Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 31st May, 2013
32700 items listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

420 results found for K

Startup Item or Name Status Command or Data Description Tested
k14rsystemupdaterXk14rsystemupdater.exeDetected by McAfee as RDN/Generic.dx!o and by Malwarebytes Anti-Malware as Trojan.Clicker.MNo
ker1nel32Xk1ernel32.dlIDetected by McAfee as BackDoor-RP and by Malwarebytes Anti-Malware as Trojan.DelfNo
K2ps_full.taskXK2ps_full.exeAdded by the JUNTADOR.K TROJAN!No
K6CPU.EXENK6CPU.EXEAuthenticates CPU as K6 in system propertiesNo
K7SysMonYK7SysMon.ExeK7 Computing internet security software - system monitorNo
K7SystemTrayYK7SysTry.exeK7 Computing internet security software - System Tray access/notificationsNo
K7TSStartYK7TSecurity.exeK7 Computing internet security softwareNo
Launch K9UK9.exeK9 by Robert Keir - "an email filtering application that works in conjunction with your regular POP3 email program and automatically classifies incoming emails as spam (junk email) or non-spam without the need for maintaining dozens of rules or constant updates to be downloaded. It uses intelligent statistical analysis that can result in extremely high accuracy over time"No
anhtaaaXkacsde.exeAdded by the FRETHOG-B TROJAN!No
KADxMainUKADxMain.exeSystem Tray access to IntelliSonic Speech Enhancement - by Knowles Acoustics. Designed to render speech from a user selectable direction, while canceling interfering speech from other directions, thus minimizing the effects of environmental noise and eliminating acoustic echo feedback. Found on some Dell and Fujitsu Seimens laptopsNo
Windows Service AgentXkafdprs.exeAdded by the IRCBOT.HDE BACKDOOR!No
KagwangXkagwang.exeDetected by Sophos as W32/AutoRun-XUNo
kakXkak.htaDetected by Microsoft as Trojan:JS/Kak.gen. Note - the file is located in %UserStartup% and its presence here ensures it runs when Windows startsNo
KalenderUKalender.exeUK's Kalender "helps you organizing your dates and tasks and reminds you of upcoming events"No
KalibumpUKalibump.exeUsed with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxyNo
kalvsysXkalv***32.exe [* = random char]Detected by Symantec as Trojan.ElitebarNo
kamsoftXkamsoft.exeDetected by Trend Micro as WORM_AUTORUN.BKKNo
fklw32Xkansas.exeDetected by McAfee as RDN/Generic.bfr!m and by Malwarebytes Anti-Malware as Backdoor.AgentNo
HKCUXkansas.exeDetected by McAfee as RDN/Generic.bfr!m and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
HKLMXkansas.exeDetected by McAfee as RDN/Generic.bfr!m and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
KanSenXKanSen.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%\MicrosoftNo
KanSen.exeXkansen.exeDetected by Dr.Web as Trojan.DownLoader7.870No
4abe0ecee729a9606fbe96765b6f9ff4Xkar.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%No
Microsoft Security Monitor ProcessXkar.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
[various names]XKargo.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
kartoXkarto.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd.Gen. The file is located in %AppData%\kartomizerNo
KartSvrXKartSvr.exeDetected by Dr.Web as Trojan.Siggen3.9504 and by Malwarebytes Anti-Malware as Trojan.Backdoor.SVRNo
Connect KasambaUKasamba.exe"Finding the expert help that you need is easy on Kasamba. With more than 30,000 registered experts in over 600 categories to choose from, chances are, we`ll have just the right professional in the exact area of expertise that you need"No
msenngerXkasber.exeDetected by Trend Micro as TROJ_BOTIRC.A and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Kasper AntivirusXKASPERANTIVIRUS.EXEAdded by a variant of the SPYBOT WORM!No
KasperskyAvXkaspersky.exeAdded by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky anti-virusNo
Windows Messenger ServiceXkaspersky.exeDetected by Trend Micro as WORM_MYTOB.HYNo
Kaspersky AntivirusXKasperskyAV.exeAdded by a variant of Win32/RbotNo
KasperskyAVEngXKasperskyaveng.exeAdded by the NETSKY.V WORM!No
kaspersky32XkasperskyLabs32.exeAdded by the RBOT-GOT WORM!No
MicrosoftXkasperskyLive32.exeAdded by the RBOT-GRT WORM!No
AntiVirusXkaspery.exeAdded by a variant of Win32/RbotNo
KATXKAT.vbsAdded by the SOAD-D WORM!No
SystrayXKAT.vbsAdded by the SOAD-D WORM!No
KatMouseUKatMouse.exeKatMouse - utility to enhance the functionality of mice with a scroll wheel, offering 'universal' scrolling, etcNo
AVP32XKAV.exeAdded by the AUTORUN.BCYC WORM!No
kavXkav.exeAdded by the DOGROBOT TROJAN! Note - this is not a valid old version of Kaspersky AV and is located in %System%No
KAVPersonal50YKav.exeKaspersky Anti-Virus Personal 5.0No
kviursXkav.exeAdded by the SILLYFDC.BBJ WORM!No
Protocol SettingsXkav.exeDetected by Trend Micro as WORM_RBOT.APZNo
NvCplScanXkav32.exeDetected by Sophos as W32/Forbot-EWNo
kavirXkavir.exeAdded by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an exampleNo
KavirsXKavirs.exeAdded by the AGENT-OJC TROJAN!No
Kavirs1XKavirs1.exeAdded by the AGENT-OPY TROJAN!No
LsassXkavmm.exeAdded by unidentified malware. Note - do no confuse with the legitimate Kaspersky file described here which is normally located in a sub-folder of %ProgramFiles%\Kaspersky Lab. The one is located in %Root%No
kavaXkavo.exeDetected by Sophos as Troj/Lineag-GLG and by Malwarebytes Anti-Malware as Trojan.AgentNo
Kaspersky Anti-HackerYKAVPF.exeKaspersky Anti-Hacker personal firewall - no longer availableYes
KavPFWYKavPFW.exeKingSoft Personal FirewallNo
KavStartYKAVStart.exeKingSoft Personal FirewallNo
kavsvcYkavsvc.exeKaspersky antivirusNo
WIn32S Java DLLXkavsvx.exeAdded by the AGOBOT-RZ WORM!No
KAZAANkazaa.exeKAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove itNo
