CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    Random sampling...
    NameStatusFilenameDescription
    lcvgaXlcvga.exeAdded by the Hostol-A TROJAN!
    loadfaxXloadfax.exeAdded by the Troj/Winflux-C TROJAN!
    LogMeIn GUIULogMeInSystray.exe RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN, an intranet or the Internet) - and on the client side all you need is a web browser, a terminal emulator or a WAP-enabled phone.
    LfhXLfh.exeAdded by the TROJ/ZAURGA-A TROJAN!
    li-vita****Xli-vita****.exeAdult web-dialler - **** is random
    LANDeskInventoryClientULDIScn32.exeRelated to LANDesk® _Management Agent from LANDesk Software. Note: Located in \%ROOT%LANDesk\LDClient\
    LsassXLSASS.EXEAdded by the W32/Punya-B Worm
    Live Windows Messenger VersionXmsnmessage7.7.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    LTM2X bible.exeAdded by a LITMUS VIRUS Variant!
    LSASS AuthorityXlshosts32.exeAdded by the SDBOT-UY TROJAN!
    LTM2Xwinscan.exeAdded by the TROJ/LITMUS-B TROJAN!
    load=XSpoolsv.exeAdded by the CIADOOR.B VIRUS! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file
    LogiTrayNLogiTray.exeLogitech Image Studio - installed with Logitech QuickCams
    LSASS32XIsass32.exeAdded by the W32.KELVIR.M WORM!
    LTSMMSGNLTSMMSG.exeLucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook, Acer and Sony Vaio notebooks, maybe others too
    Life FireWall Update1XFireWall-Update1.exeAdded by the W32/RBOT-ARS WORM!
    LiveSexCamsXLiveSexCams.exePremium rate adult content dialer
    LexStartUlexstart.exeLexmark printer software may add Lexstart.exe in the startup folder to handle print commands that you send to the printer. Sometimes required for the printer to work correctly - not in the case of a Lexmark Z42 for instance
    lolololX_hideme_imhiddenlololol.exeAdded by the Troj/Hideme-A Trojan Note: Makes use of rootkit stealth techniques
    lichXlich.exeAdded by Troj/QLowZon-BN TROJAN! Note: located in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (XP/WinNT/2K)
    lmpdpsrv?lmpdpsrv.exeRelated to a Lexmark printer/scanner. Printer sharing server? Is it required?
    LoadPowerProfileXASDAPI.EXEAdded by the CABRO VIRUS! Not to be confused with the valid entry below
    lsassXlsass.exeAdded by the RATSU.B VIRUS! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
    LogitechImageStudioTrayNLogiTray.exeLogitech Image Studio - installed with Logitech QuickCams
    lssassXlssas.exeAdded by the AGOBOT.RL WORM!
    LoadGolfCoursesXLoadGolfCourses.exePlayMiniGolf.com foistware - stealth installed!
    LightScribe Control PanelULightScribeControlPanel.exeRelated to LightScribe from Hewlett-Packard an innovative technology that uses a special disc drive, special media, and label-making software to burn labels directly onto CDs and DVDs. Note: Located in \%Program Files%\Common Files\LightScribe\
    load=?WINOSCFG.EXECould it be something to do with configuring Windows on a new PC from an OEM supplier?
    load=Ywpshrc.exeRequired to prevent configuration errors on a Compaq LBP-660 parallel port laser printer (and maybe others)
    lxbumon.exeUlxbumon.exeRelated to Lexmark printers/scanner Note: Located in \%Program Files%\Lexmark 6200 Series\
    lxdwamonUlxdwamon.exeRelated to Lexmark for the 7600 series or printers/scanner Note: C:\Program Files\Lexmark (printer model) Series folder. Note: Located in \%Program Files%\Lexmark 7600 Series\
    lsasssXlsasss.exeAdded by the Troj/Geekmy-A TROJAN! Note: lsasss.exe (notice the extra s) is not the legitimate Windows Process. (lsass.exe) The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    Lavasoft AdwatchUAd-watch.exePart of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
    loadXctftpscr32.exe Troj/Agent-FPN
    loadMefsXrundll32.exeAdded by the Troj/LegMir-JB TROJAN! Note: This is not the legitimate Windows Process rundll32.exe, Which is found in the Windows folder(98\ME) or the System32 folder(NT\2000\XP). This trojan file is found in the Windows\inf or Winnt\inf folder.
    LLMODCL2?rundll.exe,setupx.dll,,InstallHinfSection,..LLMODCL2.INF??
    Logitech Desktop MessengerNLogitechDesktopMessenger.exeInstalled with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech.
    load32Xswchost.exeAdded by the NIBU.I TROJAN! and the W32/Dumaru-AK WORM!
    Logitech WakeupNlgwakeup.exeLoads at startup and monitors the scanner. When a document is inserted in the scanner the wakeup program feeds the document a fraction of a inch into the scanner and then it launches the control center software. From the control center you can select whether to fax or copy or print the scanned documents. If you uncheck the Logitech wakeup software from the startup it no longer launches the control center or feeds the document a fraction of an inch. You can manually launch the control center software via Start ->Programs and still be able to scan images
    LXCJCATSULXCJtime.dllRelated to Lexmark printers/scanner Note: Located in \%WINDIR%\System32\spool\DRIVERS\W32X86\3\
    Logiciel de transfert d'images KODAKNpts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs (same program in french)
    load32Xload32.exeAdded by the W32.DUMARU WORM!
    LanSpeed2ULanSpeed2.exeMonitors any traffic that is using a LAN adapter (Ethernet or Token ring network card)
    Local Security Authority ServceXlssas.exeAdded by the W32/Poebot-T WORM! Note: This is not the legitimate Windows process lsass.exe (Notice the difference in the spelling.) This worm file (lssas.exe) is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    load=Xshambl3r.exeAdded by the REMABL VIRUS!
    Live MessangerXwllmsngr.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    LetsSearchXLetsSearch.exe BrowserAid/BrowserPal Foistware
    linkyuuXlinkuyy.exe W32/Streedom.A
    laokey.exeULaoKey.exeLao Script for Windows http://www.laoscript.net/ (LSWin) is an extension to the Windows operating system to allow Lao language to be used with many different Windows-based applications
    LoginUwinlog.exeSalfeld Child Control - parental control software
    LTM2XMSGSRV320.EXEAdded by a LITMUS VIRUS Variant!
    LingvoTrainingUTutor.exeRelated to ABBYY_Lingvo Electronic Dictionaries. Note: Located in C:\Program Files\ABBYY Lingvo 10 Multilingual Dictionary\
    LoadOrderVerificationX*.exeAdded by the TRON VIRUS! * is a random file name, possibly Pthymvfr.exe
    loadwinXwinsys.exeAdded by the TROJ/QQPASS-J TROJAN!
    load=Y[path],01comm32.exeRelated to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions, plus a terminal program, a WWW-browser launch function, Internet telephony, and address management. Required if you use those.

    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops

    spacer spacer