| Status | Autorun name | Command | Description |
| X | loaddll | loaddll.exe | Winvest spyware |
| X | loaddr | [path to trojan] | Added by the AGENT-DIY TROJAN! |
| Y | LoadDvpApi9x | DVPAPI9X.exe | Command AntiVirus for Windows 95/98/Me |
| X | loader | loader.exe | Homepage hijacker, redirecting to coolwwwsearch.com. Downloader for iedll.exe |
| X | loader | WMPLAYER.EXE | Unknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup |
| X | Loader msgzl | msgzl.exe | Added by the SDBOT.BVF WORM! |
| X | loader32 | sys*****.exe [***** = random digit] | Added by the DOMCOM TROJAN! |
| X | loader32 | Loader32.exe | Added by an unidentified TROJAN! |
| X | Loaders | HeIp.exe | Added by the SDBOT-ADB WORM! |
| X | Loaders | HeIp.pif | Added by the SDBOT-ACS WORM! |
| X | LoadEWXD | msxml4r.exe | LoadEWXD adware |
| X | loadfax | loadfax.exe | Added by the WINFLUX-C BACKDOOR! |
| X | LoadFonts | LoadFonts.vbs | Homepage hijacker that changes your homepage to an adult content site |
| X | LoadFonts | Tahoma.vbs | Homepage hijacker that changes your homepage to an adult content site |
| U | LoadFujitsuQuickTouch | QuickTouch.exe | Maps the keys on a Fujitsu Siemens Lifebook application panel to various programs and functions |
| X | LoadGolfCourses | LoadGolfCourses.exe | PlayMiniGolf.com foistware - stealth installed! |
| X | Loadhg | rundll32.exe | Added by the LINEAG-ABX TROJAN! |
| X | LoadHTML | rundll32.exe regsvr32.exe,MShtmpre | MatrixSearch adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | LoadingAgent | ZipLoader32.exe | Added by the OBLIVION TROJAN! This executable is one of the most common but there are more |
| X | LoadingAgent | msload32.exe | Added by the OBLIVION TROJAN! This executable is one of the most common but there are more |
| X | LoadManager | msload.exe | Added by the OPASERV.T WORM! |
| X | loadMecq0 | explorer.exe | Added by the MUMUBOY.C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles% |
| X | loadMecq3 | rundll32.exe | Added by the LEGMIR-AS TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in the root folder (i.e., C:\) |
| X | loadMect1 | explorer.exe | Added by the LINEAGE-L TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles% |
| X | loadMefs | rundll32.exe | Added by the LEGMIR-JB TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\inf |
| X | loadMefs | smss32.exe | Added by the FLOOD-EL TROJAN! |
| N | LoadMSvcmm | msvcmm32.exe | Auto-update for the now defunct Movielink "web-based video on demand (VOD) and electronic sell-through (EST) service offering movies, TV shows and other videos for rental or purchase". Movielink LLC were acquired by Blockbuster in 2008 |
| X | LoadOrderVerification | [random filename] | Added by the TRON.A BACKDOOR! |
| U | Loadout Manager | nost_LM.exe | Manager for the Belkin Nostromo n50 SpeedPad game controller - see here |
| X | LoadPFW | wmimgr.exe | Added by the QEDS-B WORM! |
| X | LoadPowerProfile | ASDAPI.EXE | Added by the CABRO TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll |
| U | LoadPowerProfile | Rundll32.exe powrprof.dll | Power management specifics such as monitor shut-off, system standby, etc. Associated with power management and is listed twice - see here. Loads your selected power scheme. May not be required - depends upon whether you modify the default Control Panel -> Power Options settings |
| X | LoadPowerProfile | Rundll.exe powerprof.dll | Added by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses "Rundll.exe" whereas the uninfected version uses "Rundll32.exe" |
| X | LoadPowerProfile | rundl.exe | Added by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll |
| X | LoadPowerProfile | Rundll32.exe | Added by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has "powrprof.dll" appended to the command/data line |