Kazaa lptt01Xkazaa.exeRapidBlaster variant (in a "kazaa" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the valid KaZaA file sharing program which has the same executable nameNo
Kazaa ml097eXkazaa.exeRapidBlaster variant (in a "kazaa" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the valid KaZaA file sharing program which has the same executable nameNo
kazaaliteNkazaalite.exeKazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original, this one does not contain any advertising or tracking mechanismsNo
KaZooMNKaZooM.ExeKaZoom from Blue Haven Media - "add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches"No
InternalSystrayXKazza.exeAdded by the OPTIXPRO.12.C BACKDOOR! Note - unlike the valid KaZaA executable, this is located in %System%No
KB00650640.exeXKB00650640.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeMS. The file is located in %AppData%No
KB00674719.exeXKB00674719.exeAdded by malware, such as the INJECT-RA, ZBOT-BFC and AGENT-UIN TROJANS and CRIDEX-A WORM!No
KB01403756.exeXKB01403756.exeDetected by Malwarebytes Anti-Malware as Trojan.Inject. The file is located in %AppData%No
KB674719.exeXKB674719.exeAdded by the RORPIAN-U WORM!No
KB891711YKB891711.exeInstalled by the Windows KB891711 critical update, see this security bulletin - this file reportedly needs to continue running in order to patch the vulnerability, at least until a more practical solution is found. There have however been reports of fatal exception errors in systems running Windows 98, and in such a case Microsoft advises to either uninstall the patch (Add/Remove Programs) or prevent it from running at startupNo
KB918547YKB918547.EXEBug-fix for a Microsoft graphics rendering engine vulnerability - see here. Windows 98/Me onlyNo
KB991869.exeXKB991869.exeAdded by the DWNLDR-JGZ TROJAN!No
KBDUKBD.EXEMultimedia keyboard manager. Required if you use the multimedia keysNo
rugdvvrXkbd101O.exeAdded by the AGENT-TOS TROJAN!No
FLMK08KBUKbdAp32A.exeKeyboard utility for a Medion brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboardNo
FLMTRUSTKBUKbdAp32A.exeKeyboard utility for a Trust brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboardNo
LWBKEYBOARDUKbdAp32A.exeKeyboard utility for a Labtec brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboardNo
OFFICEKBUkbdap32a.EXEKeyboard utility for a Micro Innovations brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboardNo
QjNEMzI1RUM1RTM5MzMwRUXKBDC_2.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %UserProfile%No
OTFBNTc1Njg1QjgzRjcwNkXkbddms.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserProfile%No
Kbddrv32Xkbddrv32.exeAdded by the CRYPTER.A TROJAN!No
KbddrvinfXkbddrvinf.exeAdded by the CRYPTER.A TROJAN!No
RDFCNUQzMTAzNEFERDk0QTXKBDMdms.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %UserProfile%No
kbdmgrXkbdmgr.exeDetected by Microsoft as Backdoor:Win32/Zegost.AD. Note - this entry loads from the Windows Startup folderNo
NjkyQUEzNEVCRkI0NUNEMzXkbdmwma.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %UserProfile%No
KbdrvinfXkbdrvinf.exeAdded by the CRYPTER.A TROJAN!No
KBDUKbdStub.EXEKey Watcher from HP - watches for Multimedia Keys on HP keyboardsNo
QUNGMzk1OUJCOTg1QjYxNkXkbdWMV.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
KbEkKJuBmaVdPXKbEkKJuBmaVdP.exeAdded by the FAKEAV-DIM TROJAN!No
QUNGMzk1OUJCOTg1QjYxNkXkbfde.exeDetected by Dr.Web as Trojan.DownLoader6.60462 and by Malwarebytes Anti-Malware as Trojan.AgentNo
M0I2NTU3ODQwNUYyMEVEM0XKBiphl.exeDetected by Malwarebytes Anti-Malware as Trojan.FakePDF. The file is located in %UserProfile%No
WinServiceUpdateXkbmsjeto.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %UserProfile%No
TypingSatelliteNKBOOST.exeTypingMaster background utility that collects typing errors and builds up customised typing lessons for your needsNo
KBOXUserExtension?KBOXUserExtension.exeRelated to the Dell KACE KBOX asset management productsNo
KBR95674904.exeXKBR95674904.exeAdded by the BCKDR-RHB BACKDOOR!No
XP HOT FISXkbx.exeAdded by the FORBOT-GS WORM!No
KB[random numbers]XKB[random numbers].exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.KB. The file is located in %LocalAppData%\KB[random numbers]No
KB[random numbers].exeXKB[random numbers].exeDetected by Trend Micro as BKDR_CRIDEX.CHX and by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located in %AppData% or a sub-folderNo
Malware DestructorXKB[random numbers].exeMalware Destructor 2011 rogue security software - not recommended, removal instructions hereNo
KCeasyNKCeasy.exeKCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and GnutellaNo
cpqekUkcpqek.exeFor Compaq PC's. Easy Access button support for the keyboardNo
KcrnerXKcrner.exeAdded by the LINEAG-AIL TROJAN!No
g98oXkctqfqff.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.VB. The file is located in %System%No
Windows UpdateXkdb34894234.exeDetected by Symantec as Trojan.Syginre and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
KDGJBRVYXQCVXKDGJBRVYXQCV.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%No
MicroSoft ssadssjdhasjadas3s1Xkdjfsdklfjsl.exeAdded by the SDBOT.AEX WORM!No
Mabochine Deybug MalnagerXkdm.exeAdded by the SDBOT-SD WORM!No
Keyspan Digital Media RemoteUKDMRdmn.exeRemote control driver for Keyspan Digital Media Remote devicesNo
Kernel Video DriverXkdvhost.exeDetected by Ikarus as Backdoor.Rbot. The file is located in %System%No
Microzoft_OfizXKdzEregli.exeAdded by the AMUS.A WORM!No
KeAppletXke64dyshrmlfu.exeDetected by Sophos as Troj/ZBot-AXH and by Malwarebytes Anti-Malware as Trojan.AgentNo
KeAppletXke64jlnfhw.exeDetected by Kaspersky as Backdoor.Win32.Agent.bqin and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp%No
KeenvalueXKeenvalue.exeKeenVal adwareNo
