Monday, August 13, 2012

A canonical list of Windows service names for antivirus and antimalware tools

I had a need to modify some code to check for the presence of a range of anti-virus and anti-malware tools running as a service on a Windows system.

As a background, my purpose was to find different AV services and, if multiple AV tools are starting up and running, to delay an operation until the services had finished initialising (ie, in the RUNNING state.)

As part of this exercise, I could not find a list of Windows services names for the common anti-virus tools available [let me know if you know where one is!] So while the information is not too hard to dig up for each tool, I decided to document this list here for future reference.

  • symantec antivirus:: Symantec Endpoint Protection
  • mcshield:: McAfee Security
  • windefend:: Windows Defender
  • msmpsvc:: Microsoft Security Essentials
  • msmpeng:: Microsoft Security Essentials
  • savservice:: Sophos Antivirus
  • aveservice:: Avast!
  • avast! antivirus:: Avast!
  • immunetprotect:: Immunet Protect
  • fsma:: F-Secure
  • antivirservice:: AntiVir
  • avguard:: Avira
  • fpavserver:: F-Protect
  • pshost:: Panda Security
  • pavsrv:: Panda AntiVirus
  • bdss:: BitDefender
  • abmainsv:: ArcaBit/ArcaVir
  • ikarus-guardx:: IKARUS
  • ekrn:: ESET Smart Security
  • avkproxy:: G Data Antivirus
  • klblmain:: Kaspersky Lab Antivirus
  • vbservprof:: Symantec VirusBlast
  • clamav:: ClamAV
New additions:
  • SBAMSvc:: Vipre / GFI managed AV
  • navapsvc:: Norton
  • AVP:: Kaspersky

Note that this is a reference to the Windows "Service name" value for the tool, as opposed to the Display name or Executable/Process name.

Many of these are based on web searches and information found online and have not been verified personally. Certainly, this list is by no means complete or guaranteed accurate!

If I receive corrections or additions to this list or need to extend it, I will edit this post!