| X | LoadPowerScheme | rundll32.exe powerprof.dll CheckPowerProfile | Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| U | LoadQM | loadqm.exe | Installed with MSN Explorer and loads the MSN Queue Manager. Required to enable the WU AutoUpdate feature. Note that disabling this can sometimes prevent internet sharing working on Win2K Pro SP2. Reports also suggest that removing it will re-enable internet access - hence the "users choice" recommendation. If you have problems leave it, otherwise I recommend you disable it |
| X | loads.exe | loads.exe | MediaMotor adware |
| X | loads.exe | medload.exe | Medload adware |
| X | loads.exe | suploads.exe | Added by the AGENT-BZ TROJAN! |
| X | LoadService | Rest In Peace | Added by the KANGAROO-A WORM! |
| X | LoadService | Maaf, tempatmu bukan di sin | Added by the KAGEN-A TROJAN! |
| X | LoadService | Virus | Added by the CAGER.A WORM! |
| X | LoadService | user32.com | Added by the BURMEC WORM! |
| X | LoadSIPS | rundll32.exe SIPSPI32.dll, SIPSPI32 | 123Mania adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SIPSPI32.dll" file is found in the System folder |
| X | LoadWatcher | watcher.exe | Watcher spyware |
| ? | LoadWatcher | Test.exe | Reportedly part of a webcam surveillance program that's supposed to test SMTP dialling in the event of an alert? Is this correct? |
| X | loadwin | winset.exe | Added by the QQPASS-I TROJAN! |
| X | loadwin | winsys.exe | Added by the QQPASS-J TROJAN! |
| X | LoadWindowsFile | Kernel32.exe | Added by the DELF.B BACKDOOR! |
| X | Local Area Network | OpenGL.exe | Added by a variant of the RBOT WORM! |
| X | Local Authority Service | lsass.exe | Added by the MARKTMAN-C TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Local Internet Connection | LIC.exe | Added by the SDBOT-YA WORM! |
| X | LOCAL INTERNET WEB DRIVERS FOR WIN32 | phqghume.exe | Added by a variant of the RBOT WORM! |
| X | Local Page | http://find.naupoint.com | Naupoint browser hijacker |
| X | Local runole service | srvc32.exe | Added by the SMALL-DP TROJAN! |
| X | Local Security Authority Servce | lssas.exe | Added by the POEBOT-T WORM! |
| X | Local Security Authority Service | lssas.exe | Added by the POEBOT-J WORM! |
| X | Local Security Authority Service | Isass.exe | Added by the LINKBOT.M WORM! |
| X | Local Service | Intenat.exe | Added by the NUCLEAR-J TROJAN! |
| X | Local Service | services.exe | Added by the P2PWORM-T WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Cursors |
| X | Local-Settings-of-[User Name] | [User Name].exe | Added by the GAVGENT.A WORM! |
| U | LocalProxy | proxy4free.exe | "ProxyTools is a package of Perl network utilities designed mainly to assist those whose Internet access is censored, unreliable, or otherwise damaged. Uncensored access is provided to any outside service required (Usenet News, Web browsing, IRC, Socks etc.). Setup requires installation of Perl and some modules" |
| X | LocalSystem | svchost.exe | EHU adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Locator Service | [filename] | Added by the AGOBOT-KY TROJAN! |
| X | Locinx | gdicli.exe | Added by the AGENT-PAW TROJAN! |
| U | Lock My PC | lockpc.exe | Lock My PC - a tool for quick computer locking when you leave it unattended. It shows a lock screen, disables Windows hot keys and mouse |
| X | lofgyh | lofgyh.exe | Added by the SDBOT-TP WORM! |
| U | Logan_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4500 Series multifunction printer |
| X | logg | logo_1.exe | Added by the PWFUZZ-A WORM! |
| U | Logi_MwX | Logi_MwX.exe | Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled |
| X | Logical Disk Detection | mrisvc.exe | Added by the IRCBOT.AOW BACKDOOR! |
| N | Logiciel de transfert d'images KODAK | pts.exe | Looks for Kodak camera connection and media insertion. Available via Start -> Programs |