KeePassUKeePass.exeOpen source KeePass Password Safe password manager by Dominik Reichl - "which helps you to manage your passwords in a secure way. You can put all your passwords in one database, which is locked with one master key or a key file." See the comparison page for the differences between versionsYes
KeePass 2 PreLoadUKeePass.exePart of version 2.x of the open source KeePass Password Safe password manager by Dominik Reichl - "which helps you to manage your passwords in a secure way. You can put all your passwords in one database, which is locked with one master key or a key file." See the comparison page for the differences between versions. Preloads parts KeePass into memory - not required if you have also enabled the program to run at startup (Options → Integration)Yes
KeePass Password SafeUKeePass.exeVersion 1.x of the open source KeePass Password Safe password manager by Dominik Reichl - "which helps you to manage your passwords in a secure way. You can put all your passwords in one database, which is locked with one master key or a key file." See the comparison page for the differences between versionsYes
KeePass Password Safe 1.*UKeePass.exeVersion 1.x of the open source KeePass Password Safe password manager by Dominik Reichl - "which helps you to manage your passwords in a secure way. You can put all your passwords in one database, which is locked with one master key or a key file." See the comparison page for the differences between versions. Vista/7 MSConfig and Windows Defender entry where 1.* represents the version numberYes
KeePass Password Safe 2UKeePass.exeVersion 2.x of the open source KeePass Password Safe password manager by Dominik Reichl - "which helps you to manage your passwords in a secure way. You can put all your passwords in one database, which is locked with one master key or a key file." See the comparison page for the differences between versionsYes
KeepCopXKeepCop.exeKeepCop rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
KeepCop.exeXKeepCop.exeKeepCop rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
Java UpdateXkeeper.exeAdded by the AGENT-DIS TROJAN!No
cvhnykzxXkeepSafe.exeAdded by the KILLAV.KAX TROJAN! Note - this is not the legitimate KeepSafe from Stardock Corporation which shares the same filename and is normally located in a %ProgramFiles%\Stardock subfolder. This one is found in %System%No
deryheruxcXkeepSafe.exeAdded by the KILLAV.KAX TROJAN! Note - this is not the legitimate KeepSafe from Stardock Corporation which shares the same filename and is normally located in a %ProgramFiles%\Stardock subfolder. This one is found in %System%No
dsfghjgjXkeepSafe.exeAdded by the KILLAV.KAX TROJAN! Note - this is not the legitimate KeepSafe from Stardock Corporation which shares the same filename and is normally located in a %ProgramFiles%\Stardock subfolder. This one is found in %System%No
hfdtubvnxXkeepSafe.exeAdded by the KILLAV.KAX TROJAN! Note - this is not the legitimate KeepSafe from Stardock Corporation which shares the same filename and is normally located in a %ProgramFiles%\Stardock subfolder. This one is found in %System%No
hgkytweXkeepSafe.exeAdded by the KILLAV.KAX TROJAN! Note - this is not the legitimate KeepSafe from Stardock Corporation which shares the same filename and is normally located in a %ProgramFiles%\Stardock subfolder. This one is found in %System%No
ilortgdgXkeepSafe.exeAdded by the KILLAV.KAX TROJAN! Note - this is not the legitimate KeepSafe from Stardock Corporation which shares the same filename and is normally located in a %ProgramFiles%\Stardock subfolder. This one is found in %System%No
KeepSafeYkeepsafe.exeKeepSafe from Stardock Corporation - "the intermediate step needed to secure data between backups. It saves your important files in real-time as you work on them"Yes
TXMouieXkeepSafe.exeAdded by the KILLAV.KAX TROJAN! Note - this is not the legitimate KeepSafe from Stardock Corporation which shares the same filename and is normally located in a %ProgramFiles%\Stardock subfolder. This one is found in %System%No
vcbbjfXkeepSafe.exeAdded by the KILLAV.KAX TROJAN! Note - this is not the legitimate KeepSafe from Stardock Corporation which shares the same filename and is normally located in a %ProgramFiles%\Stardock subfolder. This one is found in %System%No
xcfdhtyjkxXkeepSafe.exeAdded by the KILLAV.KAX TROJAN! Note - this is not the legitimate KeepSafe from Stardock Corporation which shares the same filename and is normally located in a %ProgramFiles%\Stardock subfolder. This one is found in %System%No
kegimnoceasaXkegimnoceasa.exeDetected by McAfee as RDN/Downloader.a!g and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
keiopXkeiop.exeAdded by the VB-ERU TROJAN!No
kelelistXkelelist.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%\kelelisprotectorNo
KERNETXkellogs.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%No
WIRENETXkellogs.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%No
Logitech SetPointUKEM.exeKeyboard and mouse drivers and utilities for Logitech's latest products - supersedes iTouch and MouseWare on their older products. Required if you use special features such as multimedia keysNo
KEMailKbUKEMailKb.EXEMultimedia keyboard/keypad manager. Required if you use the additional keysNo
Kemet?kemet.exe??No
kenizXkeniz.exeAdded by the AUTORUN-AZL WORM!No
Windows Task Manager EmulatorXkennewr.exeAdded by the SPYBOT-FA WORM!No
KeNotifyUKeNotify.exeToshiba utility found on their laptops. This program is responsible for the Toshiba LapTop Help 'FlashCards' utility that sits at the top of the screen giving easy access to the 'F keys' alternative functions such as Lock,Power Mode,Sleep etcNo
keqeliqzemecXkeqeliqzemec.exeDetected by Malwarebytes Anti-Malware as Trojan.Ransom.Gen. The file is located in %UserProfile%No
kerbuduryweaXkerbudurywea.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile%No
