| Name | Status | Filename | Description |
|---|
| lcvga | X | lcvga.exe | Added by the Hostol-A TROJAN! |
| loadfax | X | loadfax.exe | Added by the Troj/Winflux-C
TROJAN!
|
| LogMeIn GUI | U | LogMeInSystray.exe | RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN, an intranet or the Internet) - and on the client side all you need is a web browser, a terminal emulator or a WAP-enabled phone. |
| Lfh | X | Lfh.exe | Added by the TROJ/ZAURGA-A TROJAN! |
| li-vita**** | X | li-vita****.exe | Adult web-dialler - **** is random |
| LANDeskInventoryClient | U | LDIScn32.exe | Related to LANDesk® _Management Agent from LANDesk Software. Note: Located in \%ROOT%LANDesk\LDClient\ |
| Lsass | X | LSASS.EXE | Added by the W32/Punya-B Worm |
| Live Windows Messenger Version | X | msnmessage7.7.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| LTM2 | X | bible.exe | Added by a LITMUS VIRUS Variant! |
| LSASS Authority | X | lshosts32.exe | Added by the SDBOT-UY TROJAN! |
| LTM2 | X | winscan.exe | Added by the TROJ/LITMUS-B TROJAN! |
| load= | X | Spoolsv.exe | Added by the CIADOOR.B VIRUS! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file |
| LogiTray | N | LogiTray.exe | Logitech Image Studio - installed with Logitech QuickCams |
| LSASS32 | X | Isass32.exe | Added by the W32.KELVIR.M WORM! |
| LTSMMSG | N | LTSMMSG.exe | Lucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook, Acer and Sony Vaio notebooks, maybe others too |
| Life FireWall Update1 | X | FireWall-Update1.exe | Added by the W32/RBOT-ARS WORM! |
| LiveSexCams | X | LiveSexCams.exe | Premium rate adult content dialer |
| LexStart | U | lexstart.exe | Lexmark printer software may add Lexstart.exe in the startup folder to handle print commands that you send to the printer. Sometimes required for the printer to work correctly - not in the case of a Lexmark Z42 for instance |
| lololol | X | _hideme_imhiddenlololol.exe | Added by the Troj/Hideme-A Trojan Note: Makes use of rootkit stealth techniques |
| lich | X | lich.exe | Added by Troj/QLowZon-BN TROJAN! Note: located in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (XP/WinNT/2K) |
| lmpdpsrv | ? | lmpdpsrv.exe | Related to a Lexmark printer/scanner. Printer sharing server? Is it required? |
| LoadPowerProfile | X | ASDAPI.EXE | Added by the CABRO VIRUS! Not to be confused with the valid entry below |
| lsass | X | lsass.exe | Added by the RATSU.B VIRUS! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup! |
| LogitechImageStudioTray | N | LogiTray.exe | Logitech Image Studio - installed with Logitech QuickCams |
| lssass | X | lssas.exe | Added by the AGOBOT.RL WORM! |
| LoadGolfCourses | X | LoadGolfCourses.exe | PlayMiniGolf.com foistware - stealth installed! |
| LightScribe Control Panel | U | LightScribeControlPanel.exe | Related to LightScribe from Hewlett-Packard an innovative technology that uses a special disc drive, special media, and label-making software to burn labels directly onto CDs and DVDs. Note: Located in \%Program Files%\Common Files\LightScribe\ |
| load= | ? | WINOSCFG.EXE | Could it be something to do with configuring Windows on a new PC from an OEM supplier? |
| load= | Y | wpshrc.exe | Required to prevent configuration errors on a Compaq LBP-660 parallel port laser printer (and maybe others) |
| lxbumon.exe | U | lxbumon.exe | Related to Lexmark printers/scanner Note: Located in \%Program Files%\Lexmark 6200 Series\ |
| lxdwamon | U | lxdwamon.exe | Related to Lexmark for the 7600 series or printers/scanner Note: C:\Program Files\Lexmark (printer model) Series folder. Note: Located in \%Program Files%\Lexmark 7600 Series\ |
| lsasss | X | lsasss.exe | Added by the Troj/Geekmy-A
TROJAN!
Note: lsasss.exe (notice the extra s) is not the legitimate Windows Process. (lsass.exe) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. |
| Lavasoft Adwatch | U | Ad-watch.exe | Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system |
| load | X | ctftpscr32.exe | Troj/Agent-FPN |
| loadMefs | X | rundll32.exe | Added by the Troj/LegMir-JB
TROJAN!
Note: This is not the legitimate Windows Process rundll32.exe, Which is found in the Windows folder(98\ME) or the System32 folder(NT\2000\XP). This trojan file is found in the Windows\inf or Winnt\inf folder.
|
| LLMODCL2 | ? | rundll.exe,setupx.dll,,InstallHinfSection,..LLMODCL2.INF | ?? |
| Logitech Desktop Messenger | N | LogitechDesktopMessenger.exe | Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech. |
| load32 | X | swchost.exe | Added by the NIBU.I
TROJAN! and the W32/Dumaru-AK
WORM!
|
| Logitech Wakeup | N | lgwakeup.exe | Loads at startup and monitors the scanner. When a document is inserted in the scanner the wakeup program feeds the document a fraction of a inch into the scanner and then it launches the control center software. From the control center you can select whether to fax or copy or print the scanned documents. If you uncheck the Logitech wakeup software from the startup it no longer launches the control center or feeds the document a fraction of an inch. You can manually launch the control center software via Start ->Programs and still be able to scan images |
| LXCJCATS | U | LXCJtime.dll | Related to Lexmark printers/scanner Note: Located in \%WINDIR%\System32\spool\DRIVERS\W32X86\3\ |
| Logiciel de transfert d'images KODAK | N | pts.exe | Looks for Kodak camera connection and media insertion. Available via Start -> Programs (same program in french) |
| load32 | X | load32.exe | Added by the W32.DUMARU WORM! |
| LanSpeed2 | U | LanSpeed2.exe | Monitors any traffic that is using a LAN adapter (Ethernet or Token ring network card) |
| Local Security Authority Servce | X | lssas.exe | Added by the W32/Poebot-T
WORM!
Note: This is not the legitimate Windows process lsass.exe (Notice the difference in the spelling.) This worm file (lssas.exe) is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
|
| load= | X | shambl3r.exe | Added by the REMABL VIRUS! |
| Live Messanger | X | wllmsngr.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| LetsSearch | X | LetsSearch.exe | BrowserAid/BrowserPal Foistware |
| linkyuu | X | linkuyy.exe | W32/Streedom.A |
| laokey.exe | U | LaoKey.exe | Lao Script for Windows http://www.laoscript.net/ (LSWin) is an extension to the Windows operating system to allow Lao language to be used with many different Windows-based applications
|
| Login | U | winlog.exe | Salfeld Child Control - parental control software
|
| LTM2 | X | MSGSRV320.EXE | Added by a LITMUS VIRUS Variant! |
| LingvoTraining | U | Tutor.exe | Related to ABBYY_Lingvo Electronic Dictionaries. Note: Located in C:\Program Files\ABBYY Lingvo 10 Multilingual Dictionary\ |
| LoadOrderVerification | X | *.exe | Added by the TRON VIRUS! * is a random file name, possibly Pthymvfr.exe |
| loadwin | X | winsys.exe | Added by the TROJ/QQPASS-J TROJAN! |
| load= | Y | [path],01comm32.exe | Related to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions, plus a terminal program, a WWW-browser launch function, Internet telephony, and address management. Required if you use those.
|