Windows Security Authority Service lsass.exe X Added by the [email protected] mass-mailing worm. LWBMOUSE lwbwheel.exe U Mouse driver - required if you use non-standard Windows driver features Lwinst Run Profiler lwtest.exe N Logitech Wingman Profiler for the Logitech joysticks. This infection should not be confused with the legitimate C:\Windows\System32\lsass.exe file. When executed, it displays an unknown fake login page.Referenceshttp://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS_FEEBS.XSCreditsReported by Trend Micro Flag Permalink This was helpful (0) Collapse - W32/HLLP.Philis.fv by Marianna Schmudlach / February 12, 2007 7:12 AM PST http://songstersoftware.com/general/troj-dloader-os.html
When connected this infections connects to an IRC server where it waits for remote commands to execute. This infection also installs the rootkit file C:\Windows\System32\msdirectx.sys which is used to hide files, processes, and registry keys. Lexmark printer related. lexmark **** series lxbtbmgr.exe U Lexmark System Tray application (where "****" is the model) that enables scan or fax functions to run directly from the printer via the buttons.
The virus may also attempt to copy itself to remote network shares. Browse Threats in Alphabetical Order: # A B C D E F G H I J K L M N O P Q R S T U V W X Y Microsoftf DDEs Control lses.exe X Identified as a variant of Backdoor.Win32.Rbot.gen worm and IRC backdoor. Required for correct operation [random name] l?gonui.exe X PurityScan adware variant.
- SHOW ME NOW CNET © CBS Interactive Inc. / All Rights Reserved.
- http://www.claymania.com/anti-virus-fr.html Safe-Hex http://sebsauvage.net/safehex.html B) Communiquer "troj dloader atd" n'est pas le nom exact du virus trouvé...
- Visual Lube.html X Added by the WM97/Lebone-A Microsoft Word macro virus.
- Product support Online Safety @ Home The 6 Big Dangers Kid's Online Safety Resource Library All topics For Business >Small Business3-100 users Popular products: Worry-Free virus and threat protection Services
- q36i36O lms2cenu.exe X Added by the SECONDTHOUGHT VIRUS!
- If you remove this service, you may no longer be able to play certain CDs from Sony on your computer.If you have this service, then there is a good chance you
- Therefore, even after you remove TROJ_DLOADER.LPH from your computer, it’s very important to clean the registry.
- The latest protection included in virus definitions for Intelligent Updater and for LiveUpdate are available at the following link: Symantec The Symantec Security Response for Backdoor.Delf.E is available at the following
Soft Modem Messaging application - may be found on Fujitsu Lifebook, Acer and Sony Vaio notebooks, maybe others too LTWinModem1 ltmsg.exe Y One of the "popular" WinModem series. Troj/Aprodl-A may download and run further software. The welcome screen is displayed. This should not be confused with the legitimate iexplore.exe found in the C:\Program Files\Internet Explorer directory.
For restricted shares... Home Software Products WinThruster DriverDoc WinSweeper SupersonicPC FileViewPro About Support Contact Malware Encyclopedia › Trojans › TROJ_DLOADER.LPH How to Remove TROJ_DLOADER.LPH Overview Aliases Behavior Risk Level: MEDIUM Threat Name:TROJ_DLOADER.LPH Threat Family:TROJ_DLOADER Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually Windows Shell Library Loader load shell.dll /c /set X CoolWebSearch This infection steals email account information from the computer.
As a result, you will gradually notice slow and unusual computer behavior. W32/Akbot-AG spreads to other network computers by exploiting common buffer overflow vulnerabilities, including ASN.1 (MS04-007). LTCISI ltcisi.exe X Added by the W32/Delbot-AP worm and IRC backdoor. Track this discussion and email me when there are updates If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and
Common sources of such programs are: Malicious websites designed specifically to inject Trojans Legitimate websites infected with Trojans Email attachments Fake updates presented for installed software Peer-to-peer sharing software Malicious video TROJ_DELF.LDK Alias:Trojan-Downloader.Win32.Delf.cdx (Kaspersky), Downloader (Symantec), TR/Dldr.Delf.cdx.2 (Avira), TrojanDownloader:Win32/Delf (Microsoft) TROJ_DELF.CRP Alias:Trojan-Spy.Win32.Delf.ps (Kaspersky), PWS-QQGame (McAfee), Trojan Horse (Symantec), TR/Spy.Delf.PS.48 (Avira), Mal/QQPass-B...which is detected by Trend Micro as TROJ_DELF.CRY, in the said folder. http://www.sophos.com/virusinfo/analyses/trojdloadratx.html Flag Permalink This was helpful (0) Collapse - W32/HLLP.Philis.ga by Marianna Schmudlach / February 12, 2007 2:07 AM PST In reply to: VIRUS ALERTS - February 12, 2007 Description:W32/HLLP.Philis.ga is This infection should not be confused with the legitimate Microsoft file c:\windows\system32\lsass.exe.