kEReXkERe.exeAdded by the BRONTOK-BT WORM!No
Microsoft Update EmulatorXkern-mxe.exeAdded by a variant of Win32/RbotNo
kernel32Xkern32.exeDetected by Trend Micro as WORM_BADTRANS.ANo
Win32UpdaterXKERNAL32.EXEAdded by the SPYBOT-OK WORM!No
Windows Kernel 64Xkernal64.exeAdded by the YIMP-B WORM!No
Kerne0223XKerne0223.exeAdded by the LEGMIR-ZA TROJAN!No
loadXKerne121.exeAdded by the LINEAGE-ON TROJAN!No
loadXKerne1211.exeAdded by the LINEAGE-DY TROJAN!No
load=XKerne14.exeAdded by the LINEAGE-BA TROJAN!No
PlobXkernel.comAdded by the OPTIXPRO.12 BACKDOOR!No
kernel32Xkernel.dliAdded by the NETDEVIL.B TROJAN!No
Kernel32XKernel.dllDetected by McAfee as VBS/Redlof@MNo
defaultXkernel.exeAdded by the SALUNI TROJAN!No
kernelXkernel.exeDetected by Total Defense as Matcash CF. The file is located in %ProgramFiles%\kernelNo
Kernel_32XKernel.exeDetected by Malwarebytes Anti-Malware as Trojan.Inject. The file is located in %Windir%\Isp_32No
Microsoft WindowsXKernel.exeAdded by the EDIBARA-A VIRUS!No
Microsoft WindowsXKernel.vbsAdded by the EDIBARA-A VIRUS!No
kernel12.exeXkernel12.exeAdded by an unidentified WORM or TROJAN!No
Win32GXKernel32.comAdded by the ESTRELLA TROJAN!No
kernel32Xkernel32.dlIAdded by the NETDEVIL.15 TROJAN!No
Kernell32XKernel32.dll.exeDetected by McAfee as W32/Acinti.wormNo
kernel32Xkernel32.dll.vbsAdded by the WEKODE-A WORM!No
32-bit Windows KernelXKernel32.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
InternalSystrayXkernel32.exeDetected by Trend Micro as BKDR_OPTIX.12BNo
Kernel Level ApplicationXKernel32.exeDetected by Dr.Web as Trojan.PWS.Stealer.379No
Kernel32XKernel32.exeAdded by a number of VIRUSES, WORMS and TROJANS!No
LoadWindowsFileXKernel32.exeAdded by the DELF.B BACKDOOR!No
Microsoft Windows System KernelXkernel32.exeAdded by a variant of the IRCBOT TROJAN!No
MstaskXkernel32.exeAdded by the STAP-C WORM!No
rundll32Xkernel32.exeAdded by the STAP-C WORM!No
Windoes KernelXkernel32.exeAdded by the KICKIN.A (or CYDOG.C) WORM!No
WindowsXKernel32.exeAdded by the TENDOOLF.A WORM!No
WSAConfigurationXkernel32.exeAdded by the AGOBOT-KV WORM!No
systemXkernel32.iniDetected by Trend Micro as WORM_SILLYFDC.CJNo
Win32 Kernel core componentXKernel32.pifAdded by the MOKS VIRUS!No
Kernel32XKernel32.winAdded by the GAGGLE.D or GAGGLE.E WORMS!No
Distributed File SystemXkernel32dll.exeAdded by the MYFIP-C or MYFIP.K WORMS!No
Kernel32Xkernel32s.exeAdded by the BCKDR-CIC BACKDOOR!No
rundll32Xkernel33.exeAdded by the STAP-D WORM!No
Microsoft Kernel PatchXkernel3ox.exeAdded by the RBOT-UJ WORM!No
Kernel 64x supportXkernel64.exeDetected by Sophos as Troj/Vidlo-E and by Malwarebytes Anti-Malware as Trojan.MixusNo
SystemXkernel8.exeAdded by the DLOADR-AOL TROJAN!No
DefencerGBAXKernelBases.exeDetected by Microsoft as TrojanSpy:Win32/Banker.YX. The file is located in %System%No
DefencerGBAXKernelBases.exeDetected by Malwarebytes Anti-Malware as Spyware.Banker. The file is located in %UserProfile%\AppData\LocalFilesNo
filename processXkerneldll.exeAdded by the AGOBOT-PO WORM!No
KernelFaultCheck32XKernelFaultCheck32.exeDetected by Dr.Web as Trojan.Siggen5.4841No
PlobXkerneli.comAdded by the OPTIXPRO.12 BACKDOOR!No
SystemXkernels1118.exeAdded by a variant of W32/Sdbot.wormNo
SystemToolsXkernels1118.exeAdded by a variant of W32/Sdbot.wormNo
Service SystemXkernels32.exeDetected by Sophos as Troj/Bancos-DA and by Malwarebytes Anti-Malware as Trojan.BankerNo
SystemXkernels32.exeDetected by Sophos as Troj/Dloader-FC and by Malwarebytes Anti-Malware as Trojan.FakeAlertNo
SystemToolsXkernels32.exeDetected by Sophos as Troj/Dloader-FCNo
SystemXkernels64.exeAdded by the VIXUP-S TROJAN!No
SystemXkernels8.exeDetected by Trend Micro as TROJ_TIBS.AINo
SystemToolsXkernels8.exeAdded by the FNG TROJAN!No
SystemXkernels88.exeDetected by Sophos as Troj/Tibs-PP and by Malwarebytes Anti-Malware as Trojan.AgentNo
SystemToolsXkernels88.exeDetected by Sophos as Troj/Tibs-PP and by Malwarebytes Anti-Malware as Trojan.AgentNo
IMEKernel32XKernelsys32.exeDetected by Symantec as W32.HLLW.GOP@mmNo
KernelwXKernelw32.exeAdded by the INDOR.E WORM!No
SystemXkernelwind32.exeDetected by Total Defense as Vxidl FT and by Malwarebytes Anti-Malware as Trojan.FakeAlertNo
SystemXkernelwind64.exeDetected by Trend Micro as TROJ_DLOADER.DJD and by Malwarebytes Anti-Malware as Trojan.DownloaderNo
KernelRuntimeXkernel_runtime.exeAdded by the MYTOB-JO WORM!No
KRNLXKernl32.exeDetected by Kaspersky as Backdoor.Win32.Zomby.bNo
LazXKernn.exeDetected by Sophos as Troj/Bancos-LNNo
MicroSoft ToolbarXkey.exeAdded by the RBOT-AEW WORM!No
KeyAccessYkeyacc32.exeKeyServer KeyAccess client software - "when the KeyServer program is launched, the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess, a keyed program cannot run, so license control is very secure"No
AidemHotKey?KEYAPP.EXEKeyboard relatedNo
KeybdcntlXkeybdcntl.exeAdded by the GEMA TROJAN!No
[various names]Xkeybdll.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
keyboardXkeyboard*.exe [* = number]Detected by Kaspersky as the VB.ZG TROJAN!No
(Default)XKEYBOARD.exeAdded by the AUTORUN.BUK WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
KeyBoardUKeyboard.exeLabtec keyboard utilityNo
Microsoft Taskmanager UpdaterXkeyboard.exeAdded by the RBOT-ALU WORM!No
Microsoft Windows Keyboard serviceXkeyboard.exeAdded by the RBOT-CRF WORM!No
NLS KeyboardXkeyboard.exeAdded by a variant of the SPYBOT WORM!No
ntgyXkeyboarda.exeDetected by Dr.Web as Trojan.DownLoader8.18852 and by Malwarebytes Anti-Malware as Trojan.AgentNo
XvtpiqbeXkeyboardo.exeDetected by Dr.Web as Trojan.DownLoader9.10873No
keyboard_enumXkeyboard_enum.exeAdded by the BDOOR-GP BACKDOOR!No
Srv32WinXKeyCaptor.exeKeyCaptor surveillance software. Uninstall this software unless you put it there yourselfNo
