server
LAEClientHostServiceAEClientHostService.exeRelated to GE_Fanuc_Automation enable you to act in real-time to optimize productivity and increase
XAge of Empires III: The WarChiefsageofempires.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:Windowsd
LAgente de directivas IPSEClsass.exeSpanish Windows 2000 IPSEC policy agent
LAgere Service (AgrSrvce)AgrSrvce.exeRelated to Proxim_Corp Client manager software associated with the ORiNOCO wireless LAN card.
XAIM (AIM)aim.exeAdded by the W32/Rbot-AGC or W32/Sdbot-BFX WORM! Read the link rootkit type stealth involved.
Xaim.exIEXPLORER.EXEAdded by the SDBOT.COW WORM! Read the link rootkit type stealth involved.
LAlertersvchost.exeNotifies selected users and computers of administrative alerts. If the service is stopped programs t
XAlfaCleanerServiceACServer.exeAlfaCleaner is now a stealth install using exploits on unpatched systems. Seen alongside RazeSpyware
LAlmacenamiento protegidoservices.exeSpanish Windows 2000 protected storage
LAltera JTAG Server (JTAGServer)JTAGServer.exeRelated to Altera Quartus II Software. Note: Located in C:alteraquartus50in
LAltiris Agent (AeXNSClient)AeXNSAgent.exeRelated to Alteris services. http://www.altiris.com
LAltiris Carbon Copy (CarbonCopy32)ccsrvc.exeRelated to Alteris services. http://www.altiris.com
LAltiris Client ServiceACLIENT.exeRelated to Altiris Inc.
LAltiris eXpress NS Client (AeXNSClient)AeXNSClient.exeRelated to Altiris_eXpress NS Database and SVS (Software Virtualization Services).
Altiris eXpress NS Client Transport
Aluria Security Center Spyware Eliminator Service
OAluria Spyware Eliminator ServiceASEServ.exeAluria Spyware Eliminator
XAL_ADSServiceAL_ADSService.exeAluria Spyware Eliminator Spyware remover a rogue program of dubious repute - for more information s
LAmadeus Automatic UpdateAutoUpdate.exeRelated to Amadeus powerful front office travel management tool. Note: Located in C:Program FilesAut
LAMD PowerNow! . Technology Service (GemServ)GemServ.exeRelated to Advanced Micro Devices Inc. - http://www.amd.com/
XAmpi32 (wdfmgr)msvcrt.exeAdded by the W32/Tilebot-Q WORM! Note: This worm file is found in the Windows or Winnt folder. Read
LAnalysis Server (MSSQLSERVER) (MSSQLServerOLAPService)msmdsrv.exeRelated to Microsoft_SQL_server suite.
LANIWZCSd ServiceANIWZCSdS.exeRelated to Alpha_Networks
XAntiSpyUltra (Zonelaps)vsmom.exeAdded by the W32/Tilebot-E WORM! Read the link rootkit type stealth involved.
LAntiVir Scheduler (AntiVirScheduler)sched.exeRelated to AntiVir antivirus program.
LAntiVir ServiceAVGUARD.EXEAntiVir antivirus
LAntiVir UpdateAVWUPSRV.EXEAntiVir Antivirus
Xantivirus32antivirus32.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot family. Note: This worm rojan is located in
LANTS Profiler serviceRedGate.Profiler.Service.exeRelated to Red Gate Software Ltd
LAnyPoint Service - Intel CorporationAPSERVER.EXEBelongs to Intel_Anypoint home networking system
LAOL Antivirus Update Service (aolavupd)aolavupd.exeRelated to AOL Antivirus Update Service.
LAOL Connectivity ServiceAOLAcsd.exeOwner: America Online. Description: AOL Connectivity Service - starts an automatic function that res
LAOL Connectivity Serviceacsd.exeAOL related
Xaol software (Aol Software)smss.exeAdded by the W32/Tilebot-FM WORM! Note: This is not the legitimate Windows process (Which is always
LAOL Spyware Protection Serviceaolserv.exeRelated to AOL
LAOL TopSpeed Monitoraoltsmon.exeAOL Topspeed
LApacheApache.exeApache Web Server Software
LApache2Apache.exeApache Web Server
LAPACS+ NIM32 (NIM32)Nim32.exeRelated to Siemens Energy & Automation Platform. Note: located in C:Program FilesProcessSuiteNIM
LAPC PBE Serverpbeserver.exeAPC PowerChute Business Edition Server (For UPS)
LAPC UPS Servicemainserv.exeRelated to American Power Conversion Corporation
LAppExpress Clientece.exeRelated to Endeavros Technology Inc and Microsoft_Encarta
XApplication Layer Gateway Manager (AppLayerGatewayMgr)alg.exeAdded by W32/Tilebot-EU WORM! Note: not to be confused with see_Here located in C:WindowsSystem32 th
LApplication Layer Gateway Servicealg.exeProvides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Internet Co
XApplication Layer Gateway Servicesalg.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XApplication Layer Gateway System (ALGS)algsys.exeAdded by the W32/Rbot-DDF WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%WI
XApplication State Service (AppSvc)apsvc.exeAdded by the W32/Rbot-FWW WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%WI
XAppMgmtsvchost.exe -k AppMgmtAdded by the Fuwudoor TROJAN!
LAppnNodeappnnode.exeRelated to IBM_Server Note: Located in C:WINDOWSsystem32Drivers
XARC Plugin (ARCPLUG)arci.exeAdded by the W32/Tilebot-HB WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
LArcaBit NetMonitor (ABNetMon)NetMonSV.exeArcaVir an AntiVirus software from Poland. A procuct of ArcaBit Sp. z o.o
LArchestrA Logger (aaLogger)aaLogger.exeRelated to ArchestrA Software architecture for the integration of your automation systems.
LArgos Billing DialogWorkstationMonitor.exeRelated to Argos_Billing_Dialog from Sepialine inc. Print Monitor. Note: Located in c:Program FilesS
LArGoSoft Mail Server Plusmailservernt.exeRelated to ArGo Software Design Mail Server
LAscent Capture Serviceacsvc.exeRelated to Kofax Image Products.
LASF AgentASFAgent.exeIntel Alert Standard Format Console - asfagent.exe is a part of a systems management suite bundled w
LAshampooDefragServiceaDefragService.exeRelated to Ashampoo Magic Defrag Utility
LASMAgentASMAgent.exeRelated to ASAP_eSMART Smart Asset Management tool.
XASNFTP daemon (ASNFTPD)AsnFtpd.exeAdded by the W32/Tilebot-BD WORM! Note: This worm rojan file is found in the Windows or Winnt folder
LASP.NET State Service (aspnet_state)aspnet_state.exeRelated to Microsoft Windows Operating System and is the ASP State Service.
LAsset Insight Client (AICLIENT)Aiclient.EXEAsset Insight from Tangram - http://castlecops.com/s1883-AICLIENT_EXE.html
LAsset Management AgentUMCSTUB.EXERelated to Unicenter Asset Management by Computer_Associates
LAsset Management Daemondtsslsrv.exeDisplay configuration software used by several manufacturers under differing names such as Image Tun
XAsus Motherboard Utility (Asus)asus.exeAdded by the WORM_SPYBOT.IY WORM! Note: This worm rojan is located in C:%WINDIR% folder.
LASWLSVCASWLSVC.exeRelate to the ASUS_Wireless_LAN_Card_Services
XAsynchronous Load Balance (ySvcHst)srvnst.exeAdded by ServiceThreadHandler.Process TROJAN! Note: located in C:WINDOWSSystem32
LAT Host Serviceatnthost.exeRelated to WebEx
LAtheros Configuration Serviceacs.exerelated to Atheros Wireless LAN
LAti HotKey PollerAti2evxx.exeATI Video Card Control Panel
LATI Smartati2sgag.exeATI Video Card Control Panel
XATIintergrated (ATIintergrated)atigraphics.exeAdded by the SDBOT.CRX WORM! Read the link rootkit type stealth involved.
LATK Keyboard Service (ATKKeyboardService)ATKKBService.exeRelated to ASUSTeK_Computer Inc. ASUS Keyboards and provides additional configuration options for th
LAutoComplete Serviceautocomp.exeTracks Eraser Pro
LAutodata Limited License ServiceADCDLicSvc.exeRelated to Autodata Limited
LAutodesk Data Management Job DispatchConnectivity.WindowsService.JobDispatch.exeRelated to Autodesk_Data_Management Web Server. Note: Located in C:Program FilesAutodeskData Managem
LAutodesk EDM ServerConnectivity.EDMWS.Server.exeRelated to Autodesk_Data_Management Web Server. Note: Located in C:Program FilesAutodeskData Managem
LAutodesk Licensing ServiceAdskScSrv.exeRelated to Autodesk Inc.
LAutodesk MapGuide® Server 6.3 (MapServer6.3)MapServer.exeRelated to Autodesk Inc.
LAutoMate 5 (AutoMate5)AutoMate5Svc.exeRelated to Automate from Network Automation Inc. A Task Service. Note: Located in C:Program Filesaut
LAutoMate 6 (AutoMate6)AMTS.exeRelated to AutoMate from Network Automation. Tools necessary to completely automate business process
LAutomatic LiveUpdate SchedulerALUSchedulerSvc.exeRelated to to the Symantec LiveUpdate service which updates your Symantec products periodically.
XAutomatic Update Service (Automatic Update)wuapi.exeAdded by the W32/Codbot-AC WORM! Note: This worm rojan file is found in the System32 folder.
LAutoStore (autostore)batch.exeRelated to NSi's AutoStore from Notable Solutions Inc. Capture documents and securely saving the con
LAv Update Monitor (AvSvcMonitor)AvMonitor.exeAvast
Lavast! AntivirusashServ.exeRelated to Avast AntiVirus
Lavast! iAVS4 Control ServiceaswUpdSv.exeRelated to Avast AntiVirus
Lavast! Mail ScannerashMaiSv.exeRelated to Avast AntiVirus
Lavast! Web ScannerashWebSv.exeRelated to AWIL Software http://www.avast.com/
?Avast32 Start as Serviceavserver.exeseems to belong to Avast anti-virus software
XAVCore (SrvMain)avservice.exeAs of yet Unknown Worm Trojan or Malware. The file (avservice.exe) is found in the Documents and Set
LAventail Connect (As32Svc)as32svc.exeRelated to Aventail_Corp
LAVG E-mail Scanneravgemc.exeRelated to AVG anti-virus
LAVG Firewall (AVGFwSrv)avgfwsrv.exeRelated to AVG_Firewall Note: located in C:PROGRA~1GrisoftAVG7
LAVG6 Serviceavgserv.exeAVG 6 Anti virus
LAVG7 Alert Manager Serveravgamsvr.exeRelated to AVG Anti-Virus.
LAVG7 Update Serviceavgupsvc.exeUsed by the AVG 7 Antivirus program to keep your definitions up to do date. Note : For more informat
LAvid SDM Service (AvidSDMService)AvidSDMService.exeRelated to Avid_SDM_Service from Avid Technology Note: Located in C:WINDOWSsystem32
LAvid StartupAvidStartup.exeAssociated with Avid_Digital_Media Products
Lavinitntavinitnt.exeRelated to Command AntiVirus for Windows Component made by Command Software Systems Inc. Which merge
XAVKernelAVKernel.exeRouge Anti-Virus Program. Made by WinSoftware Ltd. For more information on WinAntiVirus 2005 Click_H
LAVM FRITZ!web Routing Service (de_serv)de_serv.exeInstalled alongside DSL drivers from AVM Fritz's range of modem products. http://www.liutilities.com
LAVP Control Centre Serviceavpcc.exeKaspersky AntiVirus
XAVP UPDATE IONTERFACE A6 (avA6)AVA6.SYSAdded by the DLOADER.AJQ TROJAN! Note: This has also been seen using the Display name AVP update int
XAVPX TCP (avpx32)avpx32.sysAdded by the Troj/Haxdoor-AH TROJAN! Read the link rootkit type stealth involved.
XAVPX64 TCP (avpx64)avpx64.sysAdded by the Troj/Haxdoor-AH TROJAN! Read the link rootkit type stealth involved.
Lavsinc
Xavsuite (mssuite)msuite.exeAdded by the W32/Sdbot-ABC WORM! Read the link rootkit type stealth involved.
LAVSync ManagerAvsynmgr.exeFrom McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe) WebScanX (Webscanx.exe) V
XAVupdate service interface X2 (avupdate2)avupdate2.sysAdded by the Troj/Hanlo-A TROJAN! Note: This trojan file is located in the System32 folder.
LAvUpdSvcavupdsvc.exePart of Avast! anti-virus software
X“RDRIVâ€Â (rdriv)RDRIV.SYSAdded by the TROJ_ROOTKIT.E TROJAN! Read the link rootkit type stealth involved.
LB's Recorder GOLD Library General Service (bgsvcgen)bgsvcgen.exeRelated to B_H_A_Corp B' Recording Gold for CD/DVD burning and authoring software.
LBackup Exec 8.x Alert Server (BackupExecAlertServer)alertServer.exeRelated to Veritas Software backup tool.
Backup Exec 8.x Notification Server
LBackup Exec Agent Browser (BackupExecAgentBrowser)benetns.exeRelated to the Backup Exec application from Veritas http://www.liutilities.com/products/wintaskspro/
Backup Exec Device & Media Service
LBackup Exec Job Engine (BackupExecJobEngine)bengine.exeBackup service for Veritas Backup Exec. This program is essential in keeping backups up to date and
LBackup Exec Naming Service (BackupExecNamingService)benser.exeVeritas Software Corporation. This is the Backup Exec naming service which is needed in order to ach
Backup Exec Remote Agent for Windows Servers
LBackup Exec Server (BackupExecRPCService)beserver.exeRelated to Veritas Backup Exec. This program is essential in keeping backups up to date and should n
LBackupClientSvcBackupClientSvc.exeRelated to NovaNet_WEB NovaStor Corp. Online Backup Services.
LBackupLauncher)OLlaunch.exeRelated to Intuit Inc. QuickBook - http://www.intuit.com/
Xbcrcogqrkykomueyzrua5.exe
BeatJam Music Server - HTTP
LBeatJam Music Server - UPnP (BeatJamUPnPMusicServer)BeatJamUPnPService.exeSee_BeatJam Justsystem audio software BeatJam.
LBell & Howell Database Manager (dbmang)DBMANG.EXERelated to Bell_and_Howell
LBell & Howell Monitor Service (BHMonitorService)monitor.exeRelated to Bell_and_Howell
LBelMonitor Service (BelMonitorService)BANTMonitorSvc.exeRelated to Belarc inc.
LBES Client (BESClient)BESClient.exeRelated to BESClient by BigFix Inc
LBGS_SDServiceBGS_SDservice.exeRelated BMC Software Inc. - http://www.bmc.com/
Lbh611NT611SVC.EXERelated to Bell_and_Howell
LBigPond Broadband Cable LoginbpcService.exeTelstra's BIGPOND_BROADBAND_CABLE
LBiometric Authentication ServiceDpHost.exeRelated to DigitalPersona Inc.
LBitDefender Communicatorxcommsvr.exeRelated to bitdefender Antivirus
LBitDefender Desktop Update Servicelivesrv.exeUpdate service for BitDefender_Antivirus
LBitDefender Scan Serverbdss.exeRelated to Bitdefender antivirus
LBitDefender Virus Shieldvsserv.exeRelated to bitdefender (Virusshield)
Black Hole2005 Professional Version (Black Hole2005
Black Hole2005 Professional Version (Black Hole2005
LBlackICEblackd.exeBlack Ice firewall
LBlueSoleil Hid ServiceBTNtService.exeBlueSoleil is a Bluetooth device manager for Windows. Made by the IVT_Corporation The file associate
XBluetooth Notification Service (Btnfserv)btserv.exeAdded by the W32/Sdbot-CSD WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
LBluetooth Servicebtwdins.exeBluetooth Service
Lbobomomopanda platinium antivirus
LBoeing Permissions Elevatorelevate.exeThe Boeing Company (internal use)
LBoingo Monitor Servicewmonitor.exeBoingo's Free_Wi-Fi_Software
LBonjour ServicemDNSResponder.exeCreate's a network of computers and smart devices. Made by Apple Computer Inc. For more information
XBoolTern (BoolTern)svch0st.exeAdded by the W32/Tilebot-U WORM! Note: This (svch0st.exe) is not the legitimate Windows process (Whi
XBoonty GamesBoonty.exeBoonty_Games Used with Boonty box. Will not uninstall from Add/Remove programs. This is from their P
LBroadcom ASF IP monitoring service v3.0.1basfipm.exeRelated to Broadcom communications - hardware.
Brother BidiAgent Service for Resource manager
LBrother Popup Suspend service for Resource managerBrmfrmps.exeBrother printer related
XBrowsersvchost.exe -k BrowserAdded by the Fuwudoor TROJAN!
LBrSplServicebrsvc01a.exerelated to Brother Industries Ltd
LBT Modem LockModemLock.exeRelated to NetProtector Parental control.
LBUFFALO Wireless Configuration Service (bwcsrv)bwcsrv.exeRelated to BUFFALO_Wireless Configuration Service Note: Located in C:WINDOWSSystem32Drivers
LBuffalo Wireless Service (BWSVC)bwsvc.exeRelated to Buffalo_Wireless_Service The Multimedia Combo Set by SANSUN Industries. Note: Located in
LBullGuard Email Monitoring (BsMailProxy)svchost.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
LBullGuard File Monitoring (BsFileSpy)svchost.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
LBullGuard Firewall (BsFirewall)svchost.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
LBullGuard LiveUpdate (BGLiveSvc)BullGuardUpdate.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
LBullGuard Main (BGMainSvc)svchost.exeRelated to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
XBusinessC (BusinessContinuity)msstl.exeAdded by the SDBOT.CJR WORM! Read the link rootkit type stealth involved.
LBytemobile Web Configurator (bmwebcfg)bmwebcfg.exeRelated to Bytemobile Inc. Mobile Content Filtering.
OC-DillaCdaC11BACDAC11BA.EXEcopy protection software
LC-DillaSrvCDANTSRV.EXEC-Dilla License Management software from MacroVison
LCA ISafeisafe.exeRelated to Computer Associates virus software.
LCA License Clientlic98rmt.exeComputer Associates
LCA License Serverlic98rmtd.exeComputer associates
LCA Pest Patrol Realtime Protection Service (ITMRTSVC)ITMRTSVC.exeRelated to CA_Pest_Patrol Realtime Protection Service Note: Located in C:Program FilesCAPPRTin
LCachemanXPCachemanXP.exeCachemanXP Memory Manager
LCAILIcaili.exerelated to CarryIco Software installed by a flash card reader driver setup utility.
LCanon BJ Memory Card ManagerBjmcmng.exeCanon Bubblejet Memory Card Utility
LCanon Camera Access Library 8 (CCALib8)CALMAIN.exeCanon digital camera software that provides additional configuration options for the devices.
LCanon Driver Information Assist ServiceCnxDIAS.exeCANON Driver Information Assist Core Module. This file should be found in the Program FilesCanonDIAS
LCanon PIXMA iP6000D Memory Card ManagerPDUiP6000DMemCrdMgr.exeRelated to Canon PIXMA iP6000D Bubble Jet printer
LCapture Service (CaptureService)CaptureService.exeRelated to Impact_360 from Witness Systems Inc. Workforce management. Note: Located in C:WINDOWSsyst
LCarbon Copy Scheduler (CarbonCopyScheduler)schdsrvc.exeRelated to Alteris services. http://www.altiris.com
LCarboniteServicecarboniteservice.exeRelated to Carbonite_online_backup automatically backs up all the the files on your computer.
XCard Adapter (NETDown)smss.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This is not the legitimate Windows Proce
XCdsys (Cdsys)cdcd.sysAdded by the Troj/Agent-IA TROJAN! Note: This trojan file is found in the System32 folder.
CE-Infosys Security System (CE-Infosys Security
LCeEPwrSvcCeEPwrSvc.exeRelated to TOSHIBA and COMPAL ELECTRONIC INC.
LCentennialClientAgentCAgent32.exeRelated to Centennial UK Limited - http://www.centennial.co.uk/
LCentennialIPTransferAgentxferwan.exeRelated to Centennial UK Limited - http://www.centennial.co.uk/
LcFosSpeed System Service (cFosSpeedS)spd.execFos_Software Internet acceleration program related. Note: May be necessary for the software to work
Xchange me please (VIRUS)sysdat.exeAdded by the W32/Tilebot-L WORM!
OCharter High-Speed Security SuiteSERVIC~1.EXERelated to F-Secure Backweb application
Xchckntfschckntfs.exeAdded by the W32/Tilebot-EF WORM! Note: This worm rojan is located in C:%WINDIR%
Xchkext(chkext) (chkext)chkext.exeAdded by the W32/Sdbot-CRW WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
XChong3 Me (MlCR0SOFTS UPDATE)N0RTAN.EXEAdded by the SDBOT.CNM WORM! Read the link rootkit type stealth involved.
XChong3 Me (MlCR0SOFTS UPDATEe)lexplarer.exeAdded by the SDBOT.CWB WORM! Read the link rootkit type stealth involved.
Lcics.REGION1cicssvc.exeRelated to IBM Corp.
Lcics.REGION2cicssvc.exeRelated to IBM Corp.
Lcicssfs.SCMMC223cicssfssvc.exeRelated to IBM Corp.
Lcidaemoncidaemon.exeMicrosoft Indexing Service filter daemon
Lcidaemon.exeMicrosoft Indexing Service filter daemon
LCisco Configuration Service (CCS)ccs.exeRelated to Related to Cisco_Systems Note: Located in C:WINDOWSsystem32
LCisco Systems Inc. STC Agent (STCAgent)agent.exeRelated to Cisco Systems inc. SSL VPN Client Note: located in C:Program FilesCisco SystemsSSL VPN Cl
LCisco Systems Inc. VPN Servicecvpnd.exepart of Cisco VPN
LCitrix CPU Utilization Mgmt/CPU Rebalancer (CTXCPUBal)ctxcpubal.exeRelated to Citrix MetaFrame
LCitrix CPU Utilization Mgmt/Resource Mgmt (ctxcpuSched)ctxcpusched.exeRelated to Citrix MetaFrame
Citrix CPU Utilization Mgmt/User-Session Sync
LCitrix Print Manager Service (cpsvc)CpSvc.exeRelated to Citrix MetaFrame control Printer Management.
LCitrix SMA ServiceSmaService.exeRelated to Citrix MetaFrame
LCitrix Virtual Memory OptimizationCtxSFOSvc.exeRelated to Citrix MetaFrame Monitors all DLLs on a server to find where collisions are occurring
LCitrix WMI Service (CitrixWMIService)ctxwmisvc.exeRelated to Citrix MetaFrame
LCitrix XML Service (CtxHttp)ctxxmlss.exeRelated to Citrix MetaFrame
LCitrix XTE Server (CitrixXTEServer)XTE.exeRelated to Citrix MetaFrame
LCL500_510 Remote ServerKaNTSRV.exeRelated to Panasocic_Color_Laser_Printer server. Note: Located in C:PROGRAM FILESPANASONICREMOTE SER
LClient Network (CdmService)cdmsvc.exeRelated to Citrix MetaFrame maps client drives and peripherals for access in ICA sessions.
XClient Server Runtime Procescsrss.exeAdded by the WORM_SDBOT.BTI WORM! Note: This worm rojan is located in C:%WINDIR% folder. Malicious a
LClient Server Runtime Processcsrss.exeMicrosoft Client Server Runtime Process
XClient Server Runtime Service (csrss32)csr.exeAdded by the W32/Sdbot-AFM WORM! Note: This worm file is found in the Windows or Winnt folder.
LClient Update Service for Novellcusrvc.exeRelated to Novel server.
LCliente de seguimiento de vinculos distribuidosservices.exeSpanish Windows 2000 distributed links tracking client
LCliente DHCPservices.exeSpanish Windows 2000 DHCP client
LCliente DNSservices.exeSpanish Windows 2000 DNS client
XClients Server Runtime Processcsrss.exeAdded by the W32/Sdbot-CPF WORM! Note: This worm rojan is located in C:%WINDIR% This is not the legi
XClients Server Runtime Process (Windows Internet)csrss.exeAdded by the W32/Sdbot-CPF WORM! Note: This worm rojan is located in C:%WINDIR% folder.
Xclmss (Content List Management Sub System)clmss.exeAdded by the W32/Tilebot-AO WORM! Note: This worm file is found in the Windows or Winnt folder. Read
XCodecWINCODEC.EXEAdded by the SDBOT.CJO WORM! Read the link rootkit type stealth involved.
LCognos ReportNetcogbootstrapservice.exeRelated to Cognos_ReportNet Business Intelligence software. Note: located in C:Program FilesCognoscr
LColdFusion Graphing ServerJRun.exeRelated to MacroMedia_ColdFusion products. Made by MacroMediaInc.
ColdFusion Management Repository Server (ColdFusion
LColdFusion Management ServiceCANamingAdapter.exeRelated to MacroMedia_ColdFusion products. Made by MacroMediaInc.
LColdFusion Monitoring Service (ClusterCATS Service)ccmgr.exeRelated to MacroMedia_ColdFusion products. Made by MacroMediaInc.
LColdFusion MX Application Serverjrunsvc.exeRelated to Macromedia Cold Fusion software.
LColdFusion MX ODBC Serverswstrtr.exeRelated to Macromedia Cold Fusion software.
LCOM HostcomHost.exeRelated to Norton/Symantec Internet Security
XCOM Message Transfer (mscommt)svchost.exe -k mscommtAdded by the Troj/Dbit-A TROJAN!
