| Status | Autorun name | Command | Description |
| X | K2ps_full.task | K2ps_full.exe | Added by the JUNTADOR.K TROJAN! |
| N | K6CPU.EXE | K6CPU.EXE | Authenticates CPU as K6 in system properties |
| X | kaa | SVCHHS.exe | Added by the AGENT-JKP TROJAN! |
| X | Kadoc | [random filename].exe | Added by the STAPREW TROJAN! |
| U | KADxMain | KADxMain.exe | System Tray access to IntelliSonic Speech Enhancement - by Knowles Acoustics. Designed to render speech from a user selectable direction, while canceling interfering speech from other directions, thus minimizing the effects of environmental noise and eliminating acoustic echo feedback. Found on some Dell and Fujitsu Seimens laptops |
| X | kak | kak.hta | Added by the KAKWORM WORM! |
| U | Kalender | Kalender.exe | UK's Kalender "helps you organizing your dates and tasks and reminds you of upcoming events" |
| U | Kalibump | Kalibump.exe | Used with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy |
| X | kalvsys | kalv****.exe [* = random char] | EliteBar adware |
| X | kalvsys | kalv***32.exe [* = random char] | EliteBar adware |
| X | kamsoft | ckvo.exe | Added by the GAMANIA-BW TROJAN! |
| N | Kana Reminder | Reminder.exe | Kana Reminder is a program which can be used to set a reminder to be triggered at a specified time |
| U | Karen's Once-A-Day II | PTOAD.exe | "Have a job that should be run exactly once each day? Karen's Once-A-Day II is just what you need!" Scheduler that lets you specify progams, web pages and files that be run or opened automatically, the first time |
| U | KASP | OESpamTest.exe | Kaspersky Anti-Spam |
| X | Kasper Antivirus | KASPERANTIVIRUS.EXE | Added by a variant of the SPYBOT WORM! |
| Y | Kaspersky Anti-Hacker | KAVPF.exe | Kaspersky Anti-Hacker personal firewall - no longer available |
| Y | Kaspersky Anti-Virus Monitor | AvpM.exe | Kaspersky Anti-Virus Lite - no longer available |
| X | Kaspersky Antivirus | KasperskyAV.exe | Added by a variant of the RBOT WORM! |
| X | Kaspersky Email Security | javaupd.exe | Added by the SWARLEY.A WORM! |
| X | kaspersky32 | kasperskyLabs32.exe | Added by the RBOT-GOT WORM! |
| X | KasperskyAv | kaspersky.exe | Added by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky anti-virus |
| X | KasperskyAVEng | Kasperskyaveng.exe | Added by the NETSKY.V WORM! |
| X | KAT | KAT.vbs | Added by the SOAD-D WORM! |
| U | KatMouse | KatMouse.exe | KatMouse - utility to enhance the functionality of mice with a scroll wheel, offering 'universal' scrolling, etc |
| Y | kav | avp.exe | Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory |
| X | kava | kavo.exe | Added by the LINEAG-GLG TROJAN! |
| X | KAVFOX | win1ogoin.exe | Added by the GWGHOST-M TROJAN! |
| X | kavir | kavir.exe | Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example |
| X | KAVPersonal | svchost.exe | Added by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| Y | KAVPersonal50 | Kav.exe | Kaspersky Anti-Virus Personal 5.0 |
| X | KAVPersonal90 | wscntfy.exe | Added by the BANKER-FZ TROJAN! |
| Y | KavPFW | KavPFW.exe | KingSoft Personal Firewall |
| X | KavRuns | Windll.exe | Added by the TRYNOMA TROJAN! |
| X | kavs | svchost.exe | Added by the AGENT-GLC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| Y | KavStart | KAVStart.exe | KingSoft Personal Firewall |
| Y | kavsvc | kavsvc.exe | Kaspersky antivirus |
| X | KavSvc | ******.exe reg_run [* = random char] | Added by the QOOLOGIC TROJAN! |
| X | kavsvc | [random 6 char filename] | Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe, rzazzi.exe, ivpaan.exe) |
| X | KAVutil | [worm filename] | Added by the WINTOO.B WORM! |
| N | KAZAA | kazaa.exe | KAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it |
| N | KAZAA | [path] kpp.exe [path] kazaalite.kpp | System Tray access to later versions of the Kazaa Lite P2P file sharing utility - namely the K++ and Resurrection variants. Kazaa Lite is the unauthorized modification of the original Kazaa Media Desktop - with the malware removed |
| X | Kazaa Download Accelerator Updater (required) | regsvr32 kdp****.dll [* = random char] | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% |
| X | Kazaa lptt01 | kazaa.exe | RapidBlaster variant (in a "kazaa" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name |
| X | Kazaa ml097e | kazaa.exe | RapidBlaster variant (in a "kazaa" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name |
| X | KAZAACuf | 9 | Added by the KITRO.D (or ARGEN.A) WORM! |
| N | kazaalite | kazaalite.exe | Kazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original, this one does not contain any advertising or tracking mechanisms |
| N | KaZooM | KaZooM.Exe | KaZoom from Blue Haven Media - "add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches" |
| X | kb | AUTO.txt | Added by the BRONTOK-CV WORM! |