| N | Logiciel notes Post-it® | psnotes.exe | Logicel Post-it® (developed by 3M) - now replaced by the more advanced Post-it® Digital Notes |
| U | Login | winlog.exe | Salfeld Child Control - parental control software |
| X | login | [path to trojan] | Added by the HOTWORD-A TROJAN! |
| X | Login | Login.exe | Added by the BANCBAN-AH TROJAN! |
| X | Login | lala.exe | Added by the BUGSPR-A TROJAN! |
| X | Login Screen Saver | login.scr | Added by the RBOT-AVN WORM! |
| X | Login Service | [path to file] | Added by the MIGMAF TROJAN! |
| X | Login Software 2009 | [path to trojan] | Added by the ERTFOR.B TROJAN! |
| X | LoginPassport | Lgnpsp32.exe | Added by the REDIST.C WORM! |
| X | loginui32 | loginui32.exe | Added by the LONGNU.A BACKDOOR! |
| X | Logitech | Logitech.exe | Added by the RBOT.BJH WORM! |
| Y | Logitech | Communications_Helper.exe | Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also, if it's disabled the camera will not work - at least not in the QuickCapture mode |
| N | Logitech . Product Registration | eReg.exe | Registration reminder from Leader Technologies for Logitech software such as SetPoint for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc) |
| U | Logitech BT Wizard | LBTWiz.exe | Bluetooth connection manager for Logitech based bluetooth wireless products |
| X | Logitech Camera | Soundcane.exe | Added by the SDBOT.MUC WORM! |
| ? | Logitech Camera Software | ElkCtrl.exe | Entry added when you install versions of the Logitech QuickCam webcam software. It's exact purpose is unknown at the present time |
| U | Logitech ClickSmart | ISStart.exe | Installed with Logitech's QuickSmart webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videos |
| U | Logitech ClickSmart | LogiTray.exe | System Tray access to My Logitech Pictures, Camera Settings and other features for Logitech's QuickSmart webcam software. Create your own shortcut and run it manually when required unless you use it all the time |
| U | Logitech ClickSmart | LVCOMS.EXE | Entry added when you install Logitech ClickSmart webcam software. It allows the camera to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required |
| X | Logitech Desktop | ApPache.exe | Added by the RBOT-YP WORM! |
| X | Logitech Desktop | IPCONN.EXE | Added by the SDBOT-WE WORM! |
| X | Logitech Desktop Controller | wrcam.exe | Added by a variant of the RBOT WORM! |
| N | Logitech Desktop Messenger | setup-8876480.exe | Installer for Logitech Desktop Messenger included with older versions of the software for Logitech products - which automatically checks for software upgrades and new products, services and special offers from Logitech |
| N | Logitech Desktop Messenger | ldmconf.exe | Installed with older versions of the software for Logitech products. Configures the options for Logitech Desktop Messenger to activate notifications about software upgrades and/or new products, services and special offers |
| N | Logitech Desktop Messenger | LogitechDesktopMessenger.exe | Installed with the software for Logitech products. Automatically checks for software upgrades and new products, services and special offers from Logitech |
| N | Logitech Desktop Messenger Agent | ldmconf.exe | Installed with older versions of the software for Logitech products. Configures the options for Logitech Desktop Messenger to activate notifications about software upgrades and/or new products, services and special offers |
| N | Logitech Gaming Software | LWEMon.exe | Part of Logitech Gaming Software (formerly Wingman Software) for their range of game controllers. Starts the profiler (button configuration) and loads the last used profile at start-up - including System Tray access. Unless you're a hard-core gamer it's best to leave it disabled and load when needed |