XCOM+ Component Service (COMCSVC)winmgnt.exeAdded by unknown malware the file winmgnt.exe may be a Serv-U FTP server used to download other mali
XCOM+ Messagessvchosts.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XCOM+ System Service (COMSS)SSMS.EXEAdded by unknown malware. File location is in the System32 folder.
XCOM+ System Service (DLLHOST)dllhost.exeAdded by the Backdoor.Win32.SdBot.xd as identified by Kaspersky TROJAN! Note: This worm rojan is loc
XCommand Service (cmdService)command.exeAdware
LCommServerCommSvr.exeRelated to the HiPath 1220 digital PBX system from Siemens. For more information Click_Here File loc
LComodo Application Agent (CmdAgent)cmdagent.exeRelated to Comodo_Firewall from Comodo. Note: Located in C:Program FilesComodoFirewall
LCompaq Advisorcompaq-rba.exeRelated to Compaq
LCompaq DMI Web AgentWebDmi.exeRelated to Compaq Computer.
LCompaq Local Alertercpqalert.exeRelated to Compaq Computer. Allows for fault performance and configuration management. Recommended f
OCompaq Remote Diagnostics Enabling AgentCpqdfwag.exeRelated to Compaq diagnostics utility.
XCompatibil)svchost.exeAdded by the Troj/Keylog-AT TROJAN! Note: This is not the legitimate Windows process svchost.exe (Wh
LCompuware Open Servercwjboss.exeCompuware Serversoftware
Xcomreplcomrepl32.exeAdded by the W32/Rbot-DNH WORM! Note: This worm rojan is located in C:%WINDIR% folder.
Xcomreplcomreplsvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XConfig Loaderscvhost.exeseveral Agobot variants
LConfigFree ServiceCFSvcs.exeToshiba related
XConfiguration Loader (bF)wincrt32.exeVirus and Trojan tools. http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.
XConfiguration Loadingsvchos1.exeseveral Agobot variants
LConnected Agent Service (AgentSrv)AgentSrv.EXERelated to Connected Corporation. - http://www.connected.com/
LConnected LauncherCBlaunch.exeConnected backup software
LConnected RegCapCBRegCap.EXEConnected backup software
XConnection Resewebadmin.exeW32/Forbot-FY adds this with a display name of Website Administrator Info.
LContent Index servicecisvc.exeMicrosoft Content Index service
LContent Monitoring ToolmsCMTSrvc.exeCompaq CMTS
LContentProtect (CwCpSvc20)cwsvc.exeRelated to ContentWatch Parental Control Internet Filter.
LContivity VPN ServiceExtranet_serv.exeRelated to Novel server.
LContour Shuttle Device Engine (ShuttleEngine)ShuttleEngine.exeRelated to Contou_Design
LCOSIDS_TBTbMux32.exeRelated to http://www.transaction.de/
Ocostemartinr.coste@neuf.frantivirus
Cox High Speed Internet Security Suite System Service
Xcpanelx (Microsoft Control Panel)cpanelx.exeAdded by a variant of the W32/SDBOT WORM! Note: This worm file is found in the Windows or Winnt fold
Lcpqdmicpqdmi.exeCompaq version of the Desktop Management Interface
LCQG Installation Servicecqginsts.exeRelated to CQG Inc. CQG provides extensive historical data online for charting and technical analysi
Lcrautocrauto.exeBackground task of the Paragon Encrypted Disk software which enables you to have encrypted virtual h
LCreative Labs Licensing ServiceCreativeLicensing.exeRelated to Creative Labs Licensing Service. Note: located in C:Program FilesCommon FilesCreative Lab
LCreative Service for CDROM AccessCTsvcCDA.exeCreative Service for CDROM Access
Xcrss32.execrss32.exeAdded by the W32/Tilebot-GT WORM! Note: This worm rojan is located in C:%WINDIR%
LCrypkey Licensecrypserv.exeCrypKey Software Licensing System from Cobalt Systems
LCryptainer service (ssoftservice)ssoftsrv.exeOwner:Cypherix Cypherix Encryption Software
XCryptic Protected Storage (CryptProtectedService)cpstorage.exeAdded by the W32/Tilebot-HO WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XCryptographic Engine (EngSvc)csvc.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm rojan is located in
LCrystal Cache Servercacheserver.exeCrystal Decisions Cache Server
LCrystal Event ServerEventServer.exeCrystal Decisions Event Server
LCrystal Input File Repository Serverinputfileserver.exeCrystal Decisions File Repository Server
LCrystal Management ServerCrystalMS.exeCrystal Decisions Management Server
LCrystal Output File Repository Serveroutputfileserver.exeCrystal Decisions Output File Repository Server
LCrystal Page Server (pageserver)pageserver.exeRelated to Crystal Decisions Page Server. Now owned by Business_Objects Note: Located in C:Program F
LCrystal Program Job ServerProgramServer.exeCrystal Decisions Job Server
LCrystal Report Application Servercrystalras.exeCrystal Decisions Report Application Server
LCrystal Report Job ServerJobServer.exeCrystal Decisions Report Job Server
LCrystal Web Component Server (WebCompServer)WebCompServer.exeRelated to Crystal Decisions Enterprise software. Now owned by Business_Objects Note: Located in C:P
XCTI Central Managementcti.exeLowers IE security settings
LCurtains for Windows System Service (CurtainsSysSvc)CurtainsSysSvcNt.exeRelated to Authentium Inc. http://www.authentium.com/
LCVSNT 2.5.01.1927 Dispatch service (cvsnt)cvsservice.exeRelated to CVS_on_NT service Machines. From March Hare Software. Note: Located in C:Program FilesCVS
LCVSNT 2.5.01.1927 locking service (cvslock)cvslock.exeRelated to CVS_on_NT service Machines. From March Hare Software. Note: Located in C:Program FilesCVS
LCWAFAdminControllerCWAFAdminController.exeCompuware Seversoftware
LCWAFAdminMonitorCWAFAdminMonitor.exeCompuware Serversoftware
LCWAFEventRoutercwafservice.exeCompuware Serversoftware
LCWAFNotesServiceCWAFNotesService.exeCompuware Serversoftware
LCWAFReportSchedulerCWAFSchedService.exeCompuware Serversoftware
LCWAFRmiRegistryCWAFRmiRegistry.exeCompuware Serversoftware
LCWShredder ServiceCWShredder.exeCWShredder tool from Trend Micro.
LCXPT_Service - Cyberspace Headquarters LLCwcservice.exeRelated to Internet_Security Suite from COSMI Corp.
LCyberArmor Run Servicecasvc.exeCyberArmor an Enterprise Class Personal Firewall
LCyberhawkCHService.exeRelated to Cyberhawk from Novatix Protects against Viruses Spyware Identity Theft. Note: Located in
LCyberLink Background Capture Service (CBCS) (CLCapSvc)CLCapSvc.exeRelated to CyberPower Systems Inc. - http://www.powercinema.com/english/index.jsp
LCyberLink Media Library ServiceCLMLServer.exeRelated to CyberPower Systems Inc. - http://www.powercinema.com/english/index.jsp
LCyberlink RichVideo Service(CRVS) (RichVideo)RichVideo.exeCyberLink RichVideo is an advanced technology designed to save precious video editing time.
LCyberLink Task Scheduler (CTS) (CLSched)CLSched.exeRelated to CyberPower Systems Inc. - http://www.powercinema.com/english/index.jsp
LCYGWIN cygserver (cygserver)cygrunsrv.exeRelated to Cygwin_RedHat powerful tools to assist developers in migrating applications from UNIX®/Li
LCypressLinkCypressLinkService.exeRelated to Related to CypressViewer from Siemens. Medical software. Note: Located in C:Program Files
LD-Link IP servellience Launcher (D-Link_ST3402)Launcher_DL.exeRelated to D-link Software. Note: Located in C:Program FilesD-LinkIP surveillance
LDameWare Mini Remote ControlDWRCS.EXERelated to DameWare Development
LDameWare NT Utilities 2.6 (DNTUS26)DNTUS26.EXERelated to Dameware_NT_Utilities program that allows remote access and control of a computer. This i
LdashsvcDashsvc.exeMotion computer pen interface. :Owner: Motion Computing Inc.
LData Protector InetOmniInet.exeRelated to Hewlett-Packard OpenView OmniBack II
LDatakey's Log Service (DkLogger)DkLog.exeRelated to Datakey_Electronics_Inc Products. Made by Datakey Inc. This file is found in the System32
LDatakey's Token Service (DkTknSrv)dkcktkn.exeRelated to Datakey_Electronics_Inc Products. Made by Datakey Inc. This file is found in the System32
LDataSvrDataServer.exeRelated to Wave_Systems_Corp An identity protection application that is configured to use digital ce
LDatax Sagef Server (SagefServer)Datax.Sagef.Server.exeRelated to DataX Server. Note: Located in C:Program FilesDataxServidor Sagef
LDB2 - DB2 (DB2)db2syscs.exeRelated to IBM Corp.
LDB2 - DB2DAS00 (DB2DAS00)db2syscs.exeRelated to IBM Corp.
LDB2 Governor (DB2GOVERNOR)db2govds.exeRelated to IBM Corp.
LDB2 JDBC Applet Serverdb2ccs.exeUnknown.Found in an IBM application.
LDB2 JDBC Applet Server (DB2JDS)db2jds.exeUnknown found in a IBM application.
LDB2 Remote Command (DB2REMOTECMD)db2rcmd.exeRelated to IBM Corp.
LDB2 Security Server (DB2NTSECSERVER)db2sec.exeRelated to IBM Corp.
LDB2DAS - DB2DAS00db2dasrrm.exeIBM DB2 related. The DB2 Admin Server process. This process supports both local and remote administr
LDcfssvcdcfssvc.exeAssociated with digital cameras and can cause problems which disappear if disabled. If this program
XDcom Helper (DcmHlp)dcmhelp.exeAddec by the W32/Sdbot-AJA WORM! Note: This worm rojan is located in C:%WINDIR%
XDCOM PC Service (mspcdcom)mspcdcom.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
LDCPFLICSDCPFLICS.exeRelated to: Discreet Turbosquid/3dsmax Plugin Protection
LDCS LoaderOPHALDCS.EXEPrint spooler service for Oki_Data printer
Xdcznetv2 (dcznetv2)dcznetv2.exeAdded by the W32/Tilebot-O WORM! Note: This worm/trojan file is found in the Windows or Winnt folder
LDDE de rednetdde.exeSpanish Windows 2000 network DDE
XDebug Config Systemlrsys.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
LDeepsight ExtractorExtractorService.exeSymantec Security Analyser
LDeepSight Extractor CC ServiceccExtractorService.exeRelated to Symentec corp.
LDeepSight Extractor Service for NPF03ExtractorServiceNPF03.exeSymantec Security Analyser
LDeepSight Extractor Service for NPF04ExtractorServiceNPF04.exeSymantec Security Analyser
Defragmentation Management Handler (FAT
XDefragmentation)dfrgfat32.exeAdded by the W32/Codbot-AB WORM! Note: This worm rojan file is found in the System32 folder.
LDefWatchdefwatch.exeSymantec Antivirus related
LDell Printer Status Database (DLSDB)DLSDBNT.EXERelated to Dell_Printers Note: Located in C:Program FilesDell PrintersAdditional Color Laser Softwar
LDell Printer Status Watcher (DLPWD)DLPWDNT.EXERelated to Dell_Printers Note: Located in C:Program FilesDell PrintersAdditional Color Laser Softwar
LDellDmiDellDmi.exeRelated to Dell's OpenManage software.
LDEventAgentEventAgt.exeRelated to: Dell OpenManage and used for server management.
XDEVICEMAPDEVICEMAP.SYSAdded by the TROJ_ROOTKIT.O TROJAN! Read the link rootkit type stealth involved.
LDF5ServDF5Serv.exeBy Faronics Corporation
Xdgtsys (dgtsys)dgtsys.sysAdded by Adware-DigitalNames
XDHCP Client (Ulead Service)dhcpclient.exeAdded by the W32/Codbot-AG WORM!
LDiagnostic Facility COM Server (CdfSvc)CdfSvc.exeRelated to Citrix MetaFrame Presentation Server
LDiamondCS Process Guard Service v3.000dcsuserprot.exeprocess guard
LDigiCtrldigisc.exeRelated to Matrox_Electronic_Systems DigiSuite Service Control
LDigidesign MME Refresh Service (DigiRefresh)MMERefresh.exeRelated to Digidesgin Protocols Refreshes your midi ports on the 002(R) (the 002R is a hardware audi
LdigiSPTIServicedigiSPTIService.exeRelated to Pro_Tools digital audio workstation (DAW) technology.
LDigitizer Service (Digitizer)digtizer.exeRelated to Digitizer_Service from Wacom Tech. Note: Located in C:%WINDIR%System32 (XP/WinNT/2K)
LDimension4D4.exeRelated to Dimension4 Thinking Man Software - Note: Located in C:Program FilesD4
Xdirect sound rss (dsrss)dsrss.exeAdded by the Backdoor.SdBot.xd as identified by ewido. Note: This worm rojan is located in C:%WINDIR
LDirectUpdate engineDUService.exeDirect Update - registers dynamic IPs to a fixed hostname
LDirectX Debug Service (DXDebug)DXDebugService.exeRelated to the Microsoft DirectX SDK and offers a debug facility for this development suite.
XDirectX DriversD1rectX.exeAdded by the SDBOT.CIF WORM! This should not be confused with Microsoft DirectX files. Read the link
XDirectX Graphics (dxdmain)dxdmain.exeAdded by the W32/Codbot-O WORM!
XDirectX Service (DirectService)directx.exeAdded by the Troj/Crybot-B TROJAN! This should not be confused with Microsoft DirectX files. Note: A
Xdirectx.exedirectx.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
LDIRECWAY Webcast (DPC_SRV_WEBCAST)dpcproxy.exeRelated to DIRECWAY Webcast - http://www.directway.com/
LDirMS_DefragmentationDirmsService.exeRelated to DirMS_Defragmentation from DIRMS. Allows the user to defragment hard drives with a user-f
LDisk Management Service (VxSvc)VxSvc.exeRelated to Dell Open Management system. http://www.what-process.com/process-info.aspx?p=VxSvc.exe
XDisk Manager Users Service)chkdsk32.exeAdded by the Troj/Telemot-A TROJAN! Note: This trojan file is found in the System32 folder.
XDisk Monitor Services (DiskMon32)svchost.exe -k dmonAdded by the Hanmon TROJAN! Note: This trojan file is found in the System32 folder.
LDiskeeperDkService.exeExecutive Software's Diskeeper (Defragmenter)
XDistributed Link Tracking Extensionskernel32dll.exeAdded by the W32/Myfip-I worm.
XDistributed Link Tracking Service (TrkWksvc)TrkWksvc.exeAdded by the W32.Toxbot.B WORM!
Xdistributed.net clientiosdt.exeYou have a Trojan virus on your PC . IOSDT.EXE is its main file. You most probably tried to download
Ldistributed.net client (dnetc)dnetc.exeClient part of the dstributed.net general-purpose distributed computing project.
LDK2 Network Server (DNServer32)DNSrv32.exeRelated to DESkey_Hardware reliable and flexible means to protect your software from piracy. Note: L
LDkeySyncsyncservice.exeRelated to GE_Security_Supra Note: Located in c:program filesge security supra
Ldlbt_devicedlbtcoms.exeSomething by Dell Computers
Ldlbu_devicedlbucoms.exeRelated to Dell computers
Ldlbx_devicedlbxcoms.exeRelated to Dell computers.
Ldlcc_devicedlcccoms.exeDell printer related. File is found in the System32 folder.
Ldlcj_devicedlcjcoms.exeRelated to Dell Photo AIO Printer may be the driver.
XDLL Manager (mswindll)mswindll32.exeAdded by the W32/Tilebot-AQ WORM! Note: This worm rojan file is found in the Windows or Winnt folder
LDLT - Dell Computer CorporationDLT.exeRelated to Dell OpenManage system management software
LDM Primer (DMPrimer)dmprimer.exeRelated to Unicenter_Remote_Control_Host From Computer Associates Note: Located in C:Program FilesCA
LDM1ServiceDM1Service.exeRelated to OLYMPUS Corporation
Ldmisrvdmisrv.exeAppears to be part of Dell OpenManage_Client_Instrumentation Software.
Xdmserversvchost.exe -k dmserverAdded by the Fuwudoor TROJAN!
XDNS Server (DNS Server)svchost.exeAdded by the Troj/Feutel-Y TROJAN! Note: This is not the legitimate Windows Process. (Which is found
LDNS4Me Client (DNS4MeClient)DNS4MeClient.exeRelated to Dynamic_DNS_service from RhinoSoft.com that makes it possible for you to start hosting yo
LDNSexitdnsexit_srv.exeProvides reliable DNS Services free of charge to top level domains for both business and internet us
LdnWhoDispdnwhodisp.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
LDocumentum Desktop Component InstallerDcComponentInstaller.exeRelated EMC_Corporation Content management software.
LDownload Manager Lite Service (DownloadManagerLite)dm.exeRelated to Net_Cable TV. Note: Located in C:Program FilesNCTVin
XDragon Age - Biowaredragonage.exeAdded by the W32/Vanebot-M WORM! Note: This worm rojan is located in C:%WINDIR%System32 dllcache (XP
Xdrivermsiisdrv.exeAdded by the Backdoor.Isen.Rootkit TROJAN! Read the link rootkit type stealth involved.
XDriver Cache (Driver Cache)Driver Cache.exeAdded by the Troj/Feutel-S TROJAN!
LDSDM de DDE de rednetdde.exeSpanish Windows 2000 network DDE DSDM
LDTS Agenttngdta.exeComputer Associates Data Transport Service Agent
LDTS Browsertngdoba.exeComputer Associates Data Transport Service Browser
LDTS Metrics Gatherertngdtmg.exeComputer Associates Data Transport Service
?DUN Manager Servicedmservc.exeDial-up and routed networking enhancement - http://www.magsys.co.uk/dunman/
XDUN_SERVICE3dun3.exeAdded by the Trojan.Sokiron TROJAN!
LDVD-RAM_ServiceDVDRAMSV.exeDVD driver
XDVDrealm (DVDrealm)DVDrealm.sysAdded by the Troj/Rootkit-AA TROJAN! Read the link rootkit type stealth involved.
LDvpApidvpapi.exeCommand Software Systems Inc. - anti Virus
Xdx32hhecdx32hhlp.exeAdded by the Nemog TROJAN!
XDynamic Library Host (DLLHOSTS)dllhost.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: Note: This worm rojan is loca
XDynamicHost (DLHOST)dlhost.exeAdded by the W32/Tilebot-BO WORM! Note: This worm file is found in the Windows or Winnt folder.
EarthLink Firewall Process Path Service
EarthLink Protection Control Center Service
LEasy File & Folder Protector (ACDService)EFPAP.exeEasy_File_&_Folder_Protector Deny access to certain files and folders or to hide them securely from
LEC2007 Service 1.40 (EC2007Service)ec27ser.exeElectronic_Chart_Display_and_Information System (ECDIS). Data production for Electronic Navigational
XECA (cpanel)javapanel.exeAdded by the W32/Tilebot-Y WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
LeEye Application Bus (eeyeevnt)eeyeevnt.exeRelated to eEye Digital Security
LeEye Retina Engine (RetinaEngine)RetinaEngine.exeRelated to eEye Digital Security
LElectronic Arts Licensing ServiceEA Licensing Service.exeRelated to EA_Licensing_Service.exe is installed with some games from Electronic Arts. It is require
LEloSystemServiceEloSrvce.exeElo TouchSystems Inc. - http://www.elotouch.com
LEloTouchscreenEloTouch.exeRelated to Elo TourchSystems Inc.
Xelpow_spyelpow_spy.sysAdded by the ElpowKeylogger Spyware! Note: This file is found in the System32drivers folder. Read th
LEMCliSrvEMCliSrv.exeRelated to Express_Metrix PC inventory and software usage tracking. Note: Located in C:WINDOWSsystem
XEnables Java Support (Java)winjava.exeAdded by the W32/Codbot-AA WORM! Note: This worm/trojan file is found in the System32 folder. (May u
XEnables Javascript Support (Javascript)javascript.exeAdded by the W32/Codbot-V WORM!
LEncryption Serviceencsvc.exeRelated to Citrix MetaFrame
Xend task (Taskend)Taskend.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
LEntertainmentIcVzMon.exeRelated to Sony_VAIO computers.
LEntrust Login Interface (ELIService)etlisrv.exeRelated to Entrust Login Interface service Made by Entrust Technologies Ltd. This file is found in t
LENUFF Server (ENXPSVR)ENSERVS.EXEEnuff Parental Control Software by Akrontech
LENUFF XP Service (ENXPSVC)CVSEXPSS.EXEEnuff Parental Control Software by Akrontech
LEnvironment (WS2IFSL)ws2ifsl.sysGuardMon is a commercial spyware program designed to monitor all forms of user activity on a compute
LEPrint III ServiceLPSVS03N.EXERelated to LEADTOOLS_ePrint From Lead Tech. Perform additional processing to your print job before s
XEPS Printer DriverEPSONSYS.SYSAdded by the Goldun.I TROJAN! Note: This trojan file is found in the System32 (NT/2000/XP) folder. A
LEpson Printer Status Agent (StatusAgent)SAgentNT.exeRelated to Epson_Printer Status agent. Note: Located in C:Program FilesCommon FilesEPSONEBAPI
LEPSON Printer Status Agent2SAgent2.exedetects and configures an Epson Printer Port where applicable
LEpson Printer Status Agent4 (StatusAgent4)SAgent4.exeRelated to Epson Corp.
LEPSON V3 Service2(02) (EPSON_PM_RPCV2_02)E_S00RP2.EXERelated to the EPSON Status Monitor 3
LEPSON V3 Service2(03) (EPSON_PM_RPCV2_01)E_S00RP1.EXERelated to the EPSON Status Monitor 3
LEpsonBidirectionalServiceeEBSVC.exeRelated to Epson printers.
LeScan Monitor Serviceavpm.exeeScan Antivirus
LeScan Server-UpdaterTRAYSSER.EXEeScan antivirus
LEscritorio remoto compartido de NetMeetingmnmsrvc.exeSpanish Windows 2000 Netmeeting remote desktop sharing service
LEsker FTPD (ftpds)WFTPDSNT.EXERelated to Esker software
LEsker License Control (EskerLicenseControl)eslcbcst.exeRelated to Esker License control
LEsker LPD (lpds)WLPDSNT.EXERelated to Esker software
LEsker NFSD (nfsds)WNFSDSNT.EXERelated to Esker software
LEstacióe trabajoservices.exeSpanish Windows 2000 workstation
XET54FGET54FG.SYSAdded by the TROJ_ROOTKIT.N TROJAN! Read the link rootkit type stealth involved.
LeToken Notification Service (ETOKSRV)eTSrv.exeRelated to eToken Notification Service from Aladdin Knowledge Systems Ltd. Authentication and passwo
LeTrust Antivirus Job ServerInoTask.exeAssociated with eTrust Antivirus/InoculateIT
LeTrust Antivirus Realtime ServerInoRT.exeRelated to eTrust's AntiVirus Internet Security solution.
LeTrust Antivirus RPC ServerInoRpc.exeAssociated with eTrust Antivirus/InoculateIT
LEvent Log WatchLogWatNT.exeComputer Associates
XEvent Monitor (evmon)spoolcll.exe -netcvsAdded by the W32.Spybot.IVQ WORM!
LEvtEngEvtEng.exeRelated to Intel Corporation http://www.what-process.com/process-info.aspx?p=EvtEng.exe
Lewido anti-spyware 4.0 guardguard.exeRelated to ewido_suite Note: located C:Program Filesewido anti-spyware 4.0/
Lewido security suite controlewidoctrl.exeRelated to ewido networks
Lewido security suite guardewidoguard.exeRelated to ewido networks
LExaminador de equiposservices.exeSpanish Windows 2000 computers browser
LExecView Communication Module (ECM) (ECM Service)ECM.exeRelated to VERITAS_ExecView
LExten. controlador Instrumental de admon. de Windowsservices.exeSpanish Windows 2000 windows management instrumentation drive extension
Extended Windows Security (Microsoft Extended Windows
XExterntelecomextel.exeAdded by the W32/Sdbot-AAX WORM! Read the link rootkit type stealth involved.
LF-Prot Antivirus Update Monitorfpavupdm.exeF-Prot anti-virus background scanner by F-Risk Software. http:/
LF-Prot Antivirus Update Monitorfpavupdm.exeRelated F-Prot Antivirus Update Monitor by FRISK_Software_International
LF-Secure 2006 (BackWeb Plug-in - 4476822)SERVIC~1.EXERelated to F-Secure_Antivirus Made by F-Secure Corp. This File should be found in the Program FilesF
LF-Secure Anti-Virus 2005 (BackWeb Plug-in - 4476822)SERVIC~1.EXERelated to F-Secure_Antivirus Made by F-Secure Corp. This File should be found in the Program FilesF
LF-Secure Anti-Virus Firewall Daemonfsdfwd.exeRelated to F-Secure Corporation.
LF-Secure Automatic Update Agent (FSAUA)fsaua.exeRelated to F-Secure Corporation. Note: Located in C:Program FilesF-SecureFSAUAprogram
OF-Secure BackWeb LAN Accessfsbwlan.exeRelated to F-Secure_BackWeb LAN Access. This File should be found in the Program FilesF-Secure Inter
LF-Secure Gatekeeper Handler Starterfsgk32st.exeRelated to F-Secure Anti-Virus Prog.