Lpr123 Lpr123.exe X Added by the REMPSTEAL password stealer TROJAN! have a peek at these guys Step 13 Click the Close () button in the main window to exit CCleaner. LDM LogitechDesktopMessenger.exe N Installed with the software for Logitech products. http://www.sophos.com/virusinfo/analyses/trojbanloaddx.html Flag Permalink This was helpful (0) Collapse - Troj/Bancban-GK by roddy32 / October 24, 2005 1:39 AM PDT In reply to: VIRUS ALERTS - Octobet 24, 2005 Type Spyware Trojan
CLICK HERE to verify Solvusoft's Microsoft Gold Certified Status with Microsoft >> CLOSE Business For Home Alerts No new notifications at this time. What does it do, and is it required? Preview post Submit post Cancel post You are reporting the following post: VIRUS ALERTS - Octobet 24, 2005 This post has been flagged and will be reviewed by our staff. check over here AdobeReaderPro lssas.exe X Added by the W32/Rbot-CLB worm and IRC backdoor.
DO NOT have Hijack This fix anything yet. Configuration Loader lfass.exe ? ?? If you did not install this software you should uninstall it.
lsasvc lsasvc.exe X Added by the Troj/Bckdr-PXT backdoor Trojan.
When started, this infection connects to a remote IRC server where it waits for commands to execute. Related to a Lexmark printer/scanner. li-multi**** li-multi****.exe X Adult web-dialler - **** is random li-thund**** li-thund****.exe X Adult web-dialler - **** is random li-vita**** li-vita****.exe X Adult web-dialler - **** is random Lightning Download Lightning.exe U vou savé pô aikrir!
When a document is inserted in the scanner the wakeup program feeds the document a fraction of a inch into the scanner and then it launches the control center software. Windows Update Manager lansas.exe X Added by the WORM_RBOT.EKK worm and IRC backdoor. Do not uncheck if the DSL modem is being used LTDMgr LTDMgr.exe X PowerStrip foistware LtMoh Ltmoh.exe U Modem On Hold utility - manages incoming/outgoing voice calls on a single phone http://songstersoftware.com/general/troj-dloader-rky.html Found in the Windows system folder.
LaunchAp LaunchAp.exe U Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610 Launchboard lnchbrd.exe U "LaunchBoard software from Darwin turns your keyboard into a remote LightScribeService Direct Disc Labeling Service LSSrvc.exe Y This service is required to allow 3rd-party cd/dvd writing software to properly use LightScribe technology. See here for more WinModem information ZeroAds LAS0Ads.exe U ZeroAds - culls ads, cookies and pop-ups. When executed, it drops copies of itself and a .DLL component, which Trend Micro also detects as TROJ_DELF.AQJ, in the Windows system folder.
Microsoft (R) Windows Network Security Service lsass.exe X Added by the Backdoor.Ranky backdoor Trojan. load32 load32.exe X Added by the NIBU, BAMBO TROJANS and DUMARU WORM! Microsoft Authority Service lsass.exe X Added by the [email protected] mass-mailing worm. Printer sharing server?
It extends Win98/NT/2K/XP to have a fully skinnable user interface. WINDOWS SYSTEM logic.exe X Added by the [email protected] worm. By now, your computer should be completely free of TROJ_DLOADER.LPH infection. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
Runner lsass.exe X Added by the Troj/AdClick-AG Trojan! Newer Than: Search this thread only Search this forum only Display results as threads Useful Searches Recent Posts More... It may attempt to connect to a remote server.