| Y | KB891711 | KB891711.exe | Installed by the Windows KB891711 critical update, see this security bulletin - this file reportedly needs to continue running in order to patch the vulnerability, at least until a more practical solution is found. There have however been reports of fatal exception errors in systems running Windows 98, and in such a case Microsoft advises to either uninstall the patch (Add/Remove Programs) or prevent it from running at startup |
| Y | KB918547 | KB918547.EXE | Bug-fix for a Microsoft graphics rendering engine vulnerability - see here. Windows 98/Me only |
| Y | KB926239 | rundll32.exe apphelp.dll, ShimFlushCache | Microsoft KB926239 fix. Windows Media Player 10 may close unexpectedly on a Windows XP-based computer |
| U | KBD | KBD.EXE | Multimedia keyboard manager. Required if you use the multimedia keys |
| U | KBD | KbdStub.EXE | Key Watcher from HP - watches for Multimedia Keys on HP keyboards |
| U | KBD MediaCenter | MEDIACTR.EXE | Multimedia keyboard manager. Required if you use the multimedia keys |
| X | kbddrv32 | kbddrv32.exe | Added by the CRYPTER.A TROJAN! |
| X | kbddrvinf | kbddrvinf.exe | Added by the CRYPTER.A TROJAN! |
| N | KCeasy | KCeasy.exe | KCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella |
| U | KClient | kstatus.exe | KClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet |
| X | Kcrner | Kcrner.exe | Added by the LINEAG-AIL TROJAN! |
| X | kdmsx | [8 random letters].exe | Added by the SDBOT.AIJ BACKDOOR! |
| N | kdx | KHost.exe | Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops |
| U | KE9801 | DriBat32.exe | KE9801 multimedia keyboard driver - required if you use the multimedia keys |
| X | Keenvalue | Keenvalue.exe | KeenVal adware |
| X | KeepCop | KeepCop.exe | KeepCop rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | KeepCop.exe | KeepCop.exe | KeepCop rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | keiop | keiop.exe | Added by the VB-ERU TROJAN! |
| X | kell | liser.exe | Added by the AGENT.AUTP TROJAN! |
| U | KEMailKb | KEMailKb.EXE | Controls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down |
| ? | Kemet | kemet.exe | ?? |
| U | KeNotify | KeNotify.exe | Toshiba utility found on their laptops. This program is responsible for the Toshiba LapTop Help 'FlashCards' utility that sits at the top of the screen giving easy access to the 'F keys' alternative functions such as Lock,Power Mode,Sleep etc |
| X | kERe | kERe.exe | Added by the BRONTOK-BT WORM! |
| U | Kerio VPN Client | kvpnclient.exe | Kerio VPN Client |
| X | kern64dll | [random filename] | Added by the TARNO.J TROJAN! |
| X | Kernal Fault Check | ntosrkl.exe | Added by a variant of the SDBOT WORM! |
| X | kernctl32 | rundll32 kctl32.dll, initialize | Added by the AGENT.AT TROJAN! |
| X | Kerne0223 | Kerne0223.exe | Added by the LEGMIR-ZA TROJAN! |
| X | Kernel | bboy.exe | Added by the MUMU.B WORM! |
| X | Kernel | services.exe | Added by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | kernel | kernel.exe | Added by the MATCASH.CF TROJAN! |
| X | Kernel | Update.exe | Added by the DELF-FN TROJAN! |
| X | KERNEL 32 | SKERNEL32.com | Added by the SEMAPI-A WORM |
| U | Kernel and Hardware Abstraction Layer | KHALMNPR.EXE | Part of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). When using SetPoint to adjust the mouse sensitivity it is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, this entry sets the Windows setting to 0 so it doesn't affect the one you set in SetPoint and then unloads. A separate instance of KHALMNPR.EXE loads via the main Setpoint.exe program to control communication between your radio/bluetooth wireless mouse/keyboard and SetPoint |
| X | Kernel Faults | ftphost.exe | Added by the RBOT.BHU WORM! |
| X | Kernel Loader | ntkrnl.exe | Added by the CERVIVEC.A WORM! |
| X | Kernel Manager | krnlmgr.exe | Added by the JUNY.A TROJAN! |
| X | Kernel Safe Mode | smss.exe | Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Kernel Services | service32.exe | Added by the PRX-B TROJAN! |
| X | kernel system daemon | ACTIVAT0R.exe | Added by the RANDEX.AW WORM! |
| X | Kernel_check | wmiprvse.exe | Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the %System%\wbem folder and should not normally figure in Msconfig/Startup! |
| X | kernel12.exe | kernel12.exe | Added by an unidentified WORM or TROJAN! |
| X | kernel32 | kern32.exe | Added by the BADTRANS.A WORM! |
| X | Kernel32 | Kernel32.exe | Added by a number of VIRUSES, WORMS and TROJANS! |
| X | kernel32 | kernel.dli | Added by the NETDEVIL.B TROJAN! |
| X | Kernel32 | Kernel.dll | Added by the REDLOF.M VIRUS! |
| X | kernel32 | kernel32.dlI | Added by the NETDEVIL.15 TROJAN! |
| X | Kernel32 | krnl32.exe | Added by the EPON WORM! |
| X | Kernel32 | Kernel32.win | Added by the GAGGLE.D or GAGGLE.E WORMS! |
| X | Kernel32 | kernel32s.exe | Added by the BCKDR-CIC BACKDOOR! |
| X | kernel32 | kernel32.dll.vbs | Added by the WEKODE-A WORM! |
| X | Kernel32 | svchosts.exe | Added by an unidentified WORM or TROJAN! |