LF-Secure HTTP Server (fshttps)fshttps.exeF-Secure Corporation http://www.what-process.com/process-info.aspx?p=fshttps.exe
LF-Secure Management AgentFSMA32.EXERelated to F-Secure Anti-Virus Prog.
LF-Secure Network Request BrokerFNRB32.EXERelated to F-Secure_Anti-Virus software. This File should be found in the Program FilesF-SecureCommo
LFactoryTalk Diagnostics CE Receiver (RNADiagReceiver)RNADiagReceiver.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
FactoryTalk Diagnostics Local Reader
LFast Track Installer (FastTrackInstallerService)GBInst.exeRelated to Fast_Track_USB from M-Audio. Note: Located in C:Program FilesM-Audio Fast Track
FastUserSwitchingCompatibil (Fast User Switching
XFear Service (FSVC)fear32.exeAdded by the W32/Tilebot-T WORM! Note: This worm file is found in the Windows or Winnt folder.
XFIFA WORLD CUP 2007fifa2007.exeAdded by the W32/Spybot-MQ WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache(XP/W
LFile and Folder Protectorffpsrv.exeRelated to SoftHeap.Com a software shop of Atlantic Coast PLC http://www.softheap.com/
LFileCheckerfilechecker.exeRelated to FileChecker from Javacool software. Watches important system files for changes modificati
LFileZilla Server FTP server (FileZilla Server)FileZilla Server.exeRelated to FileZilla A FTP and SFTP client for Windows from SourceForge.net
LFirebird Guardianfbguard.exeFirebird Guardian
LFirebird Serverfbserver.exeFirebird Database Server
XFireDaemon Service: events (events)FireDaemon.EXEReported by Ewido security suite as Backdoor.SdBot.nj. Note: FireDaemon is a legitimate product that
XFireDaemon Service: rundll (rundll)FireDaemon.EXEReported by Ewido security suite as Backdoor.SdBot.nj. Note: FireDaemon is a legitimate product that
Xfirefox auto updatefirefox.exeAdded by the W32/Tilebot-DN WORM! Note: Located in C:%WINDIR%
XFirewall service (FWSvc)FWSvc.exeRelated to WinAntiVirus Pro - rogue antivirus
LFix-It Task Manager (mxserver)mxserver.exeRelated to Ontrack Inc. Data Recovery service.
LFlash Communication Admin Service (FlashComAdmin)FlashComAdmin.exeAppears to be modem driver related Made by Macromedia Inc.
LFlash Communication Server (FlashCom)FlashCom.exeAppears to be modem driver related Made by Macromedia Inc.
LFLEXlm server for PTClmgrd.exelmgrd.exe is a process associated with the Macrovision application-generic license server.
LFLEXnet Licensing ServiceFNPLicensingService.exeRelated to FLEXnet_Publisher from Macrovision. Note: Located in C:Program FilesCommon FilesMacrovisi
LFolder Size (FolderSize)FolderSizeSvc.exeRelated to Folder_Size Adds an other column to your folder view. Note: Located in C:Program FilesFol
Folding@Home
LFont Cache DownlevelFontCacheService.exeService installed by the Microsoft Avalon open beta.
LForceWare Intelligent Application Manager (IAM)nSvcAppFlt.exeRelated to Nvidia Corp. Intelligent Application Manager.
LForceWare IP service (nSvcIp)nSvcIp.exeRelated to Nvidia Corp. Network Access Manager.
LForceWare user log service (nSvcLog)nSvcLog.exeRelated to Nvidia Corp. Network Access Manager.
LFortech Proxy+ProxyPlus.exeFORTECH Ltd. http://www.proxyplus.cz/
LFortinet Service Scheduler (FA_Scheduler)scheduler.exeRelated to Fortinet security systems are the new generation of real time network protection systems.
OFrameworksrvany1234.exeUnknown owner: Location C:WINDOWSsystem32srvany1234.exe
LFreeloader Monthly Subscription ServiceFreeloader Monthly Subscription Service File.exeRelated to freeloader.com Online game services.
LFreePOPsfreepopsservice.exeFreePOPs is distributed by the GNU General Public License is intended to guarantee your freedom to s
LFreeSSHDServiceFreeSSHDService.exeRelated to OpenSSH A free SSH/SecSH protocol suite providing encryption for network services like re
XFreezeScreenSaverFreezeScreenSaver.exeFREEZESCREENSAVER.EXE_is_Adware Note: Located in C:WINDOWSsystem32
Xfrepdll.exeFREPDLL.EXEAdded by the W32/Tilebot-D WORM! Note: Gives the fake description ET dll Locator tool. Read the link
LFS Service ControlNTServApp.exeRelated to ArchestrA Software architecture for the integration of your automation systems.
Lfsbwsysfsbwsys.exeRelated to F-Secure_Antivirus Made by F-Secure Corp. This File should be found in the Program FilesF
XFUS_Server (USEPigeonServer)FTPServer.exeAdded by the Troj/Hunpigon-RO TROJAN! Note: This trojan file is found in the System32 folder.
LFW Configuration InterpreterUmxCfg.exeTiny Firewall
LFW Event ManagerUmxAgent.exeTiny Firewall
LFW Live Updateumxlu.exeTiny Firewall
LFW Policy ManagerUmxPol.exeTiny Firewall
LFW User to IP Address Translationumxuta.exeTiny Firewall
LFW User-Mode Helper (UmxFwHlp)UmxFwHlp.exeTiny Software Firewall User-Mode Helper. Made by Tiny Software Inc. A subsidiary of Computer_Associa
Xfwnet64 (fwnet)fwnet64.exeAdded by Backdoor.SDBot.gen Note: This worm rojan is located in C:%WINDIR%
LFwSRServicefwsrservice.exeCheckPoint SecuRemote
LGBPollGBPoll.exeSeems to be Roxio GoBack related
XGCX ServiceGCXSRVC.EXEAdded by the RBOT.CUE WORM! Read the link rootkit type stealth involved.
LGEARSecurityGEARSEC.EXERelated to GEAR software.
LGene6 FTP ServerG6FTPSERVER.EXERelated to Gene6 Sarl. http://www.g6ftpserver.com/
XGeneral Network Servicewinsocks32.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
Xgeneric host process (svchost)svchost.exeAdded by the W32/Tilebot-BB WORM! Note: This is not the legitimate Windows process svchost.exe (Whic
Generic Host Process For Win32 Services (Generic Host
Generic Service for HID Keyboard Input Collections
LGFI LANguard System Integrity Monitor 3 agent servicecfservice.exeGFI LANguard System Integrity Monitor is a utility that provides intrusion detection by checking whe
LGhostStartServiceGHOSTS~2.EXERelated to Norton. GHOSTSTARTSERVICE is the background support task/service for Ghost for Windows.
LGiga Pocket Hardware Detectorshwserv.exeSony computers
Xgldrgldr.exeTrojan Related
LGoogle Updater ServiceGoogleUpdaterService.exe(gusvc) - Google - commonly found in a location like this: C:\Program Files (x86)\Google\Common\Goog
LGoogle Updater Service (gusvc)GoogleUpdaterService.exeRelated to Google_Updater_Service Note: Located in C:Program FilesGoogleCommonGoogle Updater
LGoogleDesktopManagerGoogleDesktopManager.exeRelated to Google_Desktop_Manager Note: Located in C:Program FilesGoogleGoogle Desktop Search
LGoToMyPCg2svc.exeRelated to Citrix Online
LGoverLAN Service (GOVsrv)GOVsrv.EXEOwner:PJ Technologies Inc. See_Here
XGray (Pigeon)Scrsss.exeAdded by the Troj/GrayBrd-AM TROJAN! Note: This worm rojan file is found in the Windows or Winnt fol
XGray_Pigeon (GrayPigeon).exeAdded by the Troj/GrayBrd-EH TROJAN! Note: This worm rojan file is found in the Program Files folder
XGray_Pigeon_Serve (GrayPigeonServer)G_Server.exeAdded by the Troj/Feutel-I or Troj/Feutel-AI TROJAN!
XGray_Pigeon_Server (GrayPigeonServer)G_Server1.2.exeAdded by the Troj/GrayBrd-AP TROJAN! Note: This worm rojan file is found in the Windows or Winnt fol
XGray_Pigeon_Server2.0 (GrayPigeonServer2.0)G_Server2.0.exeAdded by the Troj/GrayBird-O TROJAN!
LGreenBorder Client Manager Service (clnt_ClientMan)ClientMan.exeRelated to GreenBorder Secure your browsing activities on the internet. Note: Located in C:Program F
LGridIron X-Factor After Effects Peer #1 (XFACTORAE1)xlr8d.exeRelated to GridIron Nucleo For digital post production professionals using Adobe® After Effects® on
OGroove Installer ServiceGrooveInstallerService.exe???
LGS30sGS30s.exeRelated to Gizmo!_Secure USB flash drive software by Crucial
Xhandle (handle)handle.exeAdded by the SDBOT.CDD WORM! Read the link rootkit type stealth involved.
XHandling the DHCP requests (DHCP Client)dhcpclient.exeMost likely a W32.Toxbot_variant
XHardware Clock Driver (hwclock)hwclock.exeAdded by the W32/Hwbot-A WORM!
XHardware Detection (Serv-U)svchost.exeReported by Kaspersky Anti-Virus as Win32.Serv-U.gen Note: This is not the legitimate Windows proces
XHardware Monitor Service (Hardware Monitor)mshms.exeAdded by the Troj/Wollf-A TROJAN!
LHardware Monitoring Program (ADMService)admServ.exeRelated to Avocent Embedded Software and Solutions Division
LHarmonyRSOBSERV.EXERelated to Rockwell_Automation Inc. FactoryTalk suite
Xhaxdrvhaxdrv.sysAdded by the Troj/Rootkit-U TROJAN! Read the link rootkit type stealth involved.
Xhcalwayhcalway.sysAdded by the PigSearch Adware. Read the link rootkit type stealth involved.
Xhexadecimal (HexadecimaRepresentation)Edit.exeAdded by the W32/Sdbot-AAY WORM! Note: File name may be different. Read the link rootkit type stealt
LHibernationhibserv.exeRelated to Compaq-Hewlett Packard hibernation service.
?HICOM LAN Bridge VCapiDrv (vcapidrv)vcapintsvc.exeCould be related to a new version of HICOM LAN Bridge?
XHID Output Service (HODSrv)hpsvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
LHorario de Windowsservices.exeSpanish Windows 2000 windows time
Xhost (host)host.exeAdded by the Troj/GrayBrd-AR TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
Xhost Service For Windows (mshost)mshost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XHost Services (Host Services)myhost.exeAdded by the W32/Tilebot-AT WORM! Note: This worm rojan file is found in the Windows or Winnt folder
XHost Services (Host Services)svhosts.exeAdded by the W32/Tilebot-AC WORM! Note: This is not the legitimate Windows process svchost.exe (Noti
XHotplug Devices Managerhotplug.exeAdded by the W32.Orpheus.A WORM!
LHoudini License Client (HoudiniServer)hserver.exeRelated to Houdini_License_Server from Side Effects Software Inc. Note: Located in C:WINDOWSsystem32
LHoudini License Server (HoudiniLicenseServer)sesinetd.exeRelated to Houdini_License_Server from Side Effects Software Inc. Note: Located in C:WINDOWSsystem32
LHP Configuration Interface ServiceHPConfig.exeHPConfig Module
LHP Hard Drive ThermalHDThermal.exeRelated to Hewlett-Packard company.
LHP OpenView Trace ServiceOVTrace.exeHP OpenView Internet Services
LHP Port Resolverhpbpro.exeRelated to Hewlett-Packard Company
LHP RF Device ServiceHpRfDev.exesupport for HP managing wireless devices
Xhp service (Hpsys)hpsys.exeAdded by the W32/Codbot-AF WORM! Note: This service has nothing to do with HP. This worm rojan file
LHP Statushpb2ksrv.exeRelated to Hewlett-Packard Company
LHP Status Printhpbhksrv.exeRelated to Hewlett-Packard company.
LHP Status Serverhpboid.exeRelated to Hewlett-Packard Company
LHP WMI Interface (hpqwmi)HPQWMI.exeRelated to Hewlett-Packard
?hpdjhpdj.exeMaybe HP related? Sits in TEMP folder.
Xhpdriverhpdriver.sysAdded by the Troj/Rootkit-AA TROJAN! Note: This trojan file is found in the System32 folder. Read th
XHpPrinterhpserver.exeAdded by the Troj/CmjSpy-W Trojan!
Lhpqwmiexhpqwmiex.exeRelated to HP_ProtectTools security manager
XHPR34K8hpr34k8.sysAdded by the Troj/Rootkit-AA TROJAN! Read the link rootkit type stealth involved.
LHPWirelessMgrHPWirelessMgr.exeLocated in HP Notebook Utilities - guessing for wireless connection.
?huapeakhuapeak.exeUnknown origin.
LHummingbird Inetd (HCLInetd)inetd32.exeRelated to Hummingbird Ltd. - http://www.hummingbird.com/
LHummingbird Jconfig Daemon (Jconfigd)jconfigdnt.exeRelated to Hummingbird Ltd. - http://www.hummingbird.com/
XHXD Service 100 (HackerDefender100)newka.exeVirus http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39265
XH_Server (H_Server)G_Server.exeAdded by the Troj/GrayBird-W TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
Xi386pI386P.SYSAdded by the Backdoor.Rustock TROJAN! Found in the System32drivers folder. Read the link rootkit typ
LIAA Event Monitoriaantmon.exeIntel related
LIapIap.exeRelated to Dell OpenManage Client Instrumentation.
LIBM Automatic Server Restart Executable (ibmasrex)ibmasrex.exeUnknown owner :Location C:WINDOWSsystem32ibmasrex.exe Related to IBM servers.
IBM CICS Transaction Gateway
LIBM CICS Universal Client (CICSClient)cclserv.exeRelated to IBM Corp.
LIBM Enterprise Extender (ldlcserv)ldlcserv.exeRelated to IBM Corp. - http://www.anti-spy.info/process/ldlcserv.exe.html
LIBM HDD APS Logging Service (TPHDEXLGSVC)TPHDEXLG.EXERelated to IBM's Active_Protection_System Made by the IBM_Corporation The file associated with this
LIBM KCU ServiceTpKmpSVC.exerelated to IBM ThinkPad
LIBM Mobility Client DHCP Control (artdhcp)artdhcp.exeRelated to IBM_Mobility_Client DHCP Control Note: Located in C:Program FilesIBMMobility Client
LIBM MQSeriesamqsvc.exeIBM WebSphere® MQ to exchange information across different platforms
LIBM PM Serviceibmpmsvc.exePower management driver for IBM laptops
LIBM PSA Access Driver ControlPsaSrv.exerelated to Professional Services Automation (PSA) from SharpOWL
LIBM Rapid Restore Ultra Servicerrpcsb.exerelated to Xpoint Technologies
LIBM Trace Facility (TrcBoot)trcboot.exeRelated to IBM Corp.
LIBM User Verification Manageruvmserv.exeRelated to IBM_User_Verification_Manager (UVM) secure logon interface. Note: located in C:Program Fi
IBM WebSphere Application Server V5 - server1
LICONICS License Server (GenRegistrar) (GenRegistrar)GenRegistrarServer.exeRelated to ICONICS Inc. Visualization and Automation software products
XICQ Update Service (ICQUPD)kpsf.sysDetected as Backdoor.HackDefender. Rootkit type stealth involved.
LICRAplusICRAplus.exeRelated to ICRAplus internet filter parental control etc. Note: Located in C:Program FilesICRAplusIC
Xicrss manager 32bit (icrss)icrss.exeAdded by the W32/Rbot-FZB WORM! Note: Located in C:WINDOWSsystem
Licservice - ONTRACK Data International Inc.icserv.exeRelated to SuperAdBlocker
LiD2 Smart Card Server (id2scaps)id2scaps.exeiD2 is a client product that brings security user authentication and digital signatures to standard
Xieupdater (Microsoft IE Updater)ieupdate.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:Document
Xiexplorer (iexplorer)iexplorer.exeAdded by the Troj/Singu-U TROJAN! Note: This trojan file is found in the System32 folder
LIgniteService.exeIgniteService.exeRelated to Accenture_Media_Viewer
Image Converter video recording monitor for VAIO
XImagePath (win32ssr)win32ssr.exeAdded by the W32/Sdbot-AMA WORM! Read the link rootkit type stealth involved.
LIMail FINGER Server (FINGRD32)FINGRD32.exeRelated to Ipswitch Inc. Network Management.
LIMail IMAP4 Server (IMAP4D32)IMAP4D32.exeRelated to Ipswitch Inc. Network Management.
LIMail LDAP Service (OpenLDAP-slapd)slapd.exeRelated to Ipswitch Inc. Network Management.
LIMail Monitor Service (IMONITOR)IMonitor.exeRelated to Ipswitch Inc. Network Management.
LIMail POP3 Server (POP3D32)POP3D32.exeRelated to Ipswitch Inc. Network Management.
LIMail PWD Server (PSERVE)PSERVE.exeRelated to Ipswitch Inc. Network Management.
LIMail Queue Manager Service (QUEUEMGR)queuemgr.exeRelated to Ipswitch Inc. Network Management.
LIMail SMTP Server (SMTPD32)smtpd32.exeRelated to Ipswitch Inc. Network Management.
LIMail Sys Logger Service (SYSLOGD)SYSLOGD.exeRelated to Ipswitch Inc. Network Management.
LIMail Web Calendar Service (IWEBCAL)IWebCal.exeRelated to Ipswitch Inc. Network Management.
LIMail Web Service (IWEBMSG)iwebmsg.exeRelated to Ipswitch Inc. Network Management.
LIMail WHOIS Server (WHOISD32)WHOISD32.exeRelated to Ipswitch Inc. Network Management.
LIMAPI CD-Burning COM ServiceImapiRox.exeIMAPI CD-Burning COM Service
LIMountSRVIMountSRV.exeRelated to Paragon hard_disk_manager
LInbound Distributor Serviceinbounddistributorservice.exeRelated to Inbound_Logistics
LInCD File SystemInCDsrv.exeInCD Packet Writer related.
LInCD HelperInCDsrv.exeInCD Packet Writer service from Nero Burning ROM (Ahead Software)
LIndependent Management Architecture (IMAService)ImaSrv.exeRelated to Citrix MetaFrame
XIndex Service (b3)dllhost32.exeAdded by the WORM_AGOBOT.CH WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XIndexing Helps (Indexingbox)svchest.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XIndexing The System Files (Indexing Service)winupdatez.exewinupdatez.exe
LInfrastructure)cm.exeRelated to Trend Micro Inc.
LInicio de sesión redlsass.exeSpanish Windows 2000 net logon
XInstallDriver Service (ISDS)csscv.exeAdded by the W32/Sdbot-CPL WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
LInstallDriver Table ManagerIDriverT.exeRelated to Macrovision Corporation.
LInstallShield Licensing ServiceInstallShield Licensing Service.exeRelated to InstallShield_Licensing_Service from Macrovision. Create high-quality software installati
LInstantáas de volumenvssvc.exeVolume Shadow Copy Service found in Windows XP and 2003.
LInstrumental de administracióe WindowsWinMgmt.exeSpanish Windows 2000 windows management instrumentation
LIntel Alert Handlerhndlrsvc.exeRelated to Intel Corp.
LIntel Alert Originatoriao.exeRelated to Intel Corp.
LIntel CI ManagerCiMgrLdr.exeRelated to Intel Corp.
LIntel Client Instrumentation for DMI (ni_nic)ni_nic.exeIntel Client Instrumentation for DMI
LIntel File Transferxfr.exeRelated to Intel Corp.
LIntel IIDSIIDS.exeRelated to Intel Corp.
LIntel Local Scheduler ServiceLOCALSCH.EXEPart of LANDesk Management Suite.
LIntel NCS NetService (NetSvc)NetSvc.exeIntel NCS NetService
LIntel PDSpds.exeRelated to Intel Corp.
LIntel QIP Client ServiceQIPCLNT.EXEPart of LANDesk Management Suite.
LIntel SSMssm.exeRelated to Intel Corp.
LIntel Targeted Multicasttmcsvc.exePart of LANDesk Management Suite.
LIntel(R) NMSNMSSvc.exeNIC Management Service - diagnostics program for Intel Pro family network cards
LIntel® Active Monitor (imonNT)imonnt.exehttp://www.liutilities.com/products/wintaskspro/processlibrary/imonnt/
LIntel® NMSNMSSvc.exeRelated to Intel Corp.
LIntel® Desktop Utilities Service (iHCService)IDUServ.exeRelated to Intel® Desktop_Utilities service from OSA Technologies. Inc. Note: Located in C:Program F
LIntel® Quick Resume Technology Drivers (ELService)ELService.exeRelated to Intel® _Quick_Resume_Technology Drivers. Note: Located in C:Program FilesIntelIntelDHInte
LInterbase Guardianibguard.exeInterbase database server related
LInterBase InterClient Serverinterserver.exeInterbase database server related
LInterBase Serveribserver.exeInterbase database server
LInternet Connection Monitor EngineICMNT.EXEUser reports that it's for a Home Router from Deerfield Communications www.deerfield.com/
XInternet Explorer (Internet Explorer)Internet.exeAdded by the Troj/Feutel-AA TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
LInternet ProxyInternetProxy.exeRelated to ICRAplus internet filter parental control etc. Note: Located in C:Program FilesICRAplusIC
XInternet Service Manager (INETSVC)INETSVC.EXEAdded by the Backdoor.Win32.SdBot.xd detected by Kaspersky More: Here Note: This worm rojan is locat
XInternet TCP Protocol (Win_ad)TCPServer.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:Windowsw
Xinternew (internew)system.exeAdded by the Troj/Cmjspy-BN TROJAN!
LInterPlot IMF Printer Driver Servicepidrpcs.exeInterPlot device drivers - See Here InterPlot/Overview.htm
XIntespention (Win32)IEXPLORE.exeAdded by the W32/Forbot-FL WORM!
XIntranet Service (IntranetService)intranet.exeOwner:Brought to you by the Bandwidth Bandits. Location: C:WINDOWSSYSTEM32intranet.exe
LInVircible Scheduler (IVScheduler)IVSCHED.EXESecurity software package to protect personal computers and PC networks. Owner: NetZ Computing Ltd.
Liolo System GuardIoloSGCtrl.exeRelated to System_Mechanic by Iolo
LIomega Active DiskADService.exeRelated to Iomega Corporation
LIomega Activity Disk2ActivityDisk.exeActivityDisk Iomega Corporation SmartSoft ActivityDisk
LIomega App ServicesAppServices.exeIomega related
LIomegaAccessIOMEGAACCESS.EXErelated to Iomega Backup
LION Java Daemon 2.0ion_srv.exeRelated to ITT_Visual_Information_Solutions ION Script is a powerful tool for creating Web-based IDL
LION Java Daemon 6.1ion_srv.exeRelated to ITT_Visual_Information_Solutions ION Script is a powerful tool for creating Web-based IDL
XIp4Sec (Ip4Sec)ip.sysAdded by the Satiloler.E TROJAN! Read the link rootkit type stealth involved.
LiPassConnectEngineiPassConnectEngine.exeRelated to iPassConnect Universal Client. iPass addresses the needs of both users and IT by making s
LiPod ServiceiPodService.exeRelated to Apple iPod.
LiPodSrviPodSrv.exeRelated to iPod Apple software. Note: located in C:Program FilesiPodin in Windows 2000/XP/2003.
XIPRIP (IPRIP)svchost.exe -k netsvcsAdded by the Backdoor.Ripgof TROJAN! Read the link rootkit type stealth involved.
LIPS Core Service (IPSSVC)IPSSVC.EXEA VPN client service found in Lenovo Thinkpad. Note: located in C:WINDOWSsystem32
LIpswitch WS_FTP Queue (ftpqueue)ftpsched.exeRelated to Part of WS_FTP Pro from Ipswitch. Note: Located in C:Program FilesWS_FTP Pro
XIPtableipconfig32.exeAdded by the W32/Tilebot-AP WORM! Note: This worm file is found in the Windows or Winnt folder.
XIPv6 Helper Drivercsass.exeAdded by the AGOBOT.TC WORM!
LIrBridge User-Level Interface (USRBRIDG)usrbridg.exeRelated to the Extended Systems infrared port made by Extended_Systems Inc. This file should be loca
LISAM SMT Service (ISAMsmt)isamsmt.exeRelated to IBM Global Services - http://www.anti-spy.info/process/isamsmt.exe.html
LiSeries Access for Windows Remote Command (Cwbrxd)CWBRXD.EXERelated to IBM Corporation. http://www.ibm.com/
XISEXEngangelex.exeBargain Buddy variant
LISSI EZUpdate (ISSIMon)issimsvc.exeRelated to Ibm_Global_Services Used internally by IBM for automatic updating of software and microso
LISSvcISSVC.exeRelated to Norton Internet Security
XItalian Grand Prixgrand.exeAdded by the W32/Spybot-MK WORM! Note: C:%WINDIR%System32dllcache (XP/WinNT/2K)
XiTunes Music Service (iTunesMusic)iTunesMusic.exeAdded by W32.Spybot.NLX WORM! Rootkit Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32
LIxia Endpoint (IxiaEndpoint)endpoint.exeAdded by Ixia_Endpoint Note: Located in C:PROGRA~1NetIQEndpoint
LJaguarjagsrv.exeRelated to Sybase_EAServer Note: Located in C:SybaseEAServerin
XJava development Serviceswindows.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XJava development Serviceslogins32.exeAdded by the W32/Tilebot-HC WORM! Note: This worm rojan is located in C:%WINDIR% folder. Steal infor
XJava ineticerealetin.exeAdded by the Troj/Bckdr-PQM TROJAN! Note: This worm rojan is located in C:Program FilesCommon FilesM
XJava Sun Scheduler (JUSCHED)jusched.exeAdded by the W32/Sdbot-CQC WORM! Note: This worm rojan is located in C:%WINDIR% folder. More here
XJavaPlatform64JavaPlatformAdded by the W32/Kassbot-M WORM! Note: Located in C:%WINDIR%
XJiurlPortHide (JiurlPortHide)JiurlPortHide.sysAdded by the Troj/Progent-A TROJAN!
