Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Submit a log and you will receive ALL the information we have in our DB's on everything on your system INSTANTLY!

services.exe


Click here to scan for services.exe Related Errors and Optimize PC performance

services.exe is a part of Windows that manages the processes. Anytime a service starts or stops it is through services.exe. During system startup and shutdown is when this process sees most of its action. You should never end this process unless it is running outside of your windows system folder.

Fix services.exe Errors: Free Scan

Recommended: Run a Free Performance Scan to automatically optimize memory, CPU and Internet Settings




services.exe is a Windows System File and should be in a system directory. If it is then this application is safe.

Startup DB Entries:
[WinCheck]"Added by the SOBER.V WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft and note the space at the beginning of the ""Startup Item"" field" b
[WinData]"Added by the SOBER-AD WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\PoolData and note the space at the beginning of the ""Startup Item"" field" b
[Windows]"Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity and note the space at the beginning of the ""Startup Item"" field" b
[WinINet]"Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus and note the space at the beginning of the ""Startup Item"" field" b
[WinStart]"Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status and note the space at the beginning of the ""Startup Item"" field" b
[.Prog]"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe processb
[Amie Release V6.9D]"Added by the VB-EAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%" b
[AutoAdministrator]"Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWS" b
[AutoUpdate32]"Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64" b
[BaRloNdDiLhep]"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder" b
[BuildLab]"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe processb
[ccApps]"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe processb
[ConfigVir]"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder" b
[DHCP32]"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display" b
[FriendlyTypeName]"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe processb
[Golum]"Added by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe processb
[golumm]"Added by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""golumm"" subfolder" b
[LiveUpdate32]"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas" b
[Microsoft (R) Windows Protected Content Restoration Service]"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc" b
[Microsoft (R) Windows TCP/IP Socket Layer]"Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock" b

Service DB Entries:
System Spooler Host Added by the W32/Sdbot-COV WORM! Note: This worm rojan is located in C:Windowscursorsmstask (Win9x/M
Servicio RunAs Spanish Windows 2000 RunAs service
Servidor Spanish Windows 2000 server
Servicio de ayuda TCP/IP NetBIOS Spanish Windows 2000 Help service TPC/IP NetBIOS
Servicio de alerta Spanish Windows 2000 alert service.
Services an controller-settings Added by the W32/Tilebot-HY WORM! Note: This worm rojan is located in C:%WINDIR% folder.
Registro de sucesos Spanish Windows 2000 event logger
Plug and Play Spanish Windows 2000 Plug and Play
Microsoft Windows Spool Service (Windows Spool Service) Added by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
Microsoft Windows HelpFile (Windows Helpfile) Added by the W32/Tilebot-FQ WORM! Note: This worm rojan is located in C:%WINDIR% folder. disabling t
Microsoft NetWork FireWall Services http://www.sophos.com/virusinfo/analyses/w32lovgateaa.html
MaxSyncService (NTService1) Related to Maxtor_OneTouch service. Note: Located in C:ProgramMaxtorOneTouchUtils
Iomega App Services Iomega related
Horario de Windows Spanish Windows 2000 windows time
Exten. controlador Instrumental de admon. de Windows Spanish Windows 2000 windows management instrumentation drive extension

Disclaimer

Every attempt has been made to ensure the information about services.exe is accurate but alot of malware applications try to pose as valid applications. If it is something other than what was posted above please leave some feedback in the forum.
Printer Friendly

User Comments
Windows Files
lsass.exe | csrss.exe | alg.exe | dwwin.exe | Svchost.exe | Spoolsv.exe | wowexec.exe | cidaemon.exe | wmiprvse.exe | ctfmon.exe | Winlogon.exe | wuauclt.exe | Smss.exe | msmsgs.exe | rundll32.exe | mdm.exe | ntvdm.exe | wscntfy.exe | explorer.exe | ntdll.dll | iexplore.exe | msdxm.ocx | wisptis.exe | wdfmgr.exe | MsiExec.exe | PDVDServ.exe | DLLhost.exe | gcasdtserv.exe | shdoclc.dll | Winmgmt.exe | cisvc.exe | oleaut32.dll | taskmgr.exe | inetinfo.exe | Shell32.dll | mspmspsv.exe | internat.exe | hal.dll | comctl32.dll | mstask.exe |