keyhookUkeyhook.exeHotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeysYes
SiS Compatible Super VGA Keyboard DaemonUkeyhook.exeHotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeysYes
SiS Windows KeyHookUkeyhook.exeHotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeysYes
WinEssentialXKeyhost.exeDetected by Symantec as Adware.JraunNo
VC_LogUkeylog.exePaqKeylog is a surveillance software program that logs keystrokes and can run in stealth mode. Uninstall this software unless you put it there yourselfNo
ABCUkeylogger.exeKeystroke logger/monitoring program - remove unless you installed it yourself!No
HomeKeyLoggerUKeyLogger.exeSpyKeySpy surveillance software. Uninstall this software unless you put it there yourselfNo
1Win32CfgUKeyloggerpro.exeKeyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!No
CherryKeyManUKeyMan.exeMultimedia keyboard manager for the Cherry keyboard series. Only required if you use any of the special keysNo
keymapUkeymap.exeSystem Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the gameNo
TaskMgrXkeymayker.exeAdded by the LDPINCH-EP TROJAN!No
Microsoft System CheckupXKeymgr.exeAdded by the DONK.M WORM!No
KeyPangXkeypang.exeDetected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %ProgramFiles%\KeyPangNo
KeyPatrolYKeyPatrol.exeKeyPatrol - keylogger detector using both behavioral and pattern-matching algorithms. Part of the original anti-malware program by PestPatrol, Inc. Acquired by CA where it became eTrust PestPatrol Anti-Spyware and then CA Anti-Spyware - which is now included in CA AntiVirus PlusYes
Keyboard LauchpadUKeys.exeKeyboard Launchpad from Stardock Corporation - "can create keyboard short-cuts for your programs, saved clipboards, URLs, system commands, and more." Required if you want to use the custom keyboard shortcuts. Also part of the Object Desktop suiteYes
MicroUpdateXkeys.exeDetected by Dr.Web as Trojan.DownLoader6.51768 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System%\UpdaterNo
Stardock Keyboard LaunchpadUKeys.exeKeyboard Launchpad from Stardock Corporation - "can create keyboard short-cuts for your programs, saved clipboards, URLs, system commands, and more." Required if you want to use the custom keyboard shortcuts. Also part of the Object Desktop suiteYes
KeyScramblerYkeyscrambler.exeKeyScrambler from QFX Software Corporation - "encrypts your keystrokes deep in the kernel, foiling keylogging attacks with scrambled, undecipherable data"Yes
keyservXkeyserv.exeKeyThief spywareNo
ChromeMark?keysh.exeRelated to this. Don't know what keysh.exe does though and if it's requiredNo
KLogUKeyspy.exeKeyLoggPro.B keystroke logger/monitoring program - remove unless you installed it yourself!No
psklUkeyspy.exeKeyboardLogger keystroke logger/monitoring program - remove unless you installed it yourself!No
Keyboard Status?KeyStat.exeMultimedia keyboard manager for Medion desktop and notebook PCs? Located in %ProgramFiles%\Medion\KeyStatNo
Toshiba Key StateUKEYSTATE.EXEDisplays an icon in the System Tray indicating the state of the CAPS LOCK key. Can be handy on (e.g., Toshiba) laptops which do not have a Caps Lock indicator light. Available via Start → ProgramsNo
keystrokeUkeystroke.exeQuickLaunch surveillance software. Uninstall this software unless you put it there yourselfNo
Key TextNKeyText.exeKey Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start → ProgramsNo
WinEssentialXkeyword.exeAdware.Jraun variantNo
keywordfindagentXkeywordfindagent.exeDetected by McAfee as Generic.tfr!ck and by Malwarebytes Anti-Malware as Adware.KraddareNo
KeywordSearchUpdaterXkeywordfindagent.exeDetected by McAfee as Generic.tfr!ck and by Malwarebytes Anti-Malware as Adware.KraddareNo
[various names]XKeywordFinder.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
keywordpop.exeXkeywordpop.exeDetected by Dr.Web as Trojan.DownLoader7.20458 and by Malwarebytes Anti-Malware as Adware.KorAdNo
KeywordSearchUpdaterXKeywordSearchUpdater.exeKeyword Search adwareNo
keywordtabhperXkeywordtabhper.exeDetected by McAfee as Generic Downloader.x!g2g and by Malwarebytes Anti-Malware as Adware.KeywordTab.KNo
keywordtabopenXkeywordtabopen.exeDetected by McAfee as Generic Downloader.x!g2g and by Malwarebytes Anti-Malware as Adware.KeywordTab.KNo
keywordtabXkeywordtabup.exeDetected by McAfee as Generic Downloader.x!g2g and by Malwarebytes Anti-Malware as Adware.KeywordTab.KNo
KeywordYacXKeywordYacUpdate.exeDetected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %ProgramFiles%\KeywordYacNo
Service SystemXkgbfsm344.exeDetected by Sophos as Troj/Bancos-FSNo
suapafjjXkgejbaytssd.exeAdded by the AGENT-MXH TROJAN!No
kgjdi27Xkgjdie27.exeAdded by the SDBOT.AP BACKDOOR!No
KGSMXKGSM.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System%No
Winsock2 driverXkgzgjkpcw.exeAdded by the SDBOT.T TROJAN!No
SETPOINT Logitech IncXKHALMNP.exeAdded by the RBOT-AAX WORM!No
Kernel and Hardware Abstraction LayerUKHALMNPR.EXEPart of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). When using SetPoint to adjust the mouse sensitivity it is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, this entry sets the Windows setting to 0 so it doesn't affect the one you set in SetPoint and then unloads. A separate instance of KHALMNPR.EXE loads via the main Setpoint.exe program to control communication between your radio/bluetooth wireless mouse/keyboard and SetPointYes
KHALMNPRUKHALMNPR.EXEPart of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). When using SetPoint to adjust the mouse sensitivity it is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, this entry sets the Windows setting to 0 so it doesn't affect the one you set in SetPoint and then unloads. A separate instance of KHALMNPR.EXE loads via the main Setpoint.exe program to control communication between your radio/bluetooth wireless mouse/keyboard and SetPointYes