Ljsdaemonjsdaemon.exeRelated to fax service from JetFax Inc.
LJuniper Network Connect Service (dsNcService)dsNcService.exeRelated to Juniper Networks Inc. Networking Platform.
XK4NVk4nv.exeAdded by a variant of the Trojan.K4NV.Process WORM! Note: located in C:WINDOWSk4nv.exe
LK9 Time Synchronizationk9nt.exeRelated to HC Mingham-Smith Limited http://www.kaska.demon.co.uk/history.htm
LKaseya AgentAgentMon.exeRelated to Kaseya Inc.
LKaspersky Anti-Virus Service (KLBLMain)kavmm.exeRelated to Kaspersky virus removal program.
LKAV Monitor Serviceavpm.exeKaspersky AntiVirus
Lkavsvckavsvc.exeKaspersky AntiVirus
Xkbdrv64KBDRV64.SYSAdded by the TROJ_ROOTKIT.K TROJAN! Read the link rootkit type stealth involved.
Xkdcsvchost.exe -k kdcAdded by the Fuwudoor TROJAN!
LKerberos Key Transaction Coordinator (kerbkey)kerb.exeVerify one computer's identity to another and to set up encryption keys for a secure connection betw
LKerio MailServer (KerioMailServer)mailserver.exeRelated to Kerio_MailServer Note: Located in C:Program FilesKerioMailServer
LKerio Personal Firewallpersfw.exeKerio Firewall
LKerio Personal Firewall 4 (KPF4)kpf4ss.exeRelated to Kerio Personal FireWall.
XKernell32termsv.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:WindowsSyste
XKeyboard Service System Files (Keyboard Service)navupdate64.exeAdded by a variant of the WIN32.RBOT WORM! Note: This worm file is found in the System32 folder.
LKingsoft Antivirus KWatch Service (KWatchSvc)KWatch.EXERelated to Kingsoft_Antivirus virus protection and content filtering. Note: located in C:KAV**** [*
LKingsoft Personal Firewall Service (KPfwSvc)KPfwSvc.EXERelated to Kingsoft_Antivirus virus protection and content filtering. Note: located in C:KAV**** [*
LKnob Service (KNOBSERV)KnobService.exeFile belongs to Acer_Inc
LKodak Camera Connection SoftwareKodakCCS.exeKodak Software to connect digital cameras
?KServiceKService.exeAdded by KService It's part of a peer to peer package people agree to when signing up with 'Sky By B
LLANDesk Remote Control Service (ISSUSER)issuser.exeRelated to LANDesk_Remote_Control Service. Note: Located in C:Program FilesLANDeskLDClient
LLANDesk® Management Agentresidentagent.exePart of LANDesk Management Suite.
LLanSafe Power Monitor (LanSafe PM)PowerMonitor.exeRelated to LanSafe_Power_Monitor from Powerware. Uninterruptible Power Supply Note: Located in C:Pro
LLanSafe Process Managerxyntservice.exeRelated to LanSafe_Process_Manager from Powerware. Uninterruptible Power Supply Note: Located in C:P
LLavasoft Personal Firewall Service (LavasoftFirewall)lpfw.exeRelated to Lavasoft_Personal_Firewall service. Note: Located in C:Program FilesLavasoftPersonal Fire
?LckFldServiceLckFldService.exe? Could be related Proland Software. ? - http://www.pspl.com/
LLEC TranslateDotNet ServerLogoMedia TranslateDotNet Server.exeTranslates email web pages documents and instant messages. Made by the Language Engineering Company
LLeica Microsystems Data Container V1LMSDataContainerServer.exeRelated to Leica_Microsystems Now Vistec_Semiconductor_Systems advanced technologies in optics.
LLexar JD31 (LxrJD31s)LxrJD31s.exeLexar JumpDrive driver. From Lexar_Media_Inc
LLexar Secure II (LxrSII1s)LxrSII1s.exeRelated to Lexar_Media Inc. removable flash memory cards USB flash drives card readers etc...
LLexar SG20LxrSG20s.exeRelated to Lexar_Media Inc. Lexar offers a wide range of storage products. Note: Located in C:WINDOW
LLexBce ServerLEXBCES.EXELexmark Printer Service
LLibUsb-Win32 - Daemon Version 0.1.8.0libusbd-nt.exeLibUsb open-source USB driver
LLicCtrl Servicerunservice.exePart of the eLicense Copy Protection scheme employed by some software and games. (Castlecops Startup
LLicense Agentcla.exeLicense Agent for the HiPath 1220 digital PBX system from Siemens. For more information Click_Here F
LLicense Management (CLMTomcatStarterSvc)tomcat.exeRelated to Apache_Tomcat Owner: Alexandria Software Consulting.
LLicense Management Service ESDLicence Manager ESD.exeRelated to the Licence_Manager_ESD.exe is the element5 License Management Service used by some softw
LightScribeService Direct Disc Labeling Service
LLiveShare P2P ServerRoxLiveShare.exeRelated to Roxio_Inc
LLiveShare P2P Server 9 (RoxLiveShare9)RoxLiveShare9.exeRelated to Roxio_Inc
LLiveUpdateLUCOMS~1.EXERelated to Norton Internet securty suite and provides up to date antivirus data for your Norton Anti
XLmHostssvchost.exe -k LmHostsAdded by the Fuwudoor TROJAN!
XLMMng (memlow)memlow.sysAdded by the Troj/Haxdoor-AA TROJAN!
XLoader)SVCHOST.EXEAdded by the RBOT.BZF WORM! Note: This is not the legitimate Windows process SVCHOST.EXE (Which is a
XLoading Outpost Connectionscmdtel.exeWin32.Bagz.i email virus
XLocal Security Authority Subsystem Service (lsass)lsass.exeAdded by the W32/Tilebot-AK or W32.Spybot.ABDO WORM! Note: This is not the legitimate Windows proces
XLocal Security Authority System Service (lsass)lsass.exeAdded by the W32/Rbot-AJA WORM! Note: This is not the legitimate Windows process lsass.exe (Which is
LLogical Disk Manager Administrative Servicedmadmin.exeVeritas logical disk manager
LLogitech Process Monitor (LVPrcSrv)LVPrcSrv.exeRelated to Logitech QuickCam Provides additional configuration options for these devices.
LLogMeInLogMeIn.exeRelated to LogMeIn LogMeIn Rescue is used by IT helpdesks to provide instant remote support to custo
XLOGON suport serviceIES4SERVICE.SYSAdded by the Goldun.G TROJAN! Note: This trojan file is found in the System32 folder.
XLogon Terminal Managerspoolsc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
LLogonSvc (LogonSvcID)logonsvc.exeRelated to E-Pop web conferencing Note: Located in C:Program FilesE-Pop
LLookout Citadel Server (LkCitadelServer)lkcitdl.exeRelated to Lookout_Citadel_Server From National Instruments Inc. Note: Located in C:WINDOWSsystem32
LLotus Notes Single Logonnslsvice.exeIBM Lotus Notes Single Logon Service - http://www.anti-spy.info/process/nslsvice.exe.html
XLpdriver (Lpdriver)lpdriver.sysAdded by the W32/Tilebot-H or W32/Sdbot-ADG WORM! Note: This worm file is found in the System32 fold
XLSA Shel (Export Version)lsass.exeAdded by the W32/Tilebot-HQ WORM! Note: This worm rojan is located in C:%WINDIR% folder.
Xlsass (lsass)lsass.exeAdded by the W32/Rbot-AIC WORM! Note: This is not the legitimate Windows process. (Which is always f
Xlsass (Workstations)autoexec.exeAdded by the W32/Sdbot-AFN WORM! Note: This worm file is found in the System32 folder.
XLsassFTP daemon (LsassFTPD)LsassFtpd.exeAdded by the SDBOT.CDW WORM! Read the link rootkit type stealth involved.
XLsassFTPzz daemon (LsassFTPDzz)LsassFtpdz.exeAdded by the W32/Rbot-ARL WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
LLWWLicenseServiceLWWLicenseService.exeRelated to Wolters_Kluwer The Professional's First Choice for information tools and solutions that h
Llxbs_devicelxbscoms.exeRelated to LXB_Device LXB provides secure backup.
Llxbt_devicelxbtcoms.exeLexmark International services. http://www.lexmark.com/
Llxbu_devicelxbucoms.exeRelated to Lexmark Printers. Provides additional configuration options for these devices
Llxbx_devicelxbxcoms.exeRelated to Lexmark International Inc Printer service. Note: located in C:WINDOWSSystem32
Llxby_devicelxbycoms.exeRelated to Lexmark Printer service. Note: located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32 (
Llxcc_devicelxcccoms.exeRelated to Lexmark International inc. Communication module for Lexmark products. Disabling will caus
Llxcd_devicelxcdcoms.exeRelated to Lexmar Lexmark International Inc. Printers Note: Located in C:WINDOWSSystem32
Llxce_devicelxcecoms.exeRelated to Lexmark Inc. printers
Llxcf_devicelxcfcoms.exeLexmark printer related
Llxcg_devicelxcgcoms.exeRelated to Lexmark printer
LLync USB Auditor Service (LyncUSBServ)lyncusb.exeRelated to Lync_USB A toolkit that delivers an integrated removable media device discovery and audit
LM-Audio Ozone Installer (OzoneInstallerService)ozinst.exeRelated to M-Audio_Ozone products. Note: Located in C:Program FilesM-AudioOzoneInstall
LM-BUS/M-NET Administration (MCONTROL)mcontrol.exeRelated to Siemens Energy & Automation Platform. Note: located in C:Program FilesProcessSuiteMBUSDRV
LM1 Licensing Helper (iLicenseSvc)iLicenseSvc.exeRelated to Related to GE_Fanuc_Automation enable you to act in real-time to optimize productivity an
Xmac128mac128.sysAdded by the Troj/Klutz-A Trojan!
LMacFormatServiceFORMATM.EXERelated to Conversions Plus from DataViz
LMachine Debug Manager (MDM)mdm.exeVisual studio debuger if you install vs2003 mdm.exe is found in c:/program files/common files/micros
LMacromedia Licensing ServiceMacromedia Licensing.exeRelated to Macromedia products: Flash Dreamweaver etc.
LMailgate Mail/Proxy Servicemgatesvc.exeMailgate Internet Connectivity Server
XManage)dfrgfat16.exeAdded by the W32/Codbot-N WORM!
XManageer Network Connectionstelcmd.exeBAD - Look how manager is spelled.
XManageer Network Connections (Kern32)telcmd.exeA new service added by the Troj/Agent-CP TROJAN with a display name of Manageer Network Connections.
LManagement Repository)jrun.exeRelated to MacroMedia_ColdFusion products. Made by MacroMediaInc.
XManager (Windows XP Manager)msnmgr.exeAdded by the W32/Kassbot-L Read the link rootkit type stealth involved.
Managing FAT and NTFS partitions (Defragmentation
LMangomind Drive Repair (MindRepair)dirtcon.exeRelated to Mangomind access your business critical files from anywhere at any time from any computer
Lmapi HelperImapiHelper.exeISO recorder
LMarkVision Server (MvServer)lexmvservice.exeRelated to MarkVison_Server From Lexmar. Note: Located in C:WINDOWSSYSTEM32
LMarkVision Web Server (MvWebServer)lexwebservice.exeRelated to MarkVison_Server From Lexmar. Note: Located in C:WINDOWSSYSTEM32
XMass Effect™ Xbox 360mfxbox.exeAdded by the W32/Spybot-MS WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP/
LMATLAB Server (matlabserver)matlabserver.exeRelated to The MathWorks Inc.
LMaxBackServiceIntMaxBackServiceInt.exeRelated to Maxtor_backup service. Note: Located in C:ProgramMaxtorMaxtor Backup
LMaxSyncService (NTService1)SyncServices.exeRelated to Maxtor_OneTouch service. Note: Located in C:ProgramMaxtorOneTouchUtils
LMaya 6 PLE Documentation Serverwrapper.exeRelated to Alias Systems Corp.
LMC/Empower i.collecticserv.exean internet cleaning utility issued by various ISP's for their customers use
LMcAfee AgentmyAgtSvc.exeRelated to Network Associates Inc.
McAfee AntiSpyware Real-Time Scanner
LMcAfee AntiSpyware Servicemassrv.exeRelated to McAfee AntiSpyware service.
LMcAfee Desktop Firewall Service (FireSvc)FireSvc.exeRelated to McAfee Desktop Firewall Service. Note: located in C:Program FilesNetwork AssociatesMcAfee
LMcAfee E-mail Proxy (Emproxy)emproxy.exeRelated to McAfee_Email_Proxy c:program filescommon filesmcafeeEmProxy
LMcAfee FirewallCPD.EXERelated to Network Associates
LMcAfee Framework Service (McAfeeFramework)FrameworkService.exeMcAfee/CA related
LMcAfee HackerWatch ServiceHWAPI.exeRelated to McAfee_HackerWach Service installed by the McAfee Internet Security suite and whose role
LMcAfee Log Manager (McLogManagerService)mclogsrv.exeRelated to McAfee_SecurityCenter Log Manager. Note: Located in C:Program FilesMcAfeeMSC
LMcAfee Network Agent (McNASvc)mcnasvc.exeRelated to McAfee_Network_Agent Note: Located in c:program filescommon filesmcafeemna
LMcAfee Personal Firewall Service (MpfService)MPFSrv.exeRelated to McAfee_Personal_Firewall Service. Note: Located in C:Program FilesMcAfeeMPF
LMcAfee Privacy Service (GuardDogEXE)GUARDDOG.EXEBelongs to the software McAfee Internet Security or McAfee Privacy Service. For more information Cli
LMcAfee Privacy Service (MPS9)mps.exeRelated to McAfee_Privacy_Service Includes many features for families online including Internet cont
LMcAfee Protection Manager (mcpromgr)mcpromgr.exeRelated to McAfee_Integrated_Security Platform. Note: Located in C:Program FilesMcAfeeMSC
LMcAfee Proxy Service (McProxy)mcproxy.exeRelated to McAfee Proxy Service Note: Located in c:Program FilesCOMMON~1mcafeemcproxy
LMcAfee Real-time Scanner (McShield)mcshield.exeRelated to McAfee_Virus_Shield Note: Located in C:Program FilesMcAfeeVIRUSSCAN
LMcAfee Redirector Service (McRedirector)redirsvc.exeRelated to McAfee_Redirector Service Module. Note: Located in c:program filescommon filesmcafee edir
LMcAfee Scanner (McODS)mcods.exeRelated to McAfee_VirusScan On Demand Scan. Note: Located in C:Program FilesMcAfeeVIRUSSCAN
LMcAfee SecurityCenter Update Managermcupdmgr.exeMcAfee Antivirus updater
LMcAfee SecurityCenter Update Manager (mcupdmgr.exe)mcupdmgr.exeMcAfee Update manager - http://castlecops.com/s5681-MCUPDMGR_EXE.html
LMcAfee SiteAdvisor ServiceMcSvHost.exeMcafee Inc - commonly located at C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
LMcAfee SpamKiller Server (MskService)MSKSrvr.exePart of McAfee Spamkiller. http://computercops.biz/s6154-MSKSrvr_exe.html
LMcAfee SpamKiller Service (MSK80Service)MskSrver.exeRelated to McAfee SpamKiller Note: Located in C:Program FilesMcAfeeMSK
LMcAfee SystemGuards (McSysmon)mcsysmon.exeRelated to McAfee_SystemGuards Service. Note: Located in C:Program FilesMcAfeeVIRUSSCAN
LMcAfee Task Scheduler (McTskshd.exe)mctskshd.exeRelated to McAfee_Task_Scheduler Note: Located in C:Program FilesMcAfeeMSC
LMcAfee Update Manager (mcmispupdmgr)mcupdmgr.exeRelated to McAfee_SecurityCenter Update Manager. Note: Located in C:Program FilesMcAfeeMSC
LMcAfee User Manager (mcusrmgr)mcusrmgr.exeRelated to McAfee_SecurityCenter MISP User Manager. Note: Located in C:Program FilesMcAfeeMSC
LMcAfee Wireless Security Service (MwlSvc)MwlSvc.exeRelated to McAfee_Wireless_Security_Service Note: located in C:PROGRA~1McAfeeMWL
LMcAfee WSC Integration (McDetect.exe)mcdetect.exeRelated to McAfee WSC Integration.
LMcAfee.com McShieldmcshield.exeRelated to McAfee
LMcAfee.com Personal Firewall ServiceMPFSERVICE.exeRelated to McAfee.com Personal Firewall
LMcAfee.com VirusScan Online Realtime Enginemcvsrte.exeMcAfee AntiVirus
XMCFservice (mcfdrv)mcfdrv.sysAdded by the TROJ_ROOTKIT.R TROJAN! Read the link rootkit type stealth involved.
XmchInjDrvmc2A.tmpAdded by the Dialer.ICcontrol DIALER! Note: This malware can make the modem dials long-distance phon
Xmcmmng32 (Microsoft Control Manager)mcmmng32.exeAdded by the W32/Tilebot-HK WORM! Note: This worm rojan is located in C:%WINDIR% folder. disabling t
LMcShieldMcshield.exethis process is associated with McAfee's Internet Security suite. More specifically it is essential
LMD Simple Burner Service (NetMDSB)NetMDSB.exeSony Corp. MiniDisk Simple Burner
LMDaemon - Alt-N Technologies Ltd.MDAEMON.EXERelated to MDaemona Windows-based email server.
XMdeRyrpe.sysAdded by the Backdoor.Ryejet TROJAN! Read the link rootkit type stealth involved.
XMEAOI Service (MEAOI)_meaoi.exeAdded by the W32/Tilebot-AM WORM! Note: This worm rojan file is found in the Windows or Winnt folder
LMediabee (Mediabee Desktop Server)MbXmlRpcServer.exeRelated to Mediabee Group Planner & Dashboard
LMediaMax XL Service (MediaMaxXLService)MediaMaxXLService.exeRelated to MediaMax_XL from Streamload Inc. An application that automatically backs up your files an
XMedie Sariel Number Servicesmoviemk.exeAdded by the Troj/DownLd-AAP TROJAN! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me)
XMemDRV (vdnt32)vdnt32.sysAdded by the Troj/Haxdoor-AA TROJAN!
LMemeo (BMUService)MemeoService.exeRelated to Memeo backup service. Note: Located in C:Program FilesTanagraMemeo
mental ray 3.5 Satellite (32-bit)
LMerak Mail Server Control (MerakControl)control.exeRelated to Merak_Mail_Server Software. A high performance mail server software suite for Windows or
LMerak Mail Server POP3/IMAP (MerakPOP3)pop3.exeRelated to Merak_Mail_Server Software. A high performance mail server software suite for Windows or
LMerak Mail Server SMTP (MerakSMTP)smtp.exeRelated to Merak_Mail_Server Software. A high performance mail server software suite for Windows or
LMERANT XDB Server for NX 3.1xsrvnx.exeRelated to SERENA Software Inc. - http://www.serena.com/
XMessengersvchost.exe -k MessengerAdded by the Fuwudoor TROJAN!
XMessengerkernel32.exeAdded by the Troj/Kyth-A TROJAN! Note: Replaces any existing services named Messenger.
XMessengersys.exeAdded by the Troj/PcClient-H TROJAN! Note: This worm rojan file is found in the System32 folder.
XMessengerKB08953265.exeAdded by the Esteems.F TROJAN! Note: Drops multiple files.
XMessenger (Messenger)(TROJAN FILE NAME)Added by the Trojan.Neasemal TROJAN! Note: This trojan file will be found in the System32 folder and
XMessenger (Messenger)hacker.exeAdded by the Troj/PcClient-M TROJAN! Note: This trojan file is found in the System32 and Temp folder
LMetaFrame COM Server (MFCom)mfcom.exeRelated to Citrix MetaFrame
LMGABGEXEmgabg.exeMatrox BIOS Guard. What does it do and is it required?
LMICROS Backup Serverresbsm.exe

Related to MICROS Systems 3700d is a Sybase SQL Anywhere/Adaptive Server with a relational databa

XMicrosoft Agentlpohost.exeAdded by the W32/Sdbot-CWQ WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP/
XMicrosoft Agentffchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: Located in C:WindowsSystemdllcache (Win9
XMicrosoft Agentsnchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XMicrosoft Agentqxchost.exeAdded by the W32/Sdbot-CWP WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP/
XMicrosoft Agentrschost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
LMicrosoft AntiSpyware (Beta 1)gcasDtServ.exeMicrosoft AntiSpyware Data Service
LMicrosoft AntiSpyware (Beta 1)gcasServ.exeMicrosoft AntiSpyware Service
LMicrosoft AntiSpyware (Beta 1)GIANTAntiSpywareMain.exeMicrosoft AntiSpyware Main
XMicrosoft ASPI Manager (aspi113210)aspi113210.exeAdded by the Troj/Danmec-T TROJAN! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:
XMicrosoft authenticate service (MsaSvc)msasvc.exeAdded by Worm_Ircbot_Gen Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%WINDIR%Sy
XMicrosoft Bluetooth Support (BthSupp)bthsupp.exeAdded by the W32/Btbot-A WORM!
XMicrosoft Client Agent Service (Microsoft Client Agent)msclient.exeAdded by the W32/Tilebot-BP WORM! Note: This worm rojan file is found in the Windows or Winnt folder
XMicrosoft Config (mscfg)dczznet.exeAdded by the W32/Rbot-ARK WORM! Note: This is not the legitimate Windows process Msconfig.exe (Which
XMicrosoft Corporationsystemi32.exeVariant of the W32.SPYBOT WORM
XMicrosoft Corporation (Windows Wordpad)wordpad.exeAdded by the W32/Tilebot-GL WORM! Note: This worm rojan is located in C:%WINDIR% This is not Microso
LMicrosoft CTF Loaderctfmon.exeCTF Loader
XMicrosoft DHCPA Servicemshcp.exeAdded by the W32/Rbot-FNA WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP/W
LMicrosoft Digital Identity Service (InfoCard Service)infocard.exeRelated to Microsoft_NET_Framework .NET Framework is a development and execution environment that al
XMicrosoft Distributed Transaction (MSDT)msdt.exeAdded by the W32/Tilebot-BQ WORM! Note: This worm rojan file is found in the Windows or Winnt folder
XMicrosoft DLL Systemsmsc.exeAdded by the W32/Tilebot-FY WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XMicrosoft HDA Protocol (svhda)svhda.exeaDEED BY THE Backdoor.Win32.IRCBot.rr as detected by Kaspersky TROJAN! Note: This worm rojan is loca
XMicrosoft IIS helpermsiishlp.exeAdded by the Backdoor.Isen.Rootkit TROJAN! Read the link rootkit type stealth involved.
XMicrosoft information dll service (msidll)msidll.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
Microsoft Internet Information Services kernel mode
XMicrosoft Language Service (Windows Language Service)alg.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XMicrosoft Logon Servicemslogon.exeAdded by the W32.Woredbot.C TROJAN! Note: This worm rojan is located in C:%WINDIR%System32dllcache (
XMicrosoft Logon User Interface Skining (LogonUInterf)logonui.exeDetected by Ewido as Backdoor.SdBot.aad. This worm file is found in the Windows or Winnt folder.
XMicrosoft Main Window Servicemainwin32.exeAdded by the W32/Spybot-MR WORM! Note: This worm rojan is located in C:WindowsSystemdllcache (Win9x/
XMicroSoft Media ToolsMSMEDIA.EXEAdded by the SDBOT.CUH WORM! Note: This worm file is found in the System32 folder. (NT/2000/XP) Read
XMicroSoft Media Tools (MicroSoft Media Tools)MSmedia.exeAdded by the W32/Tilebot-BC WORM! Note: This worm rojan file is found in the Windows or Winnt folder
XMicrosoft MSI Servicemsi.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XMicrosoft Net API (NETAPI)msapi.exeAdded by the W32/Tilebot-HJ WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XMicrosoft NetWork FireWall ServicesNetServices.exehttp://www.sophos.com/virusinfo/analyses/w32lovgateaa.html
XMicrosoft NetWork FireWall ServicesNet_Services.exehttp://www.sophos.com/virusinfo/analyses/w32lovgateaa.html
XMicrosoft Network RPCmsnetrpc.exeRelated to the Troj/Isen-B
XMicrosoft Networks DN (msndn)msndn.exeAdded by the Backdoor.SdBot.AQZ A.K.A. Ircbot_Gen WORM! Allows a remote intruder to gain access and
XMicrosoft New Game 2 (svehost32)svehost32.exeAdded by the W32/Tilebot-I TROJAN! Read the link rootkit type stealth involved.
XMicrosoft Null Development Monitor (msdevnull)msdevnull.exeAdded by the W32/Rbot-AGE Worm! Read the link rootkit type stealth involved.
