| Status | Autorun name | Command | Description |
| X | livekey | webgrade.exe | LiveKeys adware. File located in %Program Files%\livekey\livekeys |
| X | livekeys | webgrade.exe | LiveKeys adware. File located in %Program Files%\livekey\livekeys |
| N | LiveMonitor | LMonitor.exe | MSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information |
| N | LiveNote | Livenote.exe | Asus graphics card driver live update feature |
| X | LiveProtect | LiveProtect.exe | System Live Protect rogue security software - not recommended, removal instructions here |
| X | LiveSexCams | LiveSexCams.exe | Premium rate adult content dialler |
| U | LiveUpdate | LiveUpdate.exe | Web-update utility as used by various types of software - see here |
| X | LiveUpdate | [Windows username]05.exe | Added by the LINEAGE TROJAN! |
| X | LiveUpdate | smss.exe | Added by the VB.BAU BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas |
| N | LiveUpdate | Copyer.exe | Samsung PC Studio is a Windows-based PC program package that you can use easily to manage personal data and multimedia files by connecting a Samsung Electronics Mobile phone (GSM/GPRS/UMTS) to your PC. You can launch the update manually - see the instructions here for example |
| X | LiveUpdate32 | services.exe | Added by the VB.BAU BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas |
| X | Livre | Dibane.bat | Added by the BANEDI VIRUS! |
| X | Ljx | rundll32.exe | Added by the LINEAG-ABD TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\inf |
| X | lk3h1 | [path to file] | Added by the MOSUCK-G TROJAN! |
| X | llajyn_df | lljyn081020.exe | Added by the AUTORUN-MR WORM! |
| X | llajyn_df | lljyn081017.exe | Added by the AUTORUN-MQ WORM! |
| X | lljy_df | llzjy[random digits].exe | Added by the AUTORUN-GT WORM! |
| ? | LLMODCL2 | rundll.exe setupx.dll, InstallHinfSection ..LLMODCL2.INF | ?? |
| N | LM Status | LMSTATUS.EXE | Xerox WorkCenter XE - language monitor status application |
| X | LMA Manager | lmamanager.exe | Added by the TILEBOT-AD WORM! |
| U | LManager | QtZgAcer.EXE | Acer Launch Manager - on Acer laptops it supports the dedicated multimedia buttons and allows users to configure their function. If the optional WLAN module and Bluetooth radio are installed the associated buttons can set their operating state |
| U | LManager | QtZpAcer.exe | Acer Launch Manager - on Acer laptops it supports the dedicated multimedia buttons and allows users to configure their function. If the optional WLAN module and Bluetooth radio are installed the associated buttons can set their operating state |
| U | LManager | HotkeyApp.exe | Programmable keys on Acer, Fujitsu and other laptops |
| U | LManager | QtaET2S.EXE | Acer Launch Manager - on Acer laptops, provides configurability for the special keys on their range of multimedia keyboards |
| U | LManager | CPLBCL53.EXE | System Tray icon found on Acer Travelmate laptops that allow you control access to the Internet and email buttons and other computer configurations |
| U | Lmanager | LManager.exe | Acer Launch Manager - manages configuration of the multimedia keys on their range of notebooks, netbooks and desktops |
| X | lMAPl | lMAPl.exe | Added by the AGOBOT-RE WORM! |
| U | LMgrOSD | OSDCtrl.exe | OSD (on-screen-display) utility - part of Acer Launch Manager. Gives you control to customize the monitor to your liking...from sound, brightness, contrast, horizontal and vertical positions, phase, pixel clock, color and language |
| U | LMgrVolOSD | OSD.EXE | Displays a message or graphic on-screen when you press a corresponding volume "hotkey" - such as increase, decrease or mute. Nice but not required if you don't adjust things regularly - and also known to cause a system freeze in some cases |
| N | LMonitor | LMonitor.exe | MSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information |
| ? | lmpdpsrv | lmpdpsrv.exe | Related to a Lexmark printer/scanner. Printer sharing server? Is it required? |
| X | lmrt | lmrt.exe | Unidentified adware |
| N | LMSTATUS | LMSTATUS.EXE | Xerox WorkCenter XE - language monitor status application |
| Y | LMSXXD | LMSXXD.exe | Driver for Xerox XD series printer/copiers |
| X | lmu | LMU.exe | Detected by Kaspersky as the AGENT.BG TROJAN! |
| X | lmxyzwhq.exe | lmxyzwhq.exe | Added by the AGENT-GEX TROJAN! |
| X | lnsas | lnsas.exe | Added by the ARKID TROJAN! |
| X | lnternet Explorer | AMSNDMGR.EXE | Added by the KWBOT.R WORM! Note that the "l" is a lower case "L" and not an upper case "I" |
| X | lnternet Update | lExplore.exe | Added by the RBOT-GRH WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer |
| X | lnwin.exe | lnwin.exe | Added by the DLOADR-ATC TROJAN! |
| X | LO0Cvkl | LO0Cvkl.exe | Added by the FREETHOG-Z WORM! |
| X | load | mdm.exe | Added by the BINGHE TROJAN! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only) |
| X | load | msgsr32.exe | Added by the SDBOT-QR WORM! |
| X | load | [path to worm] | Added by the KELVIR.AI WORM! |
| X | Load | MyGame.exe | Added by the LAMEYEAR-A WORM! |