Logitech Hardware Abstraction LayerUKHALMNPR.EXEPart of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). When using SetPoint to adjust the mouse sensitivity it is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, this entry sets the Windows setting to 0 so it doesn't affect the one you set in SetPoint and then unloads. A separate instance of KHALMNPR.EXE loads via the main Setpoint.exe program to control communication between your radio/bluetooth wireless mouse/keyboard and SetPointYes
Logitech SetPointUKHALMNPR.EXEPart of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). When using SetPoint to adjust the mouse sensitivity it is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, this entry sets the Windows setting to 0 so it doesn't affect the one you set in SetPoint and then unloads. A separate instance of KHALMNPR.EXE loads via the main Setpoint.exe program to control communication between your radio/bluetooth wireless mouse/keyboard and SetPointYes
khanchoUpdateXkhanag.exeDetected by Dr.Web as Trojan.DownLoader6.25995 and by Malwarebytes Anti-Malware as Adware.KraddareNo
khanchoXkhanup.exeDetected by Dr.Web as Trojan.DownLoader6.25995 and by Malwarebytes Anti-Malware as Adware.FunPop.KNo
KHATARNAK LoaderXKHATARNAK.exeDetected by Trend Micro as WORM_AUTORUN.ACONo
loadXKHATRA.exeAdded by the ORBINA-A WORM!No
nwizXKHATRA.exeAdded by the ORBINA-A WORM!No
PHIME2002AXKHATRA.exeDetected by Microsoft as Worm:Win32/Abfewsm.ANo
TaskmanXKHATRA.exeAdded by the AUTORUN-AKR WORM!No
VMware ToolsXKHATRA.exeDetected by Sophos as W32/Autoit-BPNo
VMware User ProcessXKHATRA.exeAdded by the AUTOIT.K TROJAN!No
XplorerXKHATRA.exeDetected by Sophos as W32/AutoRun-AKR and by Malwarebytes Anti-Malware as Trojan.FakeFolderNo
khookerNkhooker.exeSiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't requiredNo
SiS KHookerNkhooker.exeSiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't requiredNo
4oDUKHost.exePart of the Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops. As used by earlier versions of the UK's 4oD (4 on Demand) serviceNo
kdxNKHost.exePart of the Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops. As used by earlier versions of UK on-demand services such as Sky Anytime, BBC iPlayer and 4od (4 on-demand)No
(Default)Xkiarash test.exeDetected by Dr.Web as Trojan.MulDrop4.28932 and by Malwarebytes Anti-Malware as Trojan.Agent.TPL. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
Kryptel Component StartUKicker.exeKryptel encryption softwareNo
KICKMON.EXEUKICKMON.EXEKeepItClean - utility that deletes safe to remove files, cookies, browsing history, etc. This is the scheduler - if you don't schedule clean-ups it isn't requiredNo
KiesPreload?Kies.exePart of the SAMSUNG Kies mobile device management softwareNo
KiesAirMessageUKiesAirMessage.exeSupports the Kies Air feature from Samsung - which "is a mobile application which enables Wi-Fi mobile-to-device connections and browser-based management. You can use Kies Air without PC software or a USB connection"No
KiesUKiesHelper.exeInstalled with the SAMSUNG Kies mobile device management software. Preloads part of Kies into memory to speed up the loading time of the main program and exits after running. Tested without a supported device on a system with more than 1GB of memory it took twice as long for Kies to start with this entry disabledYes
KiesHelperUKiesHelper.exeInstalled with the SAMSUNG Kies mobile device management software. Preloads part of Kies into memory to speed up the loading time of the main program and exits after running. Tested without a supported device on a system with more than 1GB of memory it took twice as long for Kies to start with this entry disabledYes
KiesPDLR?KiesPDLR.exePart of the SAMSUNG Kies mobile device management softwareNo
Kies TrayAgentNKiesTrayAgent.exeSAMSUNG Kies mobile device management software which also allows you to view apps in full screen on your PC, no matter what network you're on. Allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Only required if you want to autostart Kies when your device is connectedYes
KiesTrayAgentNKiesTrayAgent.exeSAMSUNG Kies mobile device management software which also allows you to view apps in full screen on your PC, no matter what network you're on. Allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Only required if you want to autostart Kies when your device is connectedYes
kiGUicdXkiGUicd.exeDetected by McAfee as RDN/Generic Dropper!e and by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
MicroUpdateXKIKO.exeDetected by Dr.Web as Trojan.DownLoader6.25616 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Root%\MRTCDNo
killXkill.cplDetected by Malwarebytes Anti-Malware as Trojan.Agent.CPL. The file is located in %LocalAppData%No
ScvbostXkill.ExeDetected by Malwarebytes Anti-Malware as Backdoor.DarkKomet. The file is located in %Temp%\killer - see hereNo
[various names]Xkillall.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
KillAndCleanXKillAndClean.exeKillAndClean rogue spyware remover - not recommended, removal instructions hereNo
EasyFace AgentUKillAutoAP.exeEasyFace™ by MSI - "integrated face registration, face tracking, and face detection technology" for both internal and external webcams which allows the user to login via face recognitionNo
DlloadXkiller.exeAdded by the KILLAV-FK TROJAN!No
cartaoXkilling.exeAdded by the DLOADER-QN TROJAN!No
Kill PopupUKillPopup.exeKillPopup - pop-up stopperNo
System StartupXkimochi.exeAdded by the SPYBOT.AII WORM!No
kimochiz.exeXkimochiz.exeAdded by the MDROP-BB TROJAN!No
KinberlinkNKinberlink.exeKinberlink network messaging. Available via Start → ProgramsNo