XMicrosoft Passport Network CyberShotscybershots.exeAdded by the W32/Spybot-ND WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP/
XMicrosoft Path Finder Service (MSpath)mspath.exeAdded by the W32/Sdbot-AEO WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
XMicrosoft Path Finder Service (mspathfinder)mspathfinderAdded by the W32/Tilebot-AH WORM! Rootkit Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%Syst
XMicrosoft Performance WMI Adapter AddOn (WMIPervAddOn)wmiapsv.exeAdded by the Backdoor.Win32.SdBot.aad TROJAN! Reported by Kaspersky More Note: This worm rojan is lo
XMicrosoft Print Spooler (WINDRIVER)scvhost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XMicrosoft Registry Viewer (Dumpreg)DUMPREG.EXEAdded by the SDBOT.BXI WORM! Read the link rootkit type stealth involved.
XMicrosoft SCC Host Protocol (POOLSVR)poolsv.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
XMicrosoft SCC Host Protocol (TaskMGM)taskmg.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
XMicrosoft sdk core (sdk)lsass.exeAdded by the Troj/IRCBot-PF TROJAN! Note: Located in C:%WINDIR%
XMicrosoft Security Login Servicemssecure32.exeAdded by the W32/Vanebot-R WORM! Note: This worm rojan is located in C:WindowsSystemdllcache (Win9x/
XMicrosoft Service Manager (winmdgr)winsvcmgr.exeAdded by the W32/Rbot-AAD WORM! Read the link rootkit type stealth involved.
XMicrosoft SQL Server Debug (sql)sqldebug.exeAdded by the W32/Tilebot-FF WORM! Note: Located in C:%WINDIR%
XMicrosoft SSL (ssl)ssl.exeAdded by the W32.Esbot.C WORM! Note: This WormTrojan file is found in the System32 folder and has no
XMicrosoft Star Window Servicestarwin32.exeAdded by the W32/Rbot-FNT WORM! Note: This worm rojan is located in C:%WINDIR%System32 dllcache (XP/
XMicrosoft Star Window Servicesvcshoter.exeAdded by the WORM_SDBOT.ANK WORM! Note: This worm rojan is located in C:WindowsSystemdllcache (Win9x
XMicrosoft Star Window Servicestarwksvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:Windowsd
XMicrosoft Startup Manager. (Microsoft Startup Manager)msput.exeAdded by the W32/Sdbot-BAY WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
XMicrosoft Svc Services Dispatchersvcsrv.ldrunknown malware
XMicrosoft Terminal Servicemsterminal.exeAdded by the W32/Sdbot-CPZ WORM! Note: This worm rojan is located in C:%WINDIR%System32DllCache (XP/
XMicrosoft Translation Service (MTServ)mtserv.exeAdded by the W32/Rbot-GAL WORM! Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32 (XP/W
XMicrosoft Updata ver2005 (Microsoft Updata ver2005)tw725.exeAdded by the Troj/Feutel-P TROJAN!
XMicrosoft update (msnupdate)windupdate.exeAdded by the SDBOT.CGV WORM! Read the link rootkit type stealth involved.
XMicrosoft update Servicemsiupdate32.exeAdded by the W32/Vanebot-S WORM! Note: This worm rojan is located in C:WindowsSystemdllcache (Win9x/
Microsoft Virtual Private Network (MS Virtual Private
XMicrosoft VPS Servicemsvps.exeAdded by the W32/Rbot-FNI WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP/W
XMicrosoft Webserver (Microsoft Webserver)Microsoft Webserver.exeAdded by the Troj/Hupigon-FU TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
XMicrosoft Windows (Microsoft Windows)system.exeAdded by the W32/Rbot-AMQ WORM! Note: This worm file is found in the Windows or Winnt folder. Read t
XMicrosoft Windows Avantage Service (Windows Avantage)avantage32.exeAdded by the W32/Tilebot-HE WORM! Note: This worm rojan is located in C:%WINDIR% folder. disables th
XMicrosoft Windows BDA Servicesvhba.exeAdded by the W32/Vanebot-P WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP/
XMicrosoft Windows DMR Service (Windows DMR Service)dmrproc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XMicrosoft windows FTPdupdtftpini.exeAdded by the W32/Rbot-FUS WORM! Note: This worm rojan is located in C:Windowsdllcache (Win9x/Me) C:%
XMicrosoft Windows HDA Servicesvhda.exeAdded by the W32/IRCBot-SL WORM! Note: This worm rojan is located in C:WindowsSystemdllcache (Win9x/
XMicrosoft Windows HelpFile (Windows Helpfile)services.exeAdded by the W32/Tilebot-FQ WORM! Note: This worm rojan is located in C:%WINDIR% folder. disabling t
XMicrosoft Windows Internet Connections Manager (net32b)net32b.exeAdded by the W32/Cuebot-N WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%WI
XMicrosoft Windows Man Service (Windows Man Service)winmgr.exeAdded by the W32/Sdbot-DTL WORM! Note: This worm rojan is located in C:%WINDIR% folder.
Microsoft Windows Protection (Windows Protection
XMicrosoft Windows Spool Service (Windows Spool Service)services.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XMicrosoft Windows Spool Service (Windows Spool Service)wdfmgr.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR% Not
Microsoft Windows Spooler Service (Windows Spooler
Microsoft Windows Spooler Service (Windows Spooler
XMicrosoft Windows System32windll32.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XMicrosoft Windows System32winservs.exeAdded by the W32/Tilebot-GU WORM! Note: This worm rojan is located in C:%WINDIR% Also been identifie
XMicrosoft Windows Update (Microsoft Update)scvvhost.exeAdded by the W32/Forbot-FH WORM!
XMicrosoft Windows Update (Microsoft Windows Update)msconfig32.exeAdded by the W32/Tilebot-P WORM! Read the link rootkit type stealth involved.
XMicrosoft Windows Update (msupdate)csrss.exeAdded by an unknown TROJAN! Note: This has nothing to do with Microsoft Windows Update and this is n
Microsoft Windows Validation Service (Windows
XMicroSoft Windowz Update (MsFtUpd)MsFtUpdateXP.exeAdded by the W32/Tilebot-BL WORM! Note: This worm rojan file is found in the Windows or Winnt folder
XMicrosoft WMI Performance Adapter AddOn (WMIPerAddOn)wmiapsrv.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR% NOT
XMicrosoft(R) Windows(R) Operat (Microsoft Corporation)iexplorer.exeAdded by the Troj/Feutel-W TROJAN! Note: This is not the legitimate Windows Process (iexplore.exe) w
Xmicrosoftdvdhelp (MicrosoftDVD)msdvd.exeAdded by the W32/Rbot-AWQ WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
XMicrosoftkeysdsystemwin32.exe
LMilShieldCleanerShieldService.exeRelated to Mil_Shield from Mil Incorporated. It protects your privacy by removing all tracks from yo
LMindRetrieve Engine (MindRetrieve)MindRetrieve.exeMindRetrieve Appears to be a personal desktop search engine.
LMindStorm Agentsrvpxa.exeRelated to MindStorm_AnalyzerPro from Secure Associates. A security management tool for customers ea
LMindStorm AnalyzerPro Controllersrvctr.exeRelated to MindStorm_AnalyzerPro from Secure Associates. A security management tool for customers ea
LMindStorm AnalyzerPro Correlation Enginesrvcor.exeRelated to MindStorm_AnalyzerPro from Secure Associates. A security management tool for customers ea
LMindStorm Controllersrvctr.exeRelated to MindStorm_AnalyzerPro from Secure Associates. A security management tool for customers ea
LMindStorm Correlation Enginesrvcor.exeRelated to MindStorm_AnalyzerPro from Secure Associates. A security management tool for customers ea
XMINIServer (MiNiService)MiniServer.exeAdded by the Troj/LittleW-E TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
XMiscrosoft Updates Service 4msupd4.exeTrojan-Downloader.Win32.Agent.gn
XMiscrosoft Updates Service 5msupd5.exeTrojan. TROJ_LODMEDUD.A
LMkSUpdateIntMkSUpdateInt.exeArcaVir an AntiVirus software from Poland. A procuct of ArcaBit Sp. z o.o
LMkS_Scanmks_scan.exeArcaVir an AntiVirus software from Poland. A product of ArcaBit Sp. z o.o
Lmks_vir antivirus monitor (MksVirMonSvc)mksmonsv.exeArcaVir an AntiVirus software from Poland. A product of ArcaBit Sp. z o.o
OMLKKBDNTDriverMLKKBDNTService.exeUnknown
XMMX Virtualization Servicemmx464.sysAdded by the Goldun.J TROJAN! Read the link rootkit type stealth involved.
XMMX2 Virtualization Servicemmx464.sysAdded by the Goldun.J TROJAN! Read the link rootkit type stealth involved.
LMobility Client (ArtourService)artsvc.exeRelated to IBM_Mobility_Client Note: Located in C:Program FilesIBMMobility Client
XMOBSYNCMOBSYNC.EXEAdded by the SDBOT.CNT WORM! Read the link rootkit type stealth involved.
Xmodlb (modlb)modlb.exeAdded by the W32/Tilebot-BF WORM! Note: This worm rojan file is found in the Windows or Winnt folder
Xmondrv (mondrv)mondrv.sysAdded by the TROJ_ROOTKIT.M TROJAN! Read the link rootkit type stealth involved.
XMONDVMONDV.SYSAdded by the Troj/Rootkit-Z TROJAN! Read the link rootkit type stealth involved.
?Morrin Thumbnail Synchronized Service 5 (MrnTS_Sync5)MrnTS_Sync5.exeFrom Morrin Corporation? http://forums.spywareinfo.com/index.php?act=ST&f=18&t=43573
LMotorola Digital Audio Player ManagerMotorolaDAP.exeRelated to Motorola Inc. Motorola Digital Audio Player.
XMouse Button Monitor (mousebm)mousebm.exeAdded by the W32.Esbot.A WORM!
XMouse Click Monitor (mousecm)mousecm.exeAdded by the W32/Sdbot-ZQ Worm!
XMouse Cursor Monitor (mousecrm)mousecrm.exeAdded by the W32/Sdbot-ABQ WORM!
XMouse Hardware Sync (mousehs)mousehs.exeAdded by the Troj/Bdoor-HU WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
XMouse Movement Monitor (mousemm)mousemm.exeAdded by the W32/Cuebot-E WORM!
XMouse Synchronization (mousesync)mousesync.exeAdded by the W32/Esbot-A WORM!
XMousebMOUSEB.EXEAdded by the SDBOT.CRQ WORM! Read the link rootkit type stealth involved.
LMovielink Core ServiceMOVIEL~1.EXEAssociated with Movielink online movie download service with help from IBM. Has also been seen with
LMozyBackupmozybackup.exeRelated to Mozy Free backup at a secure remote location. Note: Located in C:Program FilesMozy
LMpServiceMPSERVIC.EXERelated to Canon Inc. http://www.canon.com/
Lmr2kservmr2kserv.exeDell Open Management software installs this service http://www.anti-spy.info/process/mr2kserv.exe.ht
XMRFCKDLLMRFCKDLL.SYSAdded by the Troj/NtRootK-F TROJAN! Read the link rootkit type stealth involved.
LMrobeServiceMRobeService.exeRelated to Olympus_America_Inc Imaging products.
LMrPostmanWrapper.exeRelated to MrPostman: POP email access.
XMs Builders (Ms Builder)Wupated.exeAdded by the W32/Agobot-SS WORM!
XMS Common Servicemscomserv.exeAdded by the Troj/Zlob-RF TROJAN! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XMS Dns Servicewincntrl.exeAdded by a variant of the Sdbot/Rbot worm
XMS Dns Service (WinNet)wincntrl.exeAdded by the W32/Rbot-AYH WORM! Note: This worm rojan file is found in the System32 folder.
XMS DTC consolemsdtc.exeAdded by the W32/Sdbot-DTO WORM! Note: This worm rojan is located in C:%WINDIR%
XMS Internet Countermeasures Framework (ICF)System32:svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note DO NOT delete the svchost.exe file.
XMS Internet Countermeasures Framework (ICF)icf.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XMS Office Updater Servicemsrvs32.exeAdded by the W32/Tilebot-HM WORM! Note: This worm rojan is located in C:%WINDIR% folder
XMS Software Shadow Download Provider (dnlsvc)dnlsvc.exeAdded by DnlSvc.Process TROJAN!
XMs Valud Loader (Ms Valud Load)Svhots.exeAdded by the W32/Agobot-SP WORM!
XMSCommscom.exeAdded by the W32.Woredbot TROJAN! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP
XMSCommmandmswincom32.exeAdded by the W32/Rbot-FMM WORM! Note: This worm rojan is located in C:WindowsSystemdllcache (Win9x/M
XMSCoolServmscolsrv.exeRahack virus
LMSCSPTISRVMSCSPTISRV.exeRelated to Sony Corporation.
XMsdebugsrvdbg32hlp.exeAdded by the SDBOT.CNG WORM! Read the link rootkit type stealth involved.
XmsdirectxMSDIRECTX.SYSAdded by the Troj/NtRootK-F TROJAN! Note: This trojan file is dropped by various other worms and tro
XMSDN Driver (msdndr)msdndr.pifAdded by the Troj/HacDef-EQ TROJAN! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C
XMsdn Update 32 (msdnupdate32)msdnupdate32Added by the W32/Tilebot-M WORM! Read the link rootkit type stealth involved.
XMsdn Update 32 (msdnupdate32)msdnupdate32.exeAdded by the SPYBOT.AHT WORM! Read the link rootkit type stealth involved.
XMsdtc Managerwinlogin.exeAdded by the W32/Rbot-FKU WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%WI
Xmsecure (mcsecure)mcsecure.exeAdded by the SDBOT.BZJ WORM! Read the link rootkit type stealth involved.
Xmserv.exemserv.exeRelated to Trojan.Win32.Killav.br
Lmsftesqlmsftesql.exeRelated to Microsoft_SQL_server suite.
XMsGrd32MSYRD32.EXEAdded by the SDBOT.BYR WORM! Read the link rootkit type stealth involved.
XMsHS64 or cvcworking setting (cvcWork or MsHS64)syscvhost.exe or MsHS64.exeAdded by the W32/Tilebot-BU WORM! Note: This worm rojan file is found in the Windows or Winnt folder
Xmsie7msie701.exeIdentified as Trojan_Downloader by PREVX Note: This worm rojan is located in C:WindowsSystem (Win9x/
Xmsinit (Microsoft Scheduling Agent)msinit.exeAdded by the W32/Tilebot-BJ WORM! Note: This worm rojan file is found in the Windows or Winnt folder
LMSI_WLAN_ServiceWLAN_Service.exePart of Microstar's WLan card. File found in the C:Program FilesMicroStarWLANUtility folder.
Xmslogon (Microsoft System Logon Manager)mslogon.exeReported as Trojan-Dropper.Win32.Delf.ng by Kaspersky Anti-Virus. Note: This file is found in the Wi
XMsLS32 (MsLS32)MsLS32.exeAdded by the W32/Tilebot-BS WORM! Note: This worm rojan file is found in the Windows or Winnt folder
XMsLX32 (MsLX32)MsLX32.exeAdded by the W32/Sdbot-AFS WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
XMSMAPDEVICEMSMAPDEVICE.SYSAdded by the TROJ_ROOTKIT.AK TROJAN! Read the link rootkit type stealth involved.
Xmsmbios (Microsoft System Management BIOS Driver)mssmbios.exeAdded by the W32/Tilebot-AI TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
LMSMPSVCMSMPSVC.exeRelated to Windows_OneCare_Live from Microsoft
LMSR CollectormsrCollector.exeRelated to Black White Box Inc. Now owned by Vericept Corp. A Risk Management Platform
Xmsriv1 (msriv1)msriv1.sysAdded by the Troj/Rootkit-W TROJAN! Read the link rootkit type stealth involved.
Xmsscmc43msscmc43.exeAdded by the W32/Spybot-NB WORM! Note: This worm rojan is located in C:WindowsSystemdllcache (Win9x/
XMSSQL (MSSQL2K6)sqlsrv.exeAdded by the SDBOT.CNY or MYTOB.NC WORM! Read the link rootkit type stealth involved.
LMSSQLServerADHelpersqladhlp.exeRelated to Microsoft SQL Server 2000 desktop engine.
XMSSvc CRSS (CRSS)MSSvc.EXEReported by Ewido security suite as Backdoor.SdBot.nj
Lmst Defrag ServicemstDfrgS.exeRelated to mst_Defrag
XMSTCSMSTCS.EXEReported as Backdoor.Iroffer TROJAN! by What-process.com
Xmstdel32 (mstdel32)mstdel32.exeAdded by the W32/Tilebot-BE WORM! Note: This worm rojan file is found in the System (95/98/ME) or Sy
XMsUpdmsupd5.exeAdded by the Lodmedud TROJAN!
XMsUpdmsupd4.exeAdded by the Lodmedud TROJAN!
XMsUpdmsupd6.exeAdded by the Lodmedud TROJAN!
XMSUpdate (Microsoft Update Service for 2005)msupdate24.exeAdded by the W32/Tilebot-H WORM!
Xmsvbnmsvbn.exeAdded by the Backdoor.Win32.SdBot.auv TROJAN! Note: This worm rojan is located in C:%WINDIR% folder.
Xmsvnc (msvnc)msvnc.sysAdded by the TROJ_ROOTKIT.M TROJAN! Read the link rootkit type stealth involved.
Xmsvrcs(msvrcs) (msvrcs)msvrcs.exeAdded by the W32/Sdbot-CRX WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
Xmuamgrd.exemuamgrd.exeAdded by a variant of the AGOBOT.GEN WORM! Note: located in C:WindowsSystem (Win9x/Me) C:%WINDIR%Sys
LMulti-user Cleanup Servicentmulti.exeRelated to IBM Lotus Note software.
LMWAgentMWASER.EXERelated to MicroWorld Technologies Inc. - Antivirus & Content Security suite. Note: Located in C:Pro
LMWSarcpktMWSEtherpkt.exeRelated to Gateway Ticketing Systems Inc. http://www.gatewayticketing.com/
LMWSejcapMWSejcap.exeRelated to Gateway Ticketing Systems Inc. http://www.gatewayticketing.com/
LMWSpollserverPollServer.exeRelated to Gateway Ticketing Systems Inc. http://www.gatewayticketing.com/
LMWSschedsutmsced.exeRelated to Gateway Ticketing Systems Inc. http://www.gatewayticketing.com/
LMWSTickMWSTick.exeRelated to Gateway Ticketing Systems Inc. http://www.gatewayticketing.com/
XMXS(mxs) (MXS)mxs.exeAdded by the W32/Sdbot-CTT WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
LMy Firewall PlusSmc.exeRelated to Webroot Firewall
LMyMedia ServerMyMediaServer.exeRelated to FUJITSU LIMITED
LMySqlmysqld-nt.exebelongs to MySQL Daemon. It is a service that handles the access to MySQL databases
LMySqlInventimemysqld-max-nt.exeRelated to MySQL database a popular open source database.
XMySrvShell Service (MySrvShell)(Path to Trojan EXE)Added by the Troj/WinterLv-C Trojan!
LNAI ePolicy Orchestrator Agent (NAIMAGENT32)naimas32.exeRelated to Network Associates anti-virus protection suite http://www.liutilities.com/products/wintas
LNAV Alertalertsvc.exeRelated to Symemtecn/Norton products
XNavegador de red (ExpIorer)ExpIorer.exeAdded by the Troj/Taladra-E TROJAN!
LNBServiceNBService.exeRelated to Nero Backup service. Note: Located in C:Program FilesNeroNero 7Nero BackItUp
LNDAS Service (ndassvc)ndassvc.exeRelated to XIMETA Inc. Smart Network Storage Solution.
XNDIS Adapter (NDIS TCP Layer Transport Device)ndis.exeAdded by the W32/Forbot-AX WORM! Note: This worm file is found in the System32 folder.
ndservndserv.exeRelated to NetDeploy_Launcher from Open Software Associates Ldt. a division of Managesoft.com Note:
Xneruo.exe (NeroFilterCheck)Explore.exeAdded by the SDBOT.DIH WORM! Read the link rootkit type stealth involved.
XNet Functions Library (Netlib)Netlib.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C: folder.
XNet Functions Monitoring (Netmon)Netmon.exeAdded by the W32/Codbot-R WORM!
XNet Service Monitornetsvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: Located in C:WINDOWS Note] Netsvc.exe: T
LNetBackup Client Service (NetBackup INET Daemon)bpinetd.exeRelated to VERITAS NetBackup Enterprise Server.
LNetBackup Volume Managerbevmd.exeRelated to VERITAS NetBackup Enterprise Server.
XNetBIOS Helpernbthlp.exeAdded by the W32.Toxbot.AL WORM! Note: Symantec has developed a removal tool to clean the infections
Xnetbios helper servicealtsvc.exeadserver adtech.de redirects
XNetBIOS Helper Service (NetBIOS Helper)nbthlp.exeAdded by the W32/Codbot-AE WORM! Note: This worm rojan file is found in the System32 folder.
XNetBTD(ntbtd) (NetBTD)netbtd.exeAdded by W32/Sdbot-BLW WORM! Note: located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32 (XP/WinN
XNetCNnetcn.sysAdded by the Hacktool.Rootkit TROJAN! Read the link rootkit type stealth involved.
XNetconDDE Service (NetconDDE)iisctrl.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
Xnetconf32 (netconf32)netconf32.exeAdded by the W32/Tilebot-BN WORM! Note: This worm rojan file is found in the Windows or Winnt folder
XNetDDE Server (NetDDEsrv)netddesrv.exeAdded by the W32/Codbot-Y WORM! Note: This worm rojan file is found in the System32 folder.
XNetDDEipx (NetDDEipx)randomAdded by the NetDDEipx TROJAN! **note 3ylv.exe may be one of the random file names used
XNETINFOnetinfo.exeAdded by the W32/Tilebot-J WORM! Read the link rootkit type stealth involved.
LNetLimiter (nlsvc)nlsvc.exeNetLimiter_2 shows list of all applications communicating over network.
XNetLogonsvchost.exe -k NetLogonAdded by the Fuwudoor TROJAN!
NetOp Helper ver. 7.50 (2002343) (NetOp Host for NT
NetOp Helper ver. 7.65 (2004242) (NetOp Host for NT
LNetropa NHK Servernhksrv.exeNetropa Hotkey Server task seen only on DELL and Compaq PCs running Windows NT4/2000/XP
LNetropa NHK ServerNhksrv.exenhksrv.exe is a process that belongs to DELL and Compaq systems. It is used to halt any configured h
LNetscape Update Servicencupdatesvc.exeNetscape Communications Corporation updater
XNetSendServer (NetSendServer)NetSend.exeAdded by the Troj/Hupigon-DQ TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
LNetSign AutoUpdate Service (NsAUSvc)NsAUSvc.exeRelated to SecurityFocus - http://www.securityfocus.com/
LNetVeda Safety.Net (ipcSvc)ipcsvc.exeRelated to Safety_net from Netveda. Security and advanced Internet firewall protection for all your
?Networknettcp.exeUnknown owner: Location C:WINDOWSsystem32 ettcp.exe
XNetwork ADSL Server (Network ADSL Server)woaisaomm.exeAdded by the Troj/GrayBrd-AQ TROJAN! Note: This trojan file is found in the System32 folder.
LNetwork Associates Task ManagerVsTskMgr.exeVirusScan Task Manager
XNetwork Client (nwclntg)winlogon.exeAdded by the Boxed.E TROJAN!
LNetwork Configuration Service (NetCfgSvr)NetCfgSv.EXERelated to AT&T http://www.anti-spy.info/process/netcfgsv.exe.html
XNetwork Connections Sharing (RpcTftpd)svchost.exeAdded by the W32.Welchia WORM! **Note - This service will be set to start manually
XNetwork DDE Client (NetDDEclnt)netddeclnt.exeAdded by the W32/Codbot-M WORM!
XNetwork dde connectionsservice.exeadtech.de redirections
XNetwork DDE Connections (NETDDEC)winmgnt.exeAdded by unknown malware the file winmgnt.exe may be a Serv-U FTP server used to download other mali
XNetwork DDE DSMA (NetDDEdsma)svchost.exeAdded by the W32/Sdbot-BMG WORM! Note: This is not the legitimate Windows Process. (Which is found i
XNetwork DDS (NetDDS)NetDDS.exeReported as Troj/ServU-Gen See Sophos Unknown owner :Location: C:WINDOWSsystem32NetDDS.exe
XNetwork Devices Controller (ndcsvc)random file nameAdded by the Alnica TROJAN!
XNetwork Devices Controller (ndcsvc)random.$$$Added by the Alnica TROJAN!
Network Distributed Transaction Coordinator for
XNetwork DRV (NTDRV)netdrvr.exeAdded by the W32/Sdbot-AZK WORM! Note: This worm file is found in the System or System32 folder.