| X | load | _Kerne1.exe | Added by the LINEAGE-AN TROJAN! |
| X | load | Internat.exe | Added by the WOWCRAFT TROJAN! |
| X | load | rundll32.exe | Added by the WOWCRAFT TROJAN! |
| X | load | svhost32.exe | Added by the WOWCRAFT TROJAN! |
| X | load | svchsot.exe | Added by the GWGHOST-O TROJAN! |
| X | load | explorer.exe | Added by the LINEAGE-OZ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | load | Kerne121.exe | Added by the LINEAGE-ON TROJAN! |
| X | load | Kerne1211.exe | Added by the LINEAGE-DY TROJAN! |
| X | load | rundl132.exe | Added by the LOOKED-CK WORM! |
| X | load | ctftpscr32.exe | Added by the AGENT-FPN TROJAN! |
| X | Load | win32.exe | Added by the RUBBLE-A WORM! |
| X | load | QQ.exe | Added by the QUADRULE.A WORM! Note - this is not the Tencent QQ Asian instant messanger program which is located in %Windir% |
| X | load | WinExplorer.exe | Added by the VB.EIW WORM! |
| X | load | Systemfile.dll.vbs | Added by an unidentified WORM or TROJAN! See here |
| X | load | KHATRA.exe | Added by the ORBINA-A WORM! |
| X | load | Scvhost.exe | Added by the AUTORUN-AJ WORM! |
| X | load | cisvc.exe | Added by the DOWNBOT TROJAN! |
| X | Load Service | SvHost.exe | Added by the PESIN-D WORM! |
| U | LOAD WB | LOADWB.EXE | Part of Stardock's WindowBlinds custom desktop program. "WindowBlinds is the first utility of its kind. It extends Win98/NT/2K/XP to have a fully skinnable user interface. You can change the style of title bars, buttons, toolbars and much more". If you use it - keep it if not then uninstall it |
| X | Load-Guard | Wscript.exe LGuarg.exe.vbs | Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "LGuarg.exe.vbs" file is located in %Windir% |
| N | load= | adw30.exe | After Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95 |
| U | load= | asistat.exe | Status monitor for an NEC SuperScript printer |
| ? | load= | cfgsys32.exe | ?? |
| U | load= | esspk.exe | Speakerphone capability through a soundcard for an ESS modem |
| Y | load= | hotkey.exe | Solo 5300 display driver for Win2K on some Gateway laptops |
| N | load= | HPWHRC.EXE | Loads the Status Window software for the HP Laserjet printers |
| ? | load= | WPSLOAD.EXE | Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk |
| N | load= | vi_grm.exe | Monitor drivers for Trio2x/3x based video cards - displays control panel for quick access to display settings |
| ? | load= | WINOSCFG.EXE | Could it be something to do with configuring Windows on a new PC from an OEM supplier? |
| Y | load= | wpshrc.exe | Required to prevent configuration errors on a Compaq LBP-660 and LBP-460 parallel port laser printers (and maybe others) |
| Y | load= | Bfrecv.exe | Bitware modem driver |
| X | load= | msater.exe | Added by the RETSAM TROJAN! |
| X | load= | shambl3r.exe | Added by the REMABL WORM! |
| X | load= | Spoolsv.exe | Added by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir% |
| ? | Load= | wtfeat.exe | Associated with the Wintab Digitizer |
| Y | load= | AICLIENT.EXE | Asset Insight from Tangram - asset managing software. Required if an organisation is running a centrally administered asset management system |
| X | load= | hint.exe | Added by the ATAK WORM! |
| X | load= | win32exec.exe | Added by the BITTER WORM! |
| X | load= | a1g.exe | Added by the ATAK.B WORM! |
| X | load= | dapdll.exe | Added by the ATAK.E WORM! |
| X | load= | svhost32.exe | Added by the LINEAGE-AB TROJAN! |
| Y | load= | 01comm32.exe | Related to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions, plus a terminal program, a WWW-browser launch function, Internet telephony, and address management. Required if you use those |
| X | load= | inetinfo.exe | Added by the PROXY-GG TROJAN! |
| X | load= | Kerne14.exe | Added by the LINEAGE-BA TROJAN! |
| X | LOAD32 | Lorena.exe | Added by the MAPSON.C WORM! |
| X | load32 | load32.exe | Added by the NIBU, BAMBO TROJANS and DUMARU WORM! |
| X | load32 | l32x.exe | Added by the DUMARU.Z or DUMARU.Y or DUMARU.AD WORM! |
| X | load32 | 1111a.exe | Added by the DUMARU.AH WORM! |
| X | load32 | swchost.exe | Added by the TURTA.A WORM! |
| X | load32 | netda.exe | Added by the NIBU.E TROJAN! |
| X | load32 | winldra.exe | Added by the NIBU.J BACKDOOR or DUMARU-BI TROJAN! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger |
| X | Loadab1 | explorer.exe | Added by the LINEAGE-AJ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles% |
| Y | LoadBlackD | blackd.exe | "Intrusion detection system" of the BlackICE PC Protection (was Defender) firewall which loads independently of the "user interface" (BlackICE Utility). BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. Starts via a registry "RunServices" key on Windows 98/Me and as a service on Windows 2K/XP/Vista |
| U | LoadBtnHnd | BtnHnd.exe | Fujitsu Siemens Lifebook laptops have some buttons on the case that can be programmed to execute specified programs (like hotkeys). The buttons can also be used as a combination lock input |
| X | LoadDBackUp | BcTool.exe | Added by the GIBE WORM! |