kinglottoXkinglottoUp.exeDetected by Malwarebytes Anti-Malware as Adware.Nieguide. The file is located in %ProgramFiles%\kinglottoNo
kingrsps.exeXkingrsps.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %Root%No
KINPle Update CheckXKinPleStart.exeDetected by Emsisoft as Backdoor.Win32.Webdor!IK and by Malwarebytes Anti-Malware as Spyware.KinPlayer. The file is located in %ProgramFiles%\KinPleNo
DSFGWRXkiuht.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Root%\fsefdsNo
FGHRSDRXkiuht.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Root%\fsefdsNo
INTEFSXkiuht.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Root%\fsefdsNo
kizzeqofliljXkizzeqoflilj.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile%No
kjEenXNPEgLSPXkjEenXNPEgLSP.exeAdded by the FAKEAV-MD TROJAN!No
faslkakj11Xkjgagklj11.exeAdded by the LEGMIE-ARE TROJAN!No
Windows DefenderXKJHEAPC69E.exeDetected by McAfee as Generic.dx!bd3y and by Malwarebytes Anti-Malware as Trojan.Agent.Gen. Note - this is not the legitimate Microsoft Windows Defender whose filename is MSASCui.exe and the file is located in %AppData%No
Microsoft UpdateXKkk.exeAdded by the RBOT-AHL WORM!No
kkkoreXkkkore.exeDetected by Malwarebytes Anti-Malware as Trojan.QHost.K. The file is located in %Windir%No
KKM ServiceXkkm.exeAdded by the NANPY-I WORM!No
KkwkwuXKkwkwu.exeDetected by Malwarebytes Anti-Malware as Worm.Dorkbot. The file is located in %AppData%No
kkw_run.exeUkkw_run.exeKensington KeyboardWorks - keyboard software. Not required unlessyou use any special featuresNo
Windows UpdateXklass.exeDetected by Sophos as Troj/Bifrose-ZH and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
LayoutMUKLayMgr.exeKeyboard manager for Chicony keyboards - required if you use any of the special or function keysNo
RKLG StartupUklg.exeLocal Keylogger Pro keystroke logger/monitoring program - remove unless you installed it yourself!No
KlipFolioUKlipFolio.exeKlipfolio Dashboard KPI (Key Performance Indicator) software which helps organizations evaluate their success or the success of a particular activity in which they're engagedNo
KLMUKLM.exeMSI Keyboard LED Manager for supported laptop models (such as the GT70) which have keyboards with multi-colored LED backlighting - allowing you to pick a color, lighting mode and section of the keyboardNo
cdmmslpoXklpllsm.exeAdded by the TEDIJINI-A TROJAN!No
WinAC v4Xklsuicbn.exeAdded by the FORBOT-CS WORM!No
BtcMaestroUKMaestro.exeMultimedia keyboard manager. Required if you use the multimedia keysNo
KeyMaestroUkmaestro.exeMultimedia keyboard manager. Required if you use the multimedia keysNo
keymatchXkmagt.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %AppData%\keymatchNo
gWtXkmiqdeimiufb.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.WTG. The file is located in %System%No
BitocmetXKMPlayir.exeDetected by Trend Micro as TROJ_VB.FPWNo
f73d8fea88579bcf83d51be1f8408f87XKMS.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp%No
Intel(Ms)Xkms.exeDetected by Dr.Web as Trojan.Siggen5.23631 and by Malwarebytes Anti-Malware as Backdoor.Agent.ITNNo
kmw_run.exeUkmw_run.exeKensington MouseWorks - mouse/trackball software. Not required unles you use any special featuresNo
kmw_show.exeUkmw_show.exeKensington MouseWorks - mouse/trackball software. Not required unles you use any special featuresNo
WinSrvXkn0x.exeDetected by Trend Micro as WORM_HOBBIT.FNo
Tablet Human Hardware Themes Class CenterXknfjpkjv.exeDetected by McAfee as RDN/Downloader.a!g and by Malwarebytes Anti-Malware as Trojan.AgentNo
Disk KnightXKnight.exeAdded by the AUTORUN-H WORM!No
KNK StartXKNK.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.STRGenNo
Windows Service Ag3ntXknpcoq.exeAdded by the SDBOT.EZX TROJAN!No
PdllXKnucker.C.vbsDetected by Malwarebytes Anti-Malware as Worm.VBS. The file is located in %System%No
KnupperXKnupperDetected by McAfee as RDN/Generic.bfr!e and by Malwarebytes Anti-Malware as Backdoor.AgentNo
KODAK Software UpdaterNKodak Software Updater.exeSoftware updater for Kodak Easyshare digital camerasNo
KodakCCSYKodakCCS.exeKodak DC File System DriverNo
WindowsXkohaLqha.exeAdded by the NUSUMP-C WORM!No
King_koXkoking.exeAdded by the AUTORUN-BMU WORM!No
rn4dXkolder.exe dirote.exeAdded by the MAROON.A BACKDOOR! Both files are located in %System%\d0e0t1No
msnupdtXkolie.exeDetected by Malwarebytes Anti-Malware as Backdoor.MessaNo
Bron-Spizaetus-5118REPMXkomodo-6321422.exeAdded by the BRONTOK-R WORM!No
PujanggaXKOMPTI.exeAdded by the PITKOM-A TROJAN!No
Warga KompTiXKOMPTI.exeAdded by the PITKOM-A TROJAN!No
Konni Symbol AutostartNKonniSymbol.exeGives configuration access to RagTime Solo professional business publishing software. RagTime Solo is the private user version of RagTime 5No
cnetNkontiki.exeKontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops. Version for c|netNo
GameSpotNkontiki.exeKontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops. Version for GameSpotNo
kontikiNkontiki.exeKontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktopsNo
zdnetNkontiki.exeKontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops. Version for ZDNetNo
kotechprotectXkotechprotect_up.exeKotech-Protect rogue security software - not recommended, removal instructions hereNo
F1XJGGIM31EBXKP4UMB72.exeDetected by McAfee as RDN/Generic.bfr!m and by Malwarebytes Anti-Malware as Backdoor.AgentNo
BLMC3Mouse-KPDrv4XPYKPDrv4XP.exeMultimedia USB mouse driver. Required if you use the additional buttonsNo
KPDrv4XPYKPDrv4XP.exeMultimedia keyboard/keypad/mouse driver. Required if you use the additional keysNo
KXT01_KPDrv4XPYKPDrv4XP.exeMultimedia USB keyboard driver. Required if you use the additional keysNo
USBKBDrvYKPDrv4XP.EXEMultimedia keyboard/keypad driver. Required if you use the additional keysNo
USB-TenKey USBKPDrvYKPDRV4XP.EXEMultimedia USB keypad driver. Required if you use the additional keysNo