XNetwork Gateway Manager (npx)csrsc.exeAdded by the W32/Sdbot-CPE WORM! Note: This worm rojan is located in C:%WINDIR%
XNetwork helper Service (MSDisk)irdvxc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XNetwork Location Managerlssc.exeAdded by the Trojan.Backdoor.Gen TROJAN! Note: This worm rojan is located in C:WindowsSystem (Win9x/
XNetwork Management Center Time (W32Times)TIMEMAN32.EXEAdded by the Troj/GrayBrd-AA TROJAN! Note: This worm rojan file is found in the Program FilesInterne
LNetwork Messenger (MStdc )mstdc.exeRelated to Microsoft Personal Web Server and Microsoft SQL Sever software http://www.2-files.com/pro
XNetwork Monitornetmon.exeReported by Panda as the Trj/Cicos.H TROJAN! This trojan if found in the Program FilesNetwork Monito
XNetwork Provision Managing Service (xmlprovman)provsvc.exeAdded by the W32/Sdbot-CRS WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
XNetwork Security ServicerandomCoolWebSearch res:// variant
XNetwork Security Service (NSS)randomCoolWebSearch res:// variant
XNetwork Station Task Manager (TASKSQ)tasksch.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
XNetwork Station Task Manager (TSKIB)taskib.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
XNetwork Windows Service (MSWindows)urdvxc.exeAdded by the W32/Allaple-B WORM! Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32 (XP/
XNetwork)MSVPN32.exeAdded by the W32/Rbot-AIO WORM!
LNI Service Locator (niSvcLoc)niSvcLoc.exeRelated to National_Instruments corp.
LNICCONFIGSVCNICCONFIGSVC.exeNICCONFIGSVC.exe is a process associated with the power management settings for network adapters on
LNICSer_WMP11NICServ.exeRelated to Linksys config utility.
Xninsvcninsvc.exeAdded by the W32/Akbot-AL WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%WI
Lnipxirmunipalsm.exeRelated to National_Instrument Corp.
LNMapnmapserv.exeNMapWin Port Scanner utility service.
LNMSAccessNMSAccess.exeRelated to Cheetah_DVD_Burner Note Must only be used on NT4/2000/XP
LNNSvcnnsvc.exeNetNanny Internet Filter
LNobleNet Portmapper for TCPportserv.exeActuate_Enterprise Reporting Applications for business intelligence analytic services
XNOD AV service (nodantivir)nodantivir.sysAdded by the Troj/Haxdoor-AK TROJAN! Note: This trojan file is found in the System32 folder. The fil
LNOD32 Kernel Service (NOD32krn)nod32krn.exeNOD32 Antivirus
LNofeel FTP Server Servicenftpdsvc.exeRelated to Nofeel_FTP_Server
LNoIPDUCServiceDUC20.exeRelated to Vitalwerks Internet Solutions
LNorman API-hooking helpernipsvc.exeNorman Anti-Virus
LNorman NJeevesNJEEVES.EXENorman Anti Virus
LNorman Type-RNPFSVICE.EXENorman Virus Control Service. Made by Norman Data Defense Systems Inc. For more information Click_He
LNorman Virus Control on-access componentnvcoas.exeNorman Virus Control on-access component
LNorman Virus Control SchedulerNVCSCHED.EXENorman Virus Control Scheduler
LNorman ZANDAZanda.exeNorman Anti Virus
LNortel Networks TunnelGuard (tunnelguardservice)CueAgent_srv.exeRelated to Nortel_Networks_TunnelGuard designed to ease the deployment of very large site-to-site an
XNorton antivirus and Firewall (it)fime.exeBogus Norton Antivirus and Firewall service. Unknown owner.
LNorton AntiVirus Auto-Protectnavapsvc.exeNorton AV leave it running.
LNorton AntiVirus Auto-Protect Service (navapsvc)navapsvc.exeRelated to Norton/Symantec AntiVirus.
LNorton AntiVirus Clientrtvscan.exeNorton Anti-virus related
LNorton AntiVirus Firewall Monitor Service (NPFMntor)NPFMntor.exeNorton Internet Worm Protection
LNorton GhostPQV2iSvc.exesymantec Norton Ghost Image related
LNorton Internet Security Accounts ManagerNISUM.EXERelated to Norton Internet Security
LNorton Internet Security Proxy ServiceSymProxySvc.exeRelated to Symantec Corporation
LNorton Internet Security ServiceNISSERV.EXERelated Symantec Corporation
XNorton Online Anti Virusavll32.exeAdded by the Backdoor.Win32.SdBot.aad reported by Kaspersky TROJAN! Note: This worm rojan is located
LNorton Personal Firewall Proxy ServiceSymProxySvc.exeRelated to Norton Firewall Proxy service
LNorton Personal Firewall ServiceNISSERV.EXERelated to Norton Personal Firewall service
LNorton Program Schedulernpssvc.exeRelated to Norton Scheculer
LNorton Protection Center Service (NSCService)NSCSRVCE.EXERelated to Norton Internet Security 2006 and Norton AntiVirus 2006. Made by Symantec_Corporation
LNorton Unerase ProtectionNPROTECT.EXENorton Protected Recycle Bin
LNotebook Manager Service (anbmService)anbmServ.exeRelated to Acer Notebooks Hardware Monitoring program. Made by OSA_Technologies Inc.
LNovell Application Launcher (NALNTSERVICE)NALNTSRV.EXENovell NAL NT service
LNovell Workstation Manager (WM)wm.exeNovell Workstation Manager
LNovell XTier Agent ServicesXTAgent.exe
LNovell ZfD Remote ManagementZenRem32.exe
LNPDOR File Monitor Service (NFMService)NPDORNT.exeRelated to NPD Online Research.
XNPFnpf.sysAdded by the Troj/NtRootK-I TROJAN! Note: This trojan file is found in the System32 folder.
Lnpkcsvcnpkcsvc.exeINCA Internet
XNS (MSLLR)ns.exeW32/Agobot-HS
LNsEngineNSENGINE.exeScheduling engine of NovaSTOR Backup Service
XNT login service (ntlogin32)libsys32.exeAdded by the W32/Sdbot-ACK WORM!
XNT login service - Unknownlibsysmgr.exeAdded by the W32/SDBOT-CAF WORM! (Castle Cops)
LNT Online ProtectionONLNSVC.EXERelated to AntiVirus_Quick Heal Virus protection. Note: located in C:Program FilesQUICKH~1
XNt System Kernelntsyskrnl.exerelated to WORM_AGOBOT.IK
XNTBOOTMGRntuser.exeFlagged as Backdoor.Iroffer / Backdoor.Noer
LNTCHARGEwinlogon.exeRelated to Microsoft Internet Information Services (IIS).
XNTFS Crypto Technology (NTFSCrypt)ntfscrypt.exeAdded by the W32/Spybot-NC WORM! Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32 (XP/
XNTFS File Location Service (NTFSFLS)ntfsloc.exeAdded by the W32/Sdbot-CSG WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
XNTFSprotect (ntfsdiscman)ntfsprotect.exeAdded by the SDBOT.CCF WORM! Read the link rootkit type stealth involved.
XNtlm_Drive_Connect (Ntlm_Drive_Connect)TimerU.sysAdded by the Tuimer TROJAN!
XNTLOADntsrv.exeFlagged as Backdoor.Iroffer / Backdoor.Noer
XNTLOADwinlogon.exeOther files in the same directory identified as Win32.Iroffer.b by Kaspersky
Xntmssvcsvchost.exe -k ntmssvcAdded by the Fuwudoor TROJAN!
XNTP (Network Time Protocol)winlogon.exeAdded by the Troj/Jtram-D TROJAN! Note: This trojan file is found in the System32Client folder.
LNTRU Hybrid TSS v1.05 TCSD (tcsd_win32.exe)tcsd_win32.exeRelated to NTRU_Cryptosystems Inc. Provider a public key cryptography system (PKCS)
XNTSec(ntsec) (NTSec)ntsec.exeIdentified as Trojan-Dropper.VB.22 by VBA32 Note: located in C:WindowsSystem (Win9x/Me) C:%WINDIR%Sy
ONTSecuresrvany1234.exeUnknown owner: Location C:WINDOWSsystem32srvany1234.exe
XNTSVCMGRwinlogon.exeOther files in the same directory identified as Win32.Iroffer.b by Kasperksy
ONTSVCMGRwinlogon.exeCreates a file win32.dll C:windowssystem32 and the old one is renamed win32.dll.bkup
XNTSVCMGRntsrv.exeFlagged as Backdoor.Iroffer / Backdoor.Noer
LNTsyslogntsyslog.exeRelated to Open_Source_Technology Group. An application logging functionality.
LnTune Service (nTuneService)nTuneService.exeRelated to NVIDIA Access Manager. Note: Located in C:Program FilesNVIDIA Corporation Tune
LNuTCRACKER Kernelnutkserv.exeRelated to openUTM from Fujitsu Siemens Computers
LNuTCRACKER Servicenutsrv4.exeRelated to Rational Rose MKS Toolkit for Enterprise Developers
XNvCplScanmsc32.exeRelated to the W32/FORBOT-DD
XNvCplScannvsc32.exeanother example added by Forbot_ET.
LNvedavtousbehci.sysRelated to OrangeWare Corp.
XnvidGUIv (nvidGUIv2)NVIDGUIV.EXEAdded by the SDBOT.CTQ WORM! Read the link rootkit type stealth involved.
LNVIDIA Display Driver Servicenvsvc32.exeNVidia
LNVIDIA Driver Helper Servicenvsvc32.exeRelated to NVIDIA drivers.
XNVIDIA Driver Service¡¡ (NVSv )svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XNvidia Graphic Displacement (nvideoGUI)nvideogui.exeAdded by the SDBOT.CQD WORM! Read the link rootkit type stealth involved.
LNVIDIA PVR Schedule Monitor (nvpvrmon)nvpvrmon.exeRelated to NVIDIA ForceWare driver. Note: Located in C:Program FilesNVIDIA CorporationForceWareMulti
Xnvsec(nvsec) (NvSec)nvsec.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
Xnvsvc32.exewmisp.exeAdded by the Backdoor_Win32_SdBot_aad WORM! - Reported by KASPERSKY ON-LINE SCANNER
LO&O CleverCache Agent (OOCleverCacheAgent)ooccag.exeRelated to O&O_Software Products. Located in folder: OO SoftwareCleverCache
LO&O ComponentInstaller Agentoocinst.exeRelated to O&O software Protection Software
LO&O Defragoodag.exewww.oo-software.com
LO2Micro Flash Memory (O2Flash)o2flash.exeRelated to O2Micro_Flash Memory Card. Note: Located in C:WINDOWSsystem32
Odyssey Client for Fujitsu Siemens Computers
XOESH (Office Source Engine Help)Program.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C: folder.
Office Server Extensions Notification Service
LOffice Source Engine (ose)OSE.EXEMicrosoft Office Source Engine
LOfficeScanNT Listenertmlisten.exepart of the Trend Micro Anti Virus application (WinTasks Process Library)
LOfficeScanNT Personal Firewall (OfcPfwSvc)OfcPfwSvc.exeRelated to Trend Micro Inc. - http://www.trendmicro.com/
LOfficeScanNT RealTime Scanntrtscan.exea process associated with the Trend Micro Antivirus application (WinTasks Process Library)
LOlCamSrvOlCamSrv.exeRelated to: Olympus_America Inc. Imaging services
LOM Common Services (omsad)omsad32.exeRelated to Dell Open Management system.
LOmniForm Printerofps.exeRelated to Nuance_Communications Inc. (Peviously Scansoft Inc.) A leading supplier of imaging speech
LOmniquad MyPrivacympsvc.exeRelated to Omniquad Security's MyPrivacy Internet tracks cleaning tool.
LONC/RPC PortmapperPORTMAP.EXERelated to Bell_and_Howell
LOnline Backup Servicents.exeRelated to Online_Backup_Service From Acpana Business Systems. Note: Located in C:Program FilesAcpan
LOpcEnumOpcEnum.exeOPC_Foundation Sets Industry standards in Interoperability of Automation.
XOpen GL DriversopenGLD.exeAdded by the SDBOT.CLW WORM! Read the link rootkit type stealth involved.
LOpenAFS Client Service (TransarcAFSDaemon)afsd_service.exeOpenAFS is a distributed filesystem product pioneered at Carnegie Mellon University
XopenSSLopenSSL32.exeAdded by the W32/Spybot-MY WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
LOpenVPN Service (OpenVPNService)openvpnserv.exeBelongs to Open VPN that seems to be a Linux VPM program that runs under Windows. File found in the
Oracle Forms Server [Forms60Server-OraForm]
LOracle OLAP 9.0.1.0.1 (OLAPServer)xsolap.exeRelated to Oracle_OLAP an option to Oracle Database 10g Enterprise Edition. Note: located in C:oracl
LOracle OLAP Agentxsaagent.exeRelated to Oracle_OLAP an option to Oracle Database 10g Enterprise Edition. Note: located in C:oracl
LOracle Reports Server [Rep60_PDB-LAPTOP-OraDevHome]rwmts60.exeRelated to Oracle products
LOracle WebDb Listenerwdblsnr.exeRelated to Oracle products
LOracle%ORACLE_HOME_SERVICE%ClientCache80ONRSD80.EXERelated to Oracle Networking (Net8 Server Executable)
LOracleDBConsoleorclnmesrvc.exeRelated to Oracle_DB_10g Database. Note: Located in C:...oracle10gin User can install in own folder
LOracleMTSRecoveryServiceomtsreco.exeRelated to Oracle SQL database application
LOracleOraDb10g_home1iSQL*Plusisqlplussvc.exeRelated to Oracle_DB_10g Database. Note: Located in C:...oracle10gin User can install in a folder o
LOracleOraHome90Agentagntsrvc.exeRelated to Oracle Intelligent Agent used to run on a remote node in the network to make the node OEM
LOracleOraHome92PagingServerpagntsrv.exeRelated to Oracle products
LOracleOraHome92TNSListenerTNSLSNR.exeRelated to Oracle products
LOracleOraHomeAgentdbsnmp.exeRelated to Oracle products
LOracleOraHomeClientCacheONRSD.EXERelated to Oracle products
LOracleOraHomeDataGatherervppdc.exeRelated to Oracle products
LOracleOraHomeHTTPServerApache.exeRelated to Oracle products
LOracleOraHomeManagementServerOMSNTsrv.exeRelated to Oracle products
LOracleOraHomePagingServerpagntsrv.exeRelated to Oracle products
LOracleOraHomeTNSListenerTNSLSNR.exeRelated to Oracle products
LOracleServiceLOCALORAORACLE.EXERelated to Oracle products
LOracleServiceSECINSTORACLE.EXERelated to Oracle products
LOracleWebAssistantOWASTsvr.exeRelated to Oracle products
LOracleXEClrAgentOraClrAgnt.exeRelated to Related to Oracle products Note: Located in C:oraclexeapporacleproduct10.2.0serverin
XORANORAN.SYSAdded by the TROJ_ROOTKIT.N TROJAN! Read the link rootkit type stealth involved.
Xorans (orans)orans.sysAdded by the Troj/Rootkit-AA TROJAN! Read the link rootkit type stealth involved.
LOrbMediaServiceOrbMediaService.exeOwner:Orb Networks
LORBPVROrbPVR.exeOwner: Unkown http://www.orb.com/
LOSCM Utility ServiceOSCMUtilityService.exeRelated to Novatel Wireless Service from Sprint phones and connectivity cards. Note: Located in C: P
LOTi Card Reader ServiceOTiReader.exeOTI_Globals contact/contactless smart card reader. Location: Program FilesCardReader2.0 folder.
LOutpost Firewall Servicesoutpost.exeAgnitum Outpost firewall service
LOvEpStatusEngineOvEpStatusEngine.exeHP OpenView Status Engine
LOvMsmAccessManagerOvMsmAccessManager.exeHP OpenView Access Manager
LOvSecurityServerOvSecurityServer.exeHP OpenView Security Server
LOwnershipProtocolOProtSvc.exeRelated to PROSet Wireless Software from Intel
XP correction service (msrdr2)msrdr2.sysAdded by the Troj/Haxdoor-AJ TROJAN! Note: This trojan file is found in the System32 folder.
XP-SYS (P-SYS Service)TERMSVRS.EXEAdded by the SDBOT.DEO WORM! Read the link rootkit type stealth involved.
LPacific Image Comm. Fax ServerPICPMON.EXERelated to SuperVoice Specialists in Voice Mail and Fax systems
XPack 2 Services)servicepack2Added by the SDBOT.COP WORM! Read the link rootkit type stealth involved.
LPacket SchedulerService.exeRelated to Packet_Scheduler from Microsoft. The packet scheduler decides the order in which packets.
LPACSPTISVRPACSPT~1.EXE PACSPTISVR.exeSony computers
LPanasonic Trap Monitor ServiceTrapmnnt.exeRelated to Panasocic_Trap_Monitor for printer service. Note: Located in C:PROGRAM FILESPANASONICTRAP
LPanda AdminSecure Administration Server (AdminServer)AdminServer.exeRelated to Panda Security programs.
LPanda AdminSecure Communications Agent (PAVAGENTE)Pagent.exeRelated to Panda Security programs.
LPanda AdminSecure Distribution Server (PadFSvr)PadFSvr.exeRelated to Panda Security programs.
LPanda AdminSecure Scheduler (PavAtScheduler)pavsched.exeRelated to Panda Security programs.
LPanda anti-virus servicepavsrv51.exePanda Anti-virus Service
LPanda anti-virus service (PAVSRV)pavsrv50.exeRelated to Panda Security programs.
LPanda Antispam Engine (pmshellsrv)pskmssvc.exeRelated to Panda Platinum 2006 Internet Security.
LPanda Antispam Server ServicePaSSrv.exeRelated to Panda Protection Software.
LPanda Antivirus Report Service (PavReport)PavReport.exeRelated to Panda Security programs.
LPanda FirewallPavFires.exePanda Firewall Service
LPanda Firewall ServicePavFires.exeRelated to Panda Firewall
LPanda Function ServicePavFnSvr.exeRElated to Panda Antovirus software
LPanda Function Service (PAVFNSVR)PavFnSvr.exeRelated to Panda Security programs.
LPanda IManager ServicePsImSvc.exeRelated to Panda Titanium Antivirus
LPanda Network Manager (PNMSRV)PNMSRV.EXERelated to Panda Firewall.
LPanda NetworkSecure Service (CPntSrv)CPntSrv.exeRelated to Panda Security programs.
LPanda PavkrePavkre.exeRelated to Panda Titanium Antivirus
LPanda PavProtPavProt.exeRelated to Panda Titanium Antivirus
LPanda Preventium+ Serviceprevsrv.exeRelated to Panda Titanium Antivirus
LPanda Process Protection Servicepavprsrv.exeRelated to Panda Software
LPanda Software ControllerPSCTRLS.EXERelated to Panda Security programs.
LPanda TPSrv (TPSrv)TPSrv.exeRelated to Panda Platinum 2006 Internet Security and Panda Titanium 2006 Antivirus Antispyware.
LPantech&Curitel Utility ServicePnCUtilityService.exeRelated to Sprint Internet Service Provider.
LPatchLink UpdateGRAVITIXSERVICE.exePatchlink_Update by Patchlink Corporation
LPATROL for Windows Operating System Monitor (PWKNTMon)pwkntmon.exeRelated BMC Software Inc. - http://www.bmc.com/
LPatrolAgentPatrolAgent.exeRelated BMC Software Inc. - http://www.bmc.com/
LPatrol_SchedulerPatrol_Scheduler.exeRelated BMC Software Inc. - http://www.bmc.com/
LPC Tools Spyware Doctorsdhelp.exeRelated to PC Tools' Spyware_Doctor
LPC-cillin PersonalFirewallPCCPFW.exeRelated to Trend Micro Inc. Firewall
LpcAnywhere Host Serviceawhost32.exePart of Symantec's pcAnywhere remote PC management software.
LPCHostpchost.exeRelated to PCHost
Xpcryptv3Xpcryptv3.exeAdded by the W32/Tilebot-AS TROJAN! Note: This worm rojan file is found in the Windows or Winnt fold
LPCS Business Connection Personal Edition ServiceConnectionService.exeRelated to sprint.com ISP
LPCTEL Speaker Phonepctspk.exeDiagnostic tool for PCtel modem.
LPDEnginePDEngine.exeRaxco PerfectDisk
LPDFCreatorMessagesPDFCreatorMessages.exeRelated to Global_Graphics_Software Ltd. Document and Print Solutions.
LPDSchedulerPDSched.exeRaxco PerfectDisk
XPE Sytray Managerssmc.exeAdded by the Backdoor.SdBot.avk as detected by ewido. More here
LPER Antivirus (pav_service)PERVAC.EXEAntivirus software from PER Systems. http://www.perantivirus.com/antivir.htm
LPER Antivirus Security Service (pav_security)PAVSS.EXEAntivirus software from PER Systems. http://www.perantivirus.com/antivir.htm
XPerformance Logs (Perfhmon)Perfhmon.exeAdded by the W32/Codbot-W WORM!
XPerformance True Type Fonts (PerfFont)perfont.exeIdentified as Trojan-Downloader.Win32.Agent.acv by ewido security suite.
LPersits Software EmailAgentEmailAgent.exeRelated to AspEmail from Persits Software Inc. A free active server component that enables your ASP
Personal Secure Drive Service
LPervasive.SQL 2000 (relational)W3SQLMGR.EXEPervasive SQL Server
LPervasive.SQL 2000 (transactional)NTBTRV.EXEPervasive SQL Server
LPestPatrol RemoteppRemoteService.exeRelated to PestPatrol products from Computer Associates International Inc.
XPEXpex.sysAdded by the Troj/RKFu-A TROJAN! Read the link rootkit type stealth involved.
LPGPsdkServicePGPsdkServ.exePGP Software
LPGPservPGPserv.exeRelated PGP Corp. http://www.pgp.com/
LPHAROS Distribution Agent (PSDistributionAgent)DistAgnt.exeRelated to Pharos_Science_ & Applications Inc. Pharos develops advanced GPS navigation and mobile lo
LPharos Systems ComTaskMasterCTskMstr.exeRelated to Pharos_Systems print asset management. Note: Located in C:PROGRAM FILESPharosin
LPhoenix VCD Service (PhnxVCDService)PhnxCDSvr.exeRelated to Phoenix_Technologies
LPhotoshop Elements Device ConnectPhotoshopElementsDeviceConnect.exeRelated to Adobe photoshop.
LPI Message Subsystem (pimsgss)pimsgss.exeRelated to OSI_Software Real-time Performance Management (RtPM) Platform. Note: located in C:Program
LPI Network Manager (pinetmgr)pinetmgr.exeRelated to OSI_Software Real-time Performance Management (RtPM) Platform. Note: located in C:Program
LPI-Buffer Server (bufserv)bufserv.exeRelated to OSI_Software Real-time Performance Management (RtPM) Platform. Note: located in C:Program
LPictureTakerPCTKRNT.SYSLANovation's PictureTaker Enterprise Edition 3.1 lets administrators create software update packages
XPigeon (PigeonServer)GServer2.exeAdded by the Troj/GrayBrd-AK TROJAN! Note: This worm rojan file is found in the System (95/98/ME) or
XPigeon_Server (PigeonServer)Server.exeAdded by the Backdoor.Graybird.R TROJAN! Note: This trojan file is found in the Windows or Winnt fol
Pinnacle Systems Media Service
LPinnacle Systems tvtv Spooler (EpgSpooler)epgspo~2.exeRelated to Pinnacle Studio Plus.
LPIPC Log Server (pilogsrv)pilogsrv.exeRelated to OSI_Software Real-time Performance Management (RtPM) Platform. Note: located in C:Program
LPixar Alfred Server 11.5.3alfserver.exeRelated to Pixar_Alfred_Server Server includes all the tools required for rendering images for film
XPixelModule (pxlmdl)nvidcgui.exeAdded by the W32/Tilebot-GS WORM! Read the link rootkit type stealth involved.
LPLFlash DeviceIoControl ServiceIoctlSvc.exeRelated to PLFlash_DeviceIoControl Service from Prolific Technology Inc. Note: located in C:WindowsS
OPLSRemote Service (PLSRemoteSvc)PLSRemote.exeRISKWARE! or potentially unwanted application. This application may have been installed by your syst
LPlug and Playservices.exeSpanish Windows 2000 Plug and Play
XPlug and Play Device Manager ($sys$DRMServer)$sys$DRMServer.exeThis is the Sony-BMG ROOTKIT! Do not try to manually remove this! For more information check Mark Ru
XpluginPLUGIN.EXEAdded by the SDBOT.BUH WORM! Read the link rootkit type stealth involved.
Lpml
Lpml
LPml DriverHPHipm09.exeRelated to HP printers
LPml Driver HPH11HPHipm11.exeHP PML Driver for HP.s Photosmart printers.
LPml Driver HPZ12HPZipm12.exeRelated to HP printers.
Lpmldriver hpz12
LPMounterPMounter.exePartition Mounter task installed with the Paragon Hard Disk Manager software. (answers that work)
LPMSveHPMSveH.exeRelated to Lenovo part or IBM ThinkVantage Note: Located in C:WINDOWSsystem32
Xpnpextwmc.exeAdded by the Troj/LeechPie-D TROJAN! Note: The file wmc.exe is a legitimate remote administration to
XPolicy Agentsvchost.exe -k Policy AgentAdded by the Fuwudoor TROJAN!
LPop-Up Stopper Anti-Spyware Service (PWISVC)PWISVC.EXERelated to Pop-Up_Stopper_Anti-Spyware from Panicware. Note: Located in C:Program FilesPanicwarePop-
LPort Reporterportreporter.exePort Reporter is a Microsft made utility information available
LTOSHIBA HDD Protection (Thpsrv)ThpSrv.exeRelated to The Toshiba_HDD_Protection TOSHIBA HDD Protection&hl=en&lr=lang_en|lang_fr system is an i
LTOSHIBA Optical Disc Drive Service (TODDSrv)TODDSrv.exeRelated to Toshiba_Optical_Disk_service RAID Backup utility. Note: Located in C:WINDOWSsystem32TODDS
LTOSHIBA RAID Service (kraidsvc)kraidsvc.exeRelated to Toshiba_Raid_Service Note: Located in C:Program FilesTOSHIBATOSHIBA RAIDService
XTrace network connections (ACCRA)mocih.exeAdded by the Chimo.B TROJAN!
LTrack-It! Remote Controlwuser32.exeRelated to Quicken/Intuit Inc. - http://www.quicken.com/
LTrack-It! Workstation ManagerTIRemoteService.exeRelated to Quicken/Intuit Inc. - http://www.quicken.com/
LTranscoding and Broadcast Service (Transcode360)transcode360.exeTranscode360 Designed for Windows XP Media Center Edition 2005 and the Xbox 360 Transcode 360 aims t
Transparent Screen Lock PRO Service (TSL PRO Lock
LTrapRcvrtrthread.exeRelated to the monitoring a particular system performance. See here
LTrayManntstart.exeTray Manager lets you put systemtray icons into a submenu to save space
LTrend Micro Central Control ComponentPcCtlCom.exeRelated to Trend Micro Incorporated.
Trend Micro Management Infrastructure (TrendMicro
LTrend Micro Personal FirewallTmPfw.exeRelated to Trend Micro Inc.
LTrend Micro Protection Against Spyware (PcScnSrv)PcScnSrv.exeRelated to Protection_Against_Spyware from Trend Micro. Note: Located in C:Program FilesTREND MICROI
LTrend Micro Proxy Servicetmproxy.exeRelated to Trend Micro Inc.
LTrend Micro Real-time ServiceTmntsrv.exeRelated to Trend Micro Incorporated.
XTrkSvrsvchost.exe -k TrkSvrAdded by the Fuwudoor TROJAN!
XTrkWkssvchost.exe -k TrkWksAdded by the Fuwudoor TROJAN!
Trlokom Central Management Helper 1.3.8 0
LTrueVector Basic Logging Client (minilog)minilog.exeRelated to Zone_Alarm_Firewall from Zone Labs Inc.
LTrueVector Internet Monitorvsmon.exeZone Alarm Firewall
LTrusted Platform Core Service (IFXTCS)IFXTCS.exeRelated to Trusted Platform Core Service from Infineon Technologies. Note: Located in C:WINDOWSsyste
Xtsecuretsecure.exeAdded by the W32/Tilebot-B WORM! Note: Gives the fake description Terminal Security. Read the link r
LTSI Remote Control Service (TSIRCSRV)TSIRCSRV.EXERelated to Laplink_Gold Software Inc. Connect to other Laplink-enabled computers over any connection
XTskSchedulertaskshed.exeAdded by the W32/Tilebot-FN WORM! Note: This worm rojan is located in C:%WINDIR% folder.
LTSMServicetsmsvc.exeT-DSL SpeedManager from T-Com_T-Online Note: File location is in the Program FilesT-DSL SpeedManager
LTSS Core Service (TSSCoreService)ibmtcsd.exeRelated to IBM ThinkVantage Client
LTuneUp WinStyler Theme ServiceWinStylerThemeSvc.exePart of TuneUp Utilities
LTVT Backup Servicerrservice.exeRelated to IBM ThinkVantage Rescue and Recovery
LTVT Schedulertvtsched.exeRelated to IBM ThinkVantage Scheduler
Ltwdnsnamed.exeRelated to TreeWalk_DNS TreeWalk DNS is a Domain Name Server program which fetches and converts Web
LTZO Client (TZONTService)TZO_NT_Service.exeRelated to TZO_DNS a leading Dynamic DNS (DDNS) service provider.
XUDP Sub Packet Classifier (UDPSPC)MSUDPSPC.EXEAdded by the SDBOT.CBF WORM! Read the link rootkit type stealth involved.
LUDS Environment Manager 5.0.14nodemgr.exeRelated to Forte_4GL_System from Sun Microsystems Inc.
LUDS Environment Manager 5.1.3nodemgr.exeRelated to Forte_4GL_System from Sun Microsystems Inc.
LUDS Repository Manager 5.0.14rpserver.exeRelated to Forte_4GL_System from Sun Microsystems Inc.
LUDS Repository Manager 5.1.3rpserver.exeRelated to Forte_4GL_System from Sun Microsystems Inc.
LUlead Burning HelperULCDRSvr.exeUlead DVD Burning Service
LUlead Burning Helper (UleadBurningHelper)ULCDRSvr.exeRelated to Ulead_DVD_workshop allows the writing to DVD and CD media.
LUnicenter Message Queuing Servercam.exeRelated to Computer Associates Inc.
LUnicenter Remote Control Host (rcHost)rcHost.exeRelated to Unicenter_Remote_Control_Host From Computer Associates Note: Located in C:BA_MGMTTNGRCORC
LUnicenter Software DeliverySDSERV.EXERelated to Unicenter Asset Management by Computer_Associates
XUniversal Serial Bus Control Protocol (pnpext)smrs.exeAdded by the Troj/Bdoor-JD TROJAN!
?Unknownwisptis.exe
LUnknown ownerwtxregds.exepart of development software for microprocessors.
LUnrealIRCdwircd.exeRelated to UnrealIRCd
XUPSups32.exe -vAdded by the W32/Mofei-H WORM!
LUPS - APC PowerChute plus (UPS)ups.exepower management application from APC PowerChute.
LUPS - UPSentry Service (UPSentry_Smart)upsd.exeRelated ro Belkin_Bulldog Plus control software for the UPS (Uninterrupted Power Supply) via a seria
LUPS Service (CyberPowerUPS)upssrv.exeCyber Power PowerPanelPlus software. In the event of a power outage PowerPanelPlus Software automati
LUPSMONServiceUPSMON_Service.ExeRelated to UPSMON Power Management Software. Made by Powercom_USA This file is found in the Program
LUS30ServiceUS30Service.exeRelated to Everstrike Software. Folder protection tool.
XUSB Devicewin32usb.exehttp://www.sophos.com/virusinfo/analyses/w32forbotbq.html
XUSB sks2drvr (sks2drvr)sks2drvr.sysAdded by the Backdoor.Haxdoor.G TROJAN! Note: This trojan file should be found in the System32 folde
XUSB sksDRVR2 (sksdrvr2)sksdrvr2.sysAdded by the Troj/Haxdoor-AL TROJAN! Note: This trojan file is found in the System32 folder.
LUSBest Service Zero (UTSCSI)UTSCSI.EXERelated to USBest PQI Card Drive (USB). Note: Located in C:%WINDIR%System32 (XP/WinNT/2K)
LUSBMateusbmate.exeRelated to Belkin_USB products. Note: located in C:Program FilesBelkinBelkin Power Management Softwa
XUSBTest (USBTest)USBTest.sysAdded by the Troj/RKPort-Fam TROJAN! Note: This trojan file is found in the System32drivers folder.
XUser Initialization (usrinit32)userinit.exeAdded by the IRC/BackDoor.SdBot2.QV as detected by Avast AVG. TROJAN! Note: This worm rojan is locat
XUser Mode Driver-Managerwdfmgrr.exeAdded by the W32/Sdbot-ZN WORM! Note: This worm rojan is located in C:%WINDIR% folder.
LUser Profile Hive Cleanup (UPHClean)uphclean.exeuphclean.exe is a process belonging to Microsoft's User profile cleanup service. This program is non
XUserinit Logon Verification (UsrInitVerif)userinit.exeAdded by the W32/Tilebot-EV WORM! Located in the Windows or Winnt folder.
Users service for disk management requests (Logical
LUStorage Server ServiceUStorSrv.exeRelated to OTi Imation Disk Manager II
LVAIO Cooporated Initialisation (VCI)VCI_SVC.exeSony VAIO computers
LVAIO Entertainment Aggregation and Control ServiceVzRs.exeSony VAIO computers
LVAIO Entertainment Database Service (VzCdbSvc)VzCdbSvc.exeRelated to Sony's VAIO Entertainment Platform.
LVAIO Entertainment File Import ServiceVzFw.exeSony VAIO computers
LVAIO Entertainment Task SchedulerVzTaskScheduler.exeSony VAIO computers
LVAIO Entertainment TV Device Arbitration ServiceVzHardwareResourceManager.exeSony VAIO computers
LVAIO Entertainment UPnP Client AdapterVCSW.exeSony VAIO computers
LVAIO Event ServiceVESMgr.exeSony VAIO computers
LVAIO Media Gateway ServerVmGateway.exeSony VAIO computers
LVAIO Media Integrated ServerVMISrv.exeSony VAIO computers
LVAIO Media Integrated Server (HTTP)SV_Httpd.exeSony VAIO computers
LVAIO Media Integrated Server (UPnP)UPnPFramework.exeSony VAIO computers
LVAIO Media Music ServerSSSvr.exeRelated to Sony Corporation
LVAIO Media Music Server (HTTP)sv_httpd.exeRelated to Sony Corporation
LVAIO Media Music Server (UPnP)UPnPFramework.exeRelated to Sony Corporations.
LVAIO Media Photo ServerPhotoAppSrv.exeRelated to Sony Corporation.
LVAIO Media Photo Server (Application)PicAppSrv.exeRelated to Sony Corporation
LVAIO Media Photo Server (HTTP)SV_Httpd.exeRelated to Sony Corporations.
LVAIO Media Photo Server (UPnP)UPnPFramework.exeRelated to Sony Corporation.
LVAIO Media Video ServerGPVSvr.exeSony VAIO computers
LVAIO Media Video Server (HTTP)SV_Httpd.exeSony VAIO computers
LVAIO Media Video Server (UPnP)UPnPFramework.exeSony VAIO computers
XValidation Service)devldr32.exeAdded by a variant of the WIN32.RBOT WORM! - Note - do NOT confuse with the legitimate Creative Labs
XVanquish Autoloader v0.1 beta10 (Vanquish)vanquish.dllVanquish Autoloader
XVanquish Autoloader v0.1 beta10 (Vanquish)vanquish.exeVanquish Autoloader
XVANTI (VANTI)God.sysAdded by the Troj/Hackvan-A TROJAN! Note: The file ranx.dll may also be added with this one both fil
LVentriloventrilo_svc.exeRelated to Venbtrilo Server/Client. Note: located in C:Program FilesVentSrv
LVeoh Client ServiceVeohClientService.exeRelated to Veoh Network. Create your own video blogs to share with friends. Note: Located in C:Progr
LVeriSign Updater (navi)naviagent.exeRelated to VeriSign Update Agent. Note: Located in C:Program FilesVeriSignNAVI
LVET Message Service (VETMSGNT)VetMsg.exeRelated to Computer_Associate Antivirus and offers real-time protection against Internet-bound threa
Xvirdrv (virdrv)virdrv.sysAdded by the TROJ_ROOTKIT.N TROJAN! Read the link rootkit type stealth involved.
LViRobot Expert Monitoring (vrmonsvc)vrmonsvc.exeSecurity software related to HAURI Inc. - http://www.hauri.net/
LVirtual CD v4 Security service (SDK - Version)vcssecs.exeVirtual CD SDK Security Service. Essential for the proper running of Virtual CD.
LVirtual CD v4 Security service (VCDSecS)vcdsecs.exeRelated to H H Software GmbH - http://www.hh-software.com/
LVirtual CD v5 Security service (VC5SecS)VC5SecS.exeRelated to Virtual_CD from H H Software and provides player support for CDs and CD images. Note: Loc
OVirtual Manager System (vmsprog)vmsprog.exeEmailSpy email monitoring program and surveillance tool
LVirtual NIC ServicePackethSvc.exeRelated to America Online Inc.
XVirtualMGRmssvc128.exeAdded by the Troj/Klutz-A Trojan!
LVirtuozzo Update Service (vzupsvc)vzupsvc.exeRelated to Virtuozzo from SWsoft Inc. Virtuozzo creates isolated partitions or virtual environments
XVIRTwin (vdmt16)vdmt16.sysAdded by the Troj/Haxdoor-AF TROJAN!
Xvirus shield enable (vshield.exe)vshield.exeAdded by the SDBOT.CBE WORM! Read the link rootkit type stealth involved.
LVisibroker Activation Daemonoad.exeBorland Visibroker
LVisiBroker Smart Agentosagent.exeBorland Visibroker
XVista ReadyService (VistaRS)readysrv.exeAdded by the W32/Sdbot-CTZ WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
XVista32Vista32.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
LVisual Studio Analyzer RPC bridgevarpc.exehttp://www.fileproperties.com/v/VARPC-EXE.htm
Vital Microsoft Sub-system Resource (Vital Microsoft
Xvmsdrv (vmsdrv)vmsdrv.sysAdded by the TROJ_ROOTKIT.AF TROJAN! Read the link rootkit type stealth involved.
LVMware Authorization Servicevmware-authd.exeRelated to VMware Inc.
XVMWare Authorization Servicec (GrayPigeonServer)Server.exeAdded by the Backdoor.Graybird.O TROJAN! {red] Note: this trojan file is located in the Program File
LVMware DHCP Servicevmnetdhcp.exeRelated to VMware Inc.
LVMware NAT Servicevmnat.exeRelated to VMware Inc.
LVMware Registration ServicevmserverdWin32.exeRelated to VMware Inc.
LVMware Tools ServiceVMwareService.exeRelated to VMware inc.
LVMware Virtual Mount Manager Extendedvmount2.exeRelated to VMWare Inc.
LVNC ServerWinVNC.exeTightVNC Remote Control utility.
LVNC Server Version 4 (WinVNC4)WinVNC4.exeThe RealVNC 4 server for VNC usage over a LAN/WAN.
XVolMapDevVolMapDev.sysAdded by the TROJ_ROOTKIT.AQ TROJAN! Read the link rootkit type stealth involved.
LVPN 5000 Service 1.00.00 (VPN5000Service)vpn5000service.exeRelated to Cisco Systems Inc. - http://www.cisco.com/
XVPNonDemand (VPNonDemand)VPN.exeAdded by the W32/Tilebot-G WORM! Read the link rootkit type stealth involved.
LVRServiceVrService.exeRelated to Panasonic Matsushita Electric Industrial Co.
LVsclient Service (VnxService)vnxserv.exeRelated to InfoExpress provides network access control solutions. More Note: Located in C:%WINDIR%Sy
LW2K PCtel speaker phonepctspk.exeRelated to PCtel services
XW32Timesvchost.exe -k W32TimeAdded by the Fuwudoor TROJAN!
LWAN Miniport (ATW) Service (WANMiniportService)wanmpsvc.exeRelated to America_Online Inc. The AOL suite's connectity relies upon this file heavily so if AOL is
LWARSVRwar-ftpd.exeThis is an FTP server.
LWasher Security Access (wwSecSvc)wwSecure.exeRelated to one of the Webroot_Internet_Security programs. The file associated with this service is l
OWDelMgr20WDelMgr20.exeSeems to be related to the RecoverLost Data or BackUp MyPC program by StompSoft
XWDNDrive (chgsprt)chgsprt.sysAdded by the Troj/Haxspy-A TROJAN!
XWeb Live Information Messengerwebmsn.exeAdded by the W32/Sdbot-CWA WORM! Note: This worm rojan is located in C:%WINDIR% folder.
LWeb Update Service by PowerProgrammer (WebUpdate)WebUpdateSvc.exeRelated to POWERPROGRAMMER.CO.UK A user friendly way to look for and download updates via the web to
LWebDrive Service (WebDriveService)wdservice.exeRelated to WebDrive FTP service. Note: Located in C:Program FilesNetDrive
LWebroot Admin Console (WebrootAdminConsole)WebrootAdminConsole.exeRelated to Webroot_Software
LWebroot Client Service (WebrootEnterpriseClientService)WebrootClientService.exeRelated to Webroot_Software
LWebroot Client Service (WRConsumerService)WRConsumerService.exe

Belongs to webroots spysweeper. If you've purchased webroot software this should be valid otherwi

LWebroot CommAgent Service (WebrootCommAgentService)CommAgent.exeRelated to Webroot Software Inc.http://www.webroot.com/
LWebroot Spy Sweeper Engine (svcWRSSSDK)WRSSSDK.exeRelated to Webroot Spy Sweeper Engine. Located in C:Program FilesWebrootSpy Sweeper
LWebroot Spy Sweeper Engine (WebrootSpySweeperService)SpySweeper.exeRelated to Webroot Software inc. Spyware protection software. Note: Located in C:Program FilesWebroo
LWebroot SpySweeper Service (WebrootSpySweeperService)SpySweeper.exeRelated to Webroot Software inc. Spyware protection software. Note: Located in C:Program FilesWebroo
LWebroot Update Service (WebrootEnterpriseUpdateService)WebrootUpdateService.exeRelated to Webroot_Software
XWebSeach Toolbar support NT serviceTBPSSvc.exeRelated to the Neo/Huntbar Toolbar
LWebsense DBManager Scheduler (DBManagerScheduler)DBManagerScheduler.exeRelated to Websense_Reporter has three primary components: the Reporter user interface the Log Serve
LWebsense Log Server (WebsenseLogServer)LogServer.exeRelated to Websense_Reporter has three primary components: the Reporter user interface the Log Serve
LWebsense Report Scheduler (Websense Reporter Scheduler)WsScheduler.exeRelated to Websense_Reporter has three primary components: the Reporter user interface the Log Serve
Xwfsup(wfsup) (wfsup)wfsup.exeAdded by the Bck/Sdbot.HPS as detected by Pandascan TROJAN! Note: This worm rojan is located in C:Wi
LWhatsUp Gold SyslogWUGSyslog.exeRelated to CiscoWorks SNMS server.
XWin Tmp Service (Wstmp)wstmp.exeAdded by the W32/Sdbot-YS Worm!
XWin UpdateSYSUPDATE.EXEAdded by the SDBOT.CLA WORM! Note: This worm file is found in the Windows or Winnt folder. Read the
XWin Updator Servicesctfnom.exeRelated to the WootBot Trojan.
XWIN32 (image)image.exeAdded by the W32/Sdbot-AAQ WORM! Read the link rootkit type stealth involved.
XWin32 Driver (shit)svchosts.exeAdded by the W32/Forbot-FD WORM!
XWin32 Kernel Update (Win32Kernel)win32host.exeAdded by the W32/Tilebot-FE WORM! Note: This worm file is found in the Windows or Winnt folder. Allo
XWin32 Login Service (Win32 Login)win32logon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XWin32 LSA Driver (Windows Lsa Service)lsa.exeAdded by the W32/Forbot-FJ WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
Xwin32 socket (win32socket)win325b.exeAdded by the W32/Tilebot-GE WORM! Note: This worm rojan is located in C:%WINDIR% folder.
XWin32 SSL Driver (Win32 SSL Driver)winssv.exeAdded by the W32/Forbot-BH WORM!
XWin32 Task Manager (Win32Task)wintasks32.exeAdded by the W32/Rbot-FPD WORM! Note: This worm rojan is located in C:%WINDIR% folder.
XWin32 Update (shit)svchosts.exeAdded by an unidentified TROJAN! of the Sdbot family. C:WindowsSystem (Win9x/Me) C:%WINDIR%System32
XWin32 Update (Win32Update)oswinupdate.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
Xwin32 update service (defiled)svchostt.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XWin32 USB2 Driversvchosting.exeW32/Forbot.J or SDBOT.HU
XWin32Exportwinsysplg.exeAdded by the W32/Rbot-FMU WORM! Note: This worm rojan is located in C:%WINDIR% folder.
LWin32SlWin32sl.exeAllows remote management application programs to access a client computer for maintainance purpose.
XWIN32SOUNDsounddv.exeAdded by the W32/Tilebot-Z WORM! Read the link rootkit type stealth involved.
XWin32Srwin32ssr.exeAdded by the W32/Sdbot-AMA WORM!
XWin32Sr (Win32Sr)win32ssr.exeAdded by the W32/Sdbot-AOT WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
LWinACD Power Button Service (ACDPowerService)acdpower.exeRelated to Compuflex's TSR-like product for the Windows environment that automatically reads the amo
Xwinauthm (spdauth)SPDAUTH.EXEAdded by the SDBOT.CFH WORM! Read the link rootkit type stealth involved.
Xwinconfig.exesvcss.exeAdded by the Troj/Agent-MD TROJAN! Note: This worm rojan is located in C:%WINDIR%
Xwinconfig.exesmsss.exeAdded by the W32/Spybot-MP WORM! Note: This is not the legitimate Windows Process. (Which is found i
Xwinconfig.exeSP2PATCH.EXEAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
Xwindbswinxtc.exeAdded by the AGOBOT-WD WORM
XWindow Boot Serviceslsiss.exeAdded by the W32/Tilebot-HP WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XWindow Dispaly Systemlsays.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XWindow LFX Serviceslxsys.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm rojan is located in
XWindow Lssas Serviceslssys.exeAdded by the Trojan.Downloader-Gen/Win.Process TROJAN! Note: This worm rojan is located in C:Windows
XWindow Plugin Servicelsscs.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XWindows 32 Bit (Windows 32 Bit Drivers)WinVid32.exeAdded by the W32/Tilebot-BH WORM! Note: This worm file is found in the Windows or Winnt folder. Read
XWindows 32-bit PnP Driverwinpnp32.exeW32.Wallz Worm. Owner:Unkown. Symantec Location: C:WindowsSystem for (9X) or C:WinntSystem32 for (NT
XWindows Anti Virus (MSAV32)MSAV32.EXEAdded by the SDBOT.CMH WORM! Read the link rootkit type stealth involved.
XWindows Archiver (winarc)devldr.exeAdded by the W32/Prex-J WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
XWindows Archiver (winarc)windat.exeAdded by the W32/Tilebot-BA WORM! Note: This worm rojan file is found in the Windows or Winnt folder
LWindows Automatic Updateswindowsautomaticupdates.exeThis Service belongs to the Folding@Home Client which uses your computer's resources on behalf of St
XWindows Basis Cont (Windows Basis Cont)WINFTP32.EXEAdded by the SDBOT.CIU WORM! Read the link rootkit type stealth involved.
XWindows CDROM Drivers (Microsoft Windows Atapi Drivers)atapid.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XWindows Client/Server Runtime Server Subsystem (WCSRSS)wcsrss.exeAdded by the W32/Tilebot-DA WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XWindows Client/Server Runtime Service (csrss)csrss.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:Windowsi
XWindows Configuration Backup Service (CfgBackupSvc)svchost.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%CONF
Windows Configuration Loader (Windows Configuration
XWindows Configuration Manager (ConfigMgr)svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XWindows DebuggerSYSNT.EXEAdded by the RBOT.CEL WORM! Read the link rootkit type stealth involved.
XWindows Decrypt manager (wincrypt32.exe)wincrypt32.exeAdded by the W32/Tilebot-GC WORM! Note: This worm rojan is located in C:%WINDIR% folder.
OWindows Desktop Securitysvcagnt.exeCheck to see if it was installed by the by user. Keylogging and screenshot software see Here Locatio
OWindows Desktop Security (dtsagntsvc)svcagnt.exeCheck to see if it was installed by the by user. Keylogging and screenshot software see Here Locatio
XWindows DLL Loader (RunDll32)rundll32.exeAdded by the Troj/Agent-MD TROJAN! Note: This is not the legitimate Windows Process. (Which is found
XWindows DLL Systemsmsc.exeAdded by the W32/Tilebot-GG WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XWindows DNS (Windows DNS)rundl32.exeAdded by the Troj/GrayBrd-AG TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
Xwindows drivers32WINDRVR32.EXEAdded by the SDBOT.CON WORM! Read the link rootkit type stealth involved.
Xwindows drivers32 (windows drivers32)windrvrs32.exeAdded by the W32/Tilebot-AG WORM! Note: This worm rojan file is found in the Windows or Winnt folder
XWindows explorerexplore.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
Xwindows explorer32explorer32.exeAdded by the W32/Sdbot-CVQ WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
Xwindows file explorer (explorer)ssms.exeAdded by the W32/Tilebot-EN WORM! Note: This worm rojan is located in C:%WINDIR% folder.
Xwindows firewall (masry)msgupdater.exeAdded by the W32/Sdbot-ADZ WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
XWindows Firewall Servicesiexplore.exeAdded by a variant of the Sdbot-ABA worm! NOTE: this file is located in the Windows folder while the
XWindows Genuine Advantage Registration Service (net32a)net32a.exeAdded by the Backdoor.IRCBot.st Identified by ewido. WORM! Note: This worm rojan is located in C:Win
XWindows Genuine Advantage Registration Service (wgareg)wgareg.exeAdded by the Win32/Cuebot.J WORM! Exploits the MS06-040 Windows vulnerability. Note: File located in
XWindows Genuine Advantage Validation (wgav)wgav.exeAdded by a variant of Win32/IRCBot.OO as reported by NOD32 TROJAN! Note: located in C:WINDOWSsystem3
XWindows Genuine Advantage Validation Monitor (wgavm)wgavm.exeAdded by the W32/Cuebot-M WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%WI
Windows Genuine Advantage Validation Notification
XWindows Help (shit)mailinfo.exeAdded by the W32/Forbot-FK WORM!
XWindows Host Services (DLLHOST32)dllhost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
XWindows HWinfo Loader (Windows HWinfo Loader)iexplre.exeAdded by the W32/Rbot-ALS WORM!