Zippy USBKPDrvYKPDRV4XP.EXEZippy multimedia USB keypad driver. Required if you use the additional keysNo
KperfectXKPerfect.exeDetected by Dr.Web as Trojan.DownLoader5.24152No
KavPFWYKPFW32.EXEKingsoft Personal FirewallNo
KPFW32.EXEYKPFW32.EXEKingSoft Personal FirewallNo
KPFWSvc.EXEYKPFWSvc.EXEKingSoft Personal FirewallNo
KPNAssistentUpdaterNKPNAssistentUpdater.exeUpdater for the KPN Assistant self-help support tool for KPN broadband users (provided by Support.com (aka SupportSoft or Tioga))No
MicrosoftctfmonXkr.exeDetected by Dr.Web as Trojan.DownLoader6.9905 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Kr0n1CXKr0n1C.exeDetected by Sophos as W32/Brontok-BONo
kragXkrag.exeAdded by the AGENT-FOW WORM!No
KraidmanUKraidman.exe"Toshiba RAID Support is a Toshiba EasyGuard feature that uses RAID Level 1 technology to minimise downtime by protecting against data loss and ensuring quick data recovery" - for Toshiba laptopsNo
MJCXREYWRURCOTI0MJNFMKXkratrwrk.exeDetected by McAfee as PWS-Zbot.gen.po and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
KREC32Ukrec32.exeKBMonitor keystroke logger/monitoring program - remove unless you installed it yourself!No
Microsoft DocumentXkrisp.exeAdded by the SDBOT-RQ WORM!No
SystemXkrln32.exeMalware installed by different rogue security software including SpyKillerProNo
startkeyXkrnl.exeAdded by the BIFROSE-S TROJAN!No
Kernel32Xkrnl32.exeAdded by the EPON WORM!No
krnl386Xkrnl386.exeDetected by Kaspersky as Trojan.Win32.VB.aqvlNo
Kernel ManagerXkrnlmgr.exeAdded by the JUNY.A TROJAN!No
KrnlmodUKrnlmod.exeKeystroke logger/monitoring program - remove unless you installed it yourself!No
krnlinitXkrnlx86.exeDetected by Dr.Web as BackDoor.IRC.Mishko.52 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Windows Service AgentXkrqbs.exeAdded by the IRCBRUTE.AZ TROJAN!No
RUI4QKYXRDLEQZRERTUXNJXkrzngtjw.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %UserProfile%No
KsjhdfxXKsjhdfx.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
MSRegScanUKSPDemo.exeKeyStalker PRO surveillance software. Uninstall this software unless you put it there yourselfNo
Ksrv32XKsrv32.exeAdded by the AGOBOT-PI WORM!No
KClientUkstatus.exeKClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnetNo
MSConfigXksum.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
Nvidia Startup ManagerXksvc32.exeDetected by Sophos as Troj/Agent-IWDNo
KSVSvc.exeXKSVSvc.exeDetected by Trend Micro as TSPY_ONLINEG.CTMNo
Microsoft AntiSpywareXKT06.pifAdded by a variant of the IRCBOT BACKDOOR!No
KTAX Auto LoaderXktax.exeAdded by the SDBOT-MZ WORM!No
ktchnsnkUktchnsnk.exeHP program found with the Office Jet 500/600/700 series which initializes the Office Jet manager each time the computer is booted up or rebootedNo
KTPWareYktp.exeRelated to KTP Ware TSR Enhancements from ELANTECHNo
Start RF Wireless KeyboardYktrexe.exeYuanxun Electronics RF wireless keyboard driverNo
Rakyat_KelaparanXKuli.exeAdded by the SILLYFDC.BDM WORM!No
Kuma_TrayNKuma_tray.exeSystem Tray access to free games from KumaNo
Optimize WindowsXKuntilanak.exeAdded by the SILLYFDC WORM!No
RPCall_WIN2KXKurawas.exeAdded by the BHARAT.A WORM!No
UUSeeiXKuwoi.exeDetected by Trend Micro as TROJ_VB.FPWNo
kvasoftXkva8wr.exeDetected by Trend Micro as WORM_ONLINEG.ICCNo
KvmSecure.exeXKvmSecure.exeKvmSecure rogue security software - not recommended, removal instructions hereNo
Kerio VPN ClientUkvpnclient.exeKerio VPN ClientNo
Kvsc3XKvsc3.exeAdded by the PWS-ANM TROJAN!No
AeTWEnNoIZyaIiUYGtHGEdWktjXkVsEoYPVDuCgJx.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System% - see hereNo
FGHDFYFJXKVVRIA96Y5.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%No
KeyWalletUKWallet.exe"KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins, passwords and other personal data manually"No
KwSvScanXkwsvscan.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%\My UserProgramsNo
KiweeHookNkwtbaim.exeKiwee toolbar - allows emoticons, winks, text and greetings to be added to conversations. Note - can be difficult to remove and is potentially dangerous as it may install malware and collect user-identifying information possibly resulting in privacy violations and identity theft - see here. For this reason it is classified as EMD (sites engaged in malware distribution) by hpHosts - see hereNo
KX509Ukx509_kfwk5.exeKerberos Secure Authentication for WindowsNo
kxescYkxetray.exeSystem Tray access to and notifications for Kingsoft security productsNo
kX MixerNkxmixer.exeProvides Mixer and Control functionality to KxProject Audio driver for EMU10k based soundcardsNo
KXT01_KeyboardUKXT01KB.EXEMultimedia USB keyboard manager. Required if you use the additional keysNo
kxvaXkxvo.exeAdded by the AUTORUN-DY WORM!No
MSNXkys7r.exeAdded by the AUTORUN-AR WORM!No
KY Control SettingsXKYSVCCD.EXEDetected by Trend Micro as WORM_SDBOT.BHJNo
KYK Control SettingsXKYSVCXD.EXEAdded by a variant of Win32/RbotNo
kytqetorjansXkytqetorjans.exeDetected by Malwarebytes Anti-Malware as Trojan.Cutwail. The file is located in %UserProfile%No
Supports RAS ConnectionsXkznytwg.EXEDetected by Sophos as Troj/Agent-AASM and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo

Notes & Warnings

If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).

"Status" key:

Variables:

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.

WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.

As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.

There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program

NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.

SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.

Copyright

Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved

Valid XHTML 1.0 Transitional

Privacy Policy Site Map Home