XWindows IMAP Shellimaped.exeAdded by the Backdoor.SDBot.F7B46034 TROJAN! Reported by BitDefender
LWindows InstallerMsiExec.exeexecutable program of the Windows Installer
XWindows Internet Control (Windows Internet)internet.exeAdded by the WORM_SDBOT.ABT WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XWindows Internet Serviceiexplore.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:Windows
XWindows Internet/Server (Internet)winlogo.exeAdded by the Troj/GrayBrd-AC TROJAN! Note: This trojan file is found in the SystemRavExt (95/98/ME)
XWindows Kernelsvchost.exeAdded by the HackerDefender SDBot TROJAN! ROOTKIT INFECTION Note: This worm rojan is located in C:Wi
XWindows Kernel (Windows Kernel)svchost.exeAdded by the W32/Rbot-ANO WORM! Note: This is not the legitimate Windows Process. (Which is found in
XWindows Kernel Serviceswinlogon.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR% Do
XWindows Kernel System Servicewkssvc.exeAdded by the W32.Spybot.YXX WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP
?Windows LAN Service Managersvchost.exeUnknow origin
XWindows Lognvsvcd.exeAdded by the BackDoor-CXT TROJAN! Note: located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32 (XP
Xwindows logonwinlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XWindows lsass Service (lsass)lsass.exeAdded by the W32/Rbot-AGD WORM! Located in C:WINDOWSlsass.exe (9XXP) or C:Winntlsass.exe (NT2000) No
XWindows Management (Windows Management)svchost.exeAdded by the Troj/Feutel-AN WORM! Note: This is not the legitimate Windows process(Which is always f
XWindows Management Construct (winmgmc)winmgc.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
Windows Management Instrument Driver Includes
LWindows Management InstrumentationWinMgmt.exeused by system administrators to create Windows management scripts
XWindows Management Updater (WinManUpdater)smss.exeAdded by the Troj/Kaos-E TROJAN! Note: This worm rojan is located in C:%WINDIR%
LWindows Media Connect Service (WMConnectCDS)wmccds.exeRelated to Windows_Media_Connect Service v2. Windows Media Connect is a Microsoft technology which e
XWindows Messengermsnmsgr.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This is not the legitimate Windows Proce
XWindows MS Update 32 (Win32)sucker.exeAdded by the W32/Forbot-GJ WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
Xwindows mssqlmssql.exeAdded by the W32/Tilebot-HZ WORM! Note: This worm rojan is located in C:%WINDIR% folder.
XWindows NetDDe (shit)wrmana32.exeAdded by the W32.Mytob.IM WORM!
XWindows Netlib Service (CSRS)netlib32.exeAdded by the W32/Tilebot-IG WORM! Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32 (XP
XWindows Network ControllerWinGmt.exeW32/Sdbot-MG trojan
XWindows Network Latency Controller (nlc)sp2vc.exe ( or 1.tmp nlc.exe)Added by a Generic_Password_Stealers TROJAN! Note: This worm rojan is located in C:WindowsSystem (Wi
XWindows Network Mapping Service (NetMap)svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. This worm rojan is located in C:%WINDIR%system
XWindows Network Security Management Service (nsms)nsms.exeAdded by the Troj/Ranck-ET TROJAN! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:
XWindows Network Security Service (lsass)lsass.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XWindows Networking Agent (Windows Networking Agent)msuls.exeAdded by the Troj/Kwoo-A TROJAN! Note: This worm rojan file is found in the System32 folder.
XWindows NTwinlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XWindows NT Logon Application (WINLOGON)winlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
LWindows NT Session Managersmss.exeMicrosoft Windows NT Session Manager
XWindows NT Session Manager (SMSS)smss.exeAdded by the Backdoor.IRCBot.rh as identified by ewido. Note: This worm rojan is located in C:%WINDI
XWindows NT Session Managerssmss.exeAdded by the W32/Sdbot-CPN WORM! Note: This worm rojan is located in C:%WINDIR% Note: not to be conf
XWindows Object Managersmss.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing servi
XWindows Object Managerlsass.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing servi
XWindows Object Managerwinlogon.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing servi
XWindows Object Managercsrss.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing servi
XWindows Object Managerservices.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing servi
XWindows Overlay Components(Random).exeReported as the Trojan-Dropper.Win32.Agent.tb TROJAN! by Kaspersky Anti-Virus. Note: This trojan fil
XWindows Packet Driver (packet)packet.exeAdded by the Troj/Hwbot-C TROJAN! Note: This trojan file is found in the System32 folder.
XWindows PE Debuggerlviss.exeAdded by the W32/Sdbot-COT WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
XWindows Process Moniter (Windows Process Moniter)winmon.exeAdded by the SDBOT.BYV WORM! Also drops winmon.sys which is a root kit. Note: This worm file is foun
XWindows Process Viewer (The Windows Process Viewer)winlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XWindows Product Activation (wpa)wpa.exeAdded by the W32.Esbot.B WORM!
XWindows Produre Call (MSRPC)msrpc.exeAdded by the W32/Sdbot-AEI WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
Windows Protected Content Restoration Service
XWindows Reg Servicelsyss.exeAdded by the W32/Tilebot-HH WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XWindows Register Controlregister.exeAdded by the W32/Tilebot-GO WORM! Note: This worm rojan is located in C:%WINDIR%
XWindows Remote Managerlsiss.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
Windows Remote Procedure Call Monitoring Service
XWindows RPC Services (winrpc)winrpc.exeAdded by the W32.Spybot.ACDM WORM! Note: This worm file is found in the Windows or Winnt folder.
XWindows Security Drivers (csrs)svchost.exeAdded by an unknown TROJAN! Note: This has nothing to do with Microsoft Windows Update and this is n
XWindows Security Drivers (csrs)csrss.exeAdded by an unknown TROJAN! Note: This has nothing to do with Microsoft Windows Update and this is n
XWindows Security Managervcmon.exeAdded by the W32/Tilebot-IC WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XWindows Security Updatesecupd.exehttp://www.sophos.com/virusinfo/analyses/trojsepucb.html
XWindows Server Management Servicenetsvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XWindows Service Manager (WSCM)service.exeAdded by the Backdoor.Agent.zb as reported by ewido suite. Note: located in C:WindowsSystem (Win9x/M
XWindows Services Configurationlsvss.exeAdded by the Backdoor.SdBot.aad as identified by ewido.WRM! More here
XWindows Smrss Servicesvchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XWindows Smrss Service (Windows Smrss Service)smrss.exeAdded by the W32/Tilebot-X WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
XWindows Smrss Service (Windows Smrss Service)cmdpipe.exeAdded by the W32/Tilebot-AE WORM! Note: This worm rojan file is found in the Windows or Winnt folder
Windows Socket 2.0 Non-IFS Service Provider Support
XWindows Socket System Servicewksrvs.exeAdded by the Troj/IRCBot-RC WORM! Note: This worm rojan is located in C:WindowsSystemdllcache (Win9x
XWindows Spooler (winspool32)spool.exeAdded by the W32/Sdbot-ADP WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
XWindows Sql Service For Windows 32 Bi (WinSql)winsql32.exeAdded by the W32/Forbot-FC WORM!
XWindows Stability Route (WSR)construct.exeAdded by the SDBOT.COO WORM! Read the link rootkit type stealth involved.
XWindows System ControllerSystem.exeAdded by the WORM_SDBOT.BLC WORM! Note: This worm rojan is located in C:%WINDIR% folder.
XWindows System Hostsychost32.exeAdded by the Troj/Agent-MD TROJAN! Note: This worm rojan is located in C:%WINDIR% More here
Windows System Service Framework (WSSF) (Windows System
XWindows System Tray (WINTRAY)wintray.exeAdded by the W32/Tilebot-EH WORM! Note: This worm file is found in the Windows or Winnt folder.
XWindows System32 (mswin32)MSUPD~.EXEAdded by the SDBOT.CCX WORM! Read the link rootkit type stealth involved.
XWindows Task Managervcmon.exeAdded by the W32/Tilebot-HS WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XWindows Task Manager Service (tskman)task.exeAdded by the W32/Tilebot-R WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
XWindows Task Scheduler (MSTASK)mstask.exeAdded by an unidentified TROJAN! of the Sdbot family. Do not delete the mstask.exe file unless it's
XWindows Taskbar Manager (wtaskbarmngr)taskbarmngr.exeAdded by the W32/Sdbot-XB or W32/Rbot-ZO WORM! Note: This worm file is found in the Windows or Winnt
XWindows TCP/IP Socket Driver (winsck)csrss.exeAdded by TROJ_RANKY.HW TROJAN! Note: This worm rojan is located in C:%WINDIR%winsock This is not the
XWindows Terminal Servicesvcmon.exeAdded by the Haxdoor.Fam HAXDOOR! Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32 (XP
XWindows Time Sync (wservtime)csrs.exeAdded by the W32/Tilebot-N WORM! Note: This is not the legitimate Windows Process csrss.exe. (Which
XWindows Time Sync (wservtime)csrss.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
LWindows Tracks Washer Registry Service (WTWService)washservice.exeAdded by Internet_Tracks_Washer Note: This is a Internet tracks cleaning tool.
XWindows UDP Communication (wudpcom)wudpcom.exeAdded by the IRC-Mocbot TROJAN! Note: This trojan file is found in the System32 folder.
XWindows Updata ServerServer.exeAdded by the Troj/Feutel-K TROJAN!
XWindows Update (Windows Update)winupdmon.exeAdded by the W32/Tilebot-AR WORM! Read the link rootkit type stealth involved.
XWindows Update 32 (Win32)slsys.exeAdded by the W32/Forbot-FT WORM! Note: This worm rojan file is found in the System32 folder.
XWindows Update 32 (Win32)winlogons.exeAdded by the W32/Forbot-FI WORM!
XWindows Update 63 (ntupd64)shupd64.exeAdded by the W32/Forbot-GA WORM! Note: This worm rojan file is found in the System32 folder.
XWindows Update Client (WUClient)upnphost.exeAdded by the W32.Janx WORM!
XWindows Update Client (WUClient)pnphost.exeAdded by the W32.Janx WORM!
XWindows Update Client (WUClient)winpnp.exeAdded by the W32.Janx WORM!
XWindows Update Manager (UpdateManager)updmgr.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%upda
XWindows Update Manager Tool (UpdateManagerTool)updmangr.exeAdded by the Troj/Ranck-EO TROJAN! Note: This worm rojan is located in C:%WINDIR%update
XWindows Update Servicewuamgrd.exeW32.SpyBot worm variant
XWindows Update Servicecdfs.exeAdded by the W32/Tilebot-HG WORM! Note: This worm rojan is located in C:%WINDIR% folder.
XWindows Update Servicepwnsvc.exeAdded by the W32/Sdbot-ZW WORM! Read the link rootkit type stealth involved.
Windows Update Service (Microsoft Windows Update
XWindows update Service (updater)wisvcc.exeAdded by the Troj/Orse-G TROJAN! Note: This trojan file is found in the System32 folder.
XWindows update Service (updater)winsvc.exeAdded by the SPYBOT-DB WORM!
XWindows Update Service (UpdateSvc)wuauclt.exeAdded by an unknown variant of a (backdoor raanky) TROJAN! Note: This worm rojan is located in C:%WI
XWindows Updater (Win32Export)win64tyt.exeAdded by the W32/Sdbot-CNH WORM! Note: This worm rojan is located in C:%WINDIR% folder.
XWindows Updater (Windows Updater)inetinfo.exeAdded by the Troj/Sdbot-AMX TROJAN! Read the link rootkit type stealth involved.
XWindows Updater (Windows Updater)msnlive.exeAdded by the W32/Tilebot-CN WORM! Read the link rootkit type stealth involved.
XWindows Updates (Windows Updates)Windowsupdates.exeAdded by the SDBOT.CLU WORM! Read the link rootkit type stealth involved.
XWindows UPnP Service (wupnp)wupnp.exeAdded by the W32.Esbot.D WORM! Note: This worm file is found in the System32 folder.
LWindows User Mode Driver Frameworkwdfmgr.exeRelated to Microsoft Windows media player 10 and above. http://www.liutilities.com/products/wintasks
XWindows VisFx Components(Random)Added by the Win32.Agent.mu Worm!
XWindows Vista/NT Runtime Compatibility Service (ntrcs)nrcs.exeAdded by the Backdoor.Ranky.X Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%WIND
XWindows web messengerMsmgs.exeAdded by the W32/Sdbot-BSL WORM! Note: This worm rojan is located in C:%WINDIR% folder.
Windows Windows Sheduler (Microsoft Windows Scheduled
Windows Workstation Service (Windows Workstation
XWindows Workstation Serviceswindows.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XWindows XP Advanced User LauncherWINLOGON.EXEAdded by the SDBOT.CPV WORM! Note: This is not the legitimate Windows process WINLOGON.EXE (Which is
LWindows XP FUS ManagerDPFUSMgr.exeRelated to DigitalPersona Inc.
Windows XP Service Pack 2 Services (Windows XP Service
Xwindows32windows32.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm rojan is located in
XWindowsF (FRundlll)FRundlll.exeAdded by the Troj/GrayBird-Y TROJAN! Note: This trojan file is found in the System32 folder.
Xwindowsnetwork (windowsnetwork)winkernel32.exeAdded by the W32/Tilebot-BM WORM! Note: This worm file is found in the Windows or Winnt folder. Read
XWindowsNod (WinNod)winnod.exeAdded by the W32/Tilebot-CG WORM! Read the link rootkit type stealth involved.
XWindowsSecurityManagerwinsm.exeAdded by the W32.Antinny.AX WORM! Note: This worm file is found in the System32 folder. (NT/2000/XP)
XWindowsService (WINSERVICE)service.exeAdded by the W32/Tilebot-K WORM! Note: This is not the legitimate Windows Process. (Which is found i
XWindowsSysBoomvsql.exeAdded by the W32/Tilebot-AN WORM! Note: Located in C:%WINDIR% Disables the automatic startup of othe
XWindowsSysBoot (WindowsSysBoot)winsys.exeAdded by the W32/Rbot-ARJ WORM! Note: This worm file is found in the Windows or Winnt folder.
XWindowsSysBoot (WindowsSysBoot)winsysnet.exeAdded by the W32/Tilebot-AF WORM! Note: This worm rojan file is found in the Windows or Winnt folder
XWindowsVideo (WindowsVideo)waudio.exeAdded by the Troj/Dupa-B TROJAN! Note: This worm rojan file is found in the Windows or Winnt folder.
XWindws BackupXPBackup.exeDetected by Ewido as Backdoor.SdBot.xd. This worm file is found in the Windows or Winnt folder.
LWinEncrypt service (wencrservice)wentxp.exeCryptArchiver file folder and drive encryption software for Windows.
LWinFax PROWFXSVC.EXESymantec Corporation
Xwinfws (winfws)winfws.exeAdded by the W32/Sdbot-ABA WORM! Read the link rootkit type stealth involved.
XWinlogin messengerwinlogin.exeAdded by an unidentified TROJAN! of the Sdbot family. This worm rojan is located in C:%WINDIR%system
Xwinlogo (winlogo)IEXPLORE.EXEAdded by the Troj/Singu-X TROJAN! Note: This worm rojan file is found in the System32 (NT/2000/XP) f
XWinlogon Notify: drct16drct16.dllBelonging to Haxdoor??
XWinMan (winmngr)winmngr.exeAdded by the W32/Protoride-N WORM!
XWinMedia (WinMedia)msmedia32.exeAdded by the W32/Tilebot-BI WORM! Note: This worm file is found in the Windows or Winnt folder.
LWinpowerWinpower.exeRelated to InstallAnywhere ZeroG Software is now owned by Macrovision. Note: located in C:Program Fi
LWinpowermanagermanager.exeRelated to InstallAnywhere ZeroG Software is now owned by Macrovision. Note: located in C:Program Fi
LWinpowermonitormonitor.exeRelated to InstallAnywhere ZeroG Software is now owned by Macrovision. Note: located in C:Program Fi
LWinpowerRMIwpRMI.exeRelated to InstallAnywhere ZeroG Software is now owned by Macrovision. Note: located in C:Program Fi
LWinPPPoverEthernetWrOS.EXERelated to Verizon OnLine ISP and iVasion a Routerware Company
LWinProxyWinProxy.exeWinProxy proxy server
XWinPwdResetWinPwdHelper.exeAdded by the Trojan.RBot TROJAN!
XWinRep (WinRep)WinRep.exeAdded by the W32/Rbot-AFW WORM! Read the link rootkit type stealth involved.
XWINS Client (RpcPatch)dllhost.exeAdded by the W32.Welchia WORM! **Note - This service will be set to start automatically
XWins Update 32 (Win32)services32.exeAdded by the W32/Forbot-FN WORM! Note: This worm file is found in the System32 folder.
Xwins(WINS) (wins)winscntrl.exeAdded by the W32/Tilebot-FT WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
XWinSec32 (~~~~)dhcp.sysAdded by the Troj/Rawdoor-A TROJAN! Note: This trojan file is found in the System32 folder.
Xwinsock32 (winsock32.exe)winsock32.exeAdded by the W32/Rbot-FMX WORM! Note: This worm rojan is located in C:%WINDIR% folder.
Xwinspd32dll (winspd32.exe)winspd32.exeAgobot Variant
LWinSSHDwinsshd.exeBitvise's SSH Server
LWinTab ServiceWtSrv.exeWindows tablet service driver
LWintab32Wintab32.exeWintab Digitizer Services 32-bit Server App. This file is installed with the driver for the AceCAD d
XWinTools for IE serviceWToolsS.exeRelated to Adware.Huntbar. Advertising program
Xwintroters (wintroters)wintroters.exeAdded by the Troj/GrayBrd-AJ TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
Xwinupdwinupd.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
XWin_Pigeon_Server (Win_Pigeon_Server)Win_Server.exeAdded by the Troj/Feutel-N TROJAN!
XWireless Connection Configuration (wificonf)mscarrt32.exeAdded by the W32/Oscabot-K WORM!
XWksPatchSvchost.exeAdded by the W32.Welchia.B or W32.Welchia.C or W32.Welchia.D or W32.Welchia.K WORM! **Note - Service
Xwkssvc (Windows Kernel Serivce)wkssvc.exeAdded by the W32/Sdbot-AOR WORM! Note: This worm rojan is located in C:%WINDIR% folder.
Xwkssvc (Windows Kernel Serivce)AIMClient.exeAdded by the W32/Tilebot-DP WORM! Note: This worm rojan is located in C:%WINDIR% folder.
XWlan1934 (Wlan1934)wlan1934.sysAdded by the Troj/Dloader-TB TROJAN!
LWLANKEEPERWLKeeper.exeRelated to Intel Corporation
Xwlmsngrwlmsngr.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:Windows
LWLTRYSVCwltrysvc.exeltrysvc.exe is a process belonging to the Broadcom Corporation Wireless Network Tray Applet which in
LWLTRYSVCbcmwltry.exeRelated to wireless networking in Dell computers
XWmDmPspsysdtc32.exeAdded by the Ircbot_Gen Worm! Note: SYSDTC32.EXE may use 13 or more path and file names read the lin
XWMFhotfix912840 (Microsoft Windows WMF hotfix 192840)enu-hotfix912840.exeAdded by the WORM_OPANKI.CG Note: This worm rojan is located in C:%WINDIR% folder. &VName=WORM_OPANK
LWMI Performance Adapter (WmiApSrv)wmiapsrv.exeRelated to Microsoft_WMI performance adapter which collects information regarding performance. Note:
Xwmpwmp.exe and wmp.cfgSee Viruslist Owner unknown : C:Program FilesWindows Media Player
?wnjfuo
LWonderware NetDDE Helper (WWNetDDE)wwnetdde.exeRelated to ArchestrA Software architecture for the integration of your automation systems.
LWonderware SuiteLink (slssvc)slssvc.exeRelated to ArchestrA Software architecture for the integration of your automation systems.
Xwordpad (wordpad)wordpad.exeAdded by the W32.Spybot.WON WORM! Note: This is not the legitimate Windows application Wordpad.exe.
XWork Station Development (NTDEV)ntdev.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
XWorking Network Connectionshicom.exeTrojan-Proxy.Win32.Agent.cx
XWorking Network Connections (TY164)hicom.exeAdded by the Troj/Chimo-F TROJAN!
XWorkstation (MSDCSRV32)mssrv.exeAdded by the PWSteal.Drorar TROJAN! Note: This trojan file is found in the Program FilesCommon Files
LWorkstation Manager (ZFDWM)wm.exeRelated to Novell_Workstation_Manager From Novell Inc. Note: Located in C:Program FilesNovellENwork
XWorkstation NetLogon ServicerandomCoolWebSearch malware
XWorkstation NetLogon Service ( 11Fßä #•ºÄÖ`I)(Random).exeCoolWebSearch malware.
XWorkstation NetLogon Service (11Fßä #•ºÄÖ`I)(Random)32.exeCoolWebSearch malware.
XWorkstation NetLogon Service(11Fß#·ºÄ`I)crzw32.exeCoolWebSearch HiJacker Service R1=res:xxxx.dll/sp.html
XWorkstation Service Library (Microsoft Locator Service)wkssvc.exeAdded by the W32/Sdbot-ABE WORM! Read the link rootkit type stealth involved.
XWPAsvchosts.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
LWPS Scanner Service (WPSScannerSvc)WPSScannerSvc.exeRelated to Skyhook_Wireless Wi-Fi positionning system. Note: Located in C:Program FilesSkyhook Wirel
XWRM CPU drive (wrmdrv)WRMDRV.SYSAdded by the GOLDUN.B WORM!
XWS2IFSL(Unknown)Added by the Trojan.Riler.E TROJAN!
Xwsmv(wsmv) (wsmv)wmsv.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
Xwto (wto)G_Server2.0.exeAdded by the Troj/GrayBrd-BN TROJAN!
XwuamWUAMPR.EXEAdded by the SDBOT.CKP WORM! It also drops the file X5.SYS detected by Trend Micro as TROJ_ROOTKIT.S
LWUOLservice (WUOLService)WUOLService.exeRelated to Novel Inc.
LWUSB54Gv2SVCWLService.exeRelated to Linksys Wireless-G USB Wireless Network Monitor
XWut Niggasyswork.exeW32/Forbot-FZ will add this the display name is: Working System Analyzer
LWZCBDL ServiceWZCBDLS.exeFile associated with D-link software
LX10 Device Network Service (x10nets)x10nets.exeX10 video streaming devices. This program is non-essential process to the running of the system but
XX5X5.SYSAdded by the TROJ_ROOTKIT.S TROJAN! Read the link rootkit type stealth involved.
XxadzrandomRelated to Backdoor.Exdis
XXCP CD Proxy (CD_Proxy)CDProxyServ.exeThis is the Sony-BMG ROOTKIT! Do not try to manually remove this! For more information check Mark Ru
LxElevate ServicexElevate_a4c3.exeThe Boeing Company (internal use)
LxElevate ServicexElevate_a4c3.exeFor Internal Use - The Boeing Company
XXP Backup (Smart XP)smtxp.exeAdded by a variant of Backdoor.Win32.SdBot.aad TROJAN! Note: This worm rojan is located in C:Windows
LXpoint Admin Server (XPadminServer)xpadmin.exePart of the IBM/XPoint Rapid Restore utility. File is found in the C:Program Filesxpointxpadmin fold
LXpoint Agent Server (xpAgentServer)Xpagent.exePart of the IBM/XPoint Rapid Restore utility. File is found in the C:PROGRA~1xpointagent folder.
LXpoint PCRadmin Server (PCRadminServer)pcradmin.exePart of the IBM/XPoint Rapid Restore utility. File is found in the C:Program FilesXpointPE folder.
Xxprtect (xprtect)xprtect.sysAdded by Adware-DigitalNames
LXtreamLok License Managerxl.exeRelated to XtreamLok prevents software being reverse engineered. Note: Located in C:%WINDIR%System32
XXXXCodec Service (XXXCodec Acceleration Service)casrv.exeAdded by Trojan-Downloader.Win32.Small.czh Identified by Kaspersky. TROJAN! Undesirable service as i
XYahoo Updater (Updater)Messenger.exeAdded by the W32/Forbot-FU WORM! Note: This worm rojan file is found in the System32 (NT/2000/XP) fo
Xyak tw (yak tw)yak_tw.exeAdded by the Backdoor.Graybird.M TROJAN!
LYATS32 Service (YATS32)yats32.exerelated to YATS32 Time Synchronization applications for desktop or corporate LANs.
LYEDIExYEDIEx.exeRelated to Y-E_Data ExpressCard Reader
XYndbybmhYndbybmh.sysAdded by the Backdoor.Darkmoon.B TROJAN! Note: This trojan file is found in the System32drivers fold
LYPCServiceYPCSER~1.EXERelated to Yahoo
Xyvlymxmnibnayvly.exeMalware service presumably random filename is service name reversed
Xyvlymxmnibna - Unknown owner -mxmnibnayvly.exeMalware servicepresumably randomfilename is service name reversed
XYwvpysxl (Ywvpysxl)Ywvpysxl.sysAdded by the Troj/Psupda-A TROJAN!
XYY_Serer (YY_Sererwin)YY_Serer.exeAdded by the Troj/GrayBird-S TROJAN!
XZESOFTzeta.exeRelated to BargainBuddy/BullsEye variant. Also appears often with VX2
XZESOFTzeta.exeSeems to be a BargainBuddy/BullsEye variant. Also appears often with VX2...
LZipToAZipToA.exeRelated to Iomega Backup
LZipToAZipToA.exerelated to Iomega Backup
Xzonealarm (iexplorer)Removeme.EXEAdded by the W32/Forbot-BG WORM!
XZykheptdZykheptd.dllAdded by the Backdoor.Hesive.B TROJAN! Read the link rootkit type stealth involved.
XzzzxIPSPECzzzxt2llso.exe
XzzzxIPSPEC_1 (zzzxIPSPEC_1)zzzx[random characters].exeAdded by the Netdepix.B TROJAN!