| Status | Autorun name | Command | Description |
| X | Kernel Safe Mode | smss.exe | Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Kernel Services | service32.exe | Added by the PRX-B TROJAN! |
| X | kernel system daemon | ACTIVAT0R.exe | Added by the RANDEX.AW WORM! |
| X | Kernel_check | wmiprvse.exe | Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the %System%\wbem folder and should not normally figure in Msconfig/Startup! |
| X | kernel12.exe | kernel12.exe | Added by an unidentified WORM or TROJAN! |
| X | kernel32 | kern32.exe | Added by the BADTRANS.A WORM! |
| X | Kernel32 | Kernel32.exe | Added by a number of VIRUSES, WORMS and TROJANS! |
| X | kernel32 | kernel.dli | Added by the NETDEVIL.B TROJAN! |
| X | Kernel32 | Kernel.dll | Added by the REDLOF.M VIRUS! |
| X | kernel32 | kernel32.dlI | Added by the NETDEVIL.15 TROJAN! |
| X | Kernel32 | krnl32.exe | Added by the EPON WORM! |
| X | Kernel32 | Kernel32.win | Added by the GAGGLE.D or GAGGLE.E WORMS! |
| X | Kernel32 | kernel32s.exe | Added by the BCKDR-CIC BACKDOOR! |
| X | kernel32 | kernel32.dll.vbs | Added by the WEKODE-A WORM! |
| X | Kernel32 | svchosts.exe | Added by an unidentified WORM or TROJAN! |
| X | Kernel32 | svchost.exe | Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\drivers |
| X | Kernel32_sysdamper | sysdamp.exe | Added by an unidentified WORM or TROJAN! See here |
| X | kernel32dll | guardpc.exe | Added by the FORBOT-CU WORM! |
| X | kernel32sys.dll | IEXPLORER.exe | Added by the RBOT-MK WORM! |
| X | kernel44.dll | taskkill /f /fi "PID ge 0" /im * | Added by the VBS.LIDO WORM! |
| X | KernelCheck | sys****.exe [* = digit] | Added by an unidentified TROJAN! |
| X | KernelCheck | winser.exe | Added by the TSPY_LMIR.SL TROJAN! |
| X | KernelCheck | winbery.exe | Added by the LEGMIR-CG TROJAN! |
| X | KernelConfig | destiny32.exe | Added by the AGOBOT.AMB WORM! |
| N | kernelfaultcheck | dumprep 0 -k | Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out |
| X | KernelFaultCheck | ptool32.exe | Added by the LEGMIR-BN TROJAN! |
| X | KernelFaultCheck | msime.exe | Added by the TINY-P TROJAN! |
| X | KernelFaultCheck | tell32.exe | Added by the LEGMIR-BF TROJAN! |
| X | KernelFaultCheck | winabc3.exe | Added by the NUBYS-A VIRUS! |
| X | KernelFaultCheck | winbin.exe | Added by the DLOADR-AAX TROJAN! |
| X | KernelFaultChk | sms.exe | Added by the DEADHAT WORM! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k" |
| X | Kernell | systems.exe | Added by the TARNO.C TROJAN! |
| X | Kernell32 | Kernell.dll | Added by the DESTINY.A TROJAN! |
| X | KernellApps | csrss.exe | Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "System" subfolder |
| X | KernellApps | lexplore.exe | Added by the BANCBAN-BS TROJAN! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer |
| X | KernellApps | svshosti.exe | Added by the BANCBAN-V TROJAN! |
| X | KernellApps32 | smss.exe | Added by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! |
| X | KernelRuntime | [path to worm] | Added by the MYTOB-JO WORM! |
| X | Kernelw | Kernelw32.exe | Added by the INDOR.E WORM! |
| X | key | sysxp.exe | Added by the BEAGLE.AB WORM! |
| X | key | sys_xp.exe | Added by the BEAGLE.AC WORM! |
| X | key | winxp.exe | Added by the BEAGLE.AG WORM! |
| X | Key Logger | csrss.exe | Added by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie, C:\) |
| N | Key Text | KeyText.exe | Key Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs |
| X | Key1 | Rlid.exe | Added by the LIXY TROJAN! |
| ? | Key2 | serve.exe | ?? |
| X | key2 | winlog.exe | Added by the BAGLEDI-AL TROJAN! |
| Y | KeyAccess | keyacc32.exe | KeyServer KeyAccess client software - "when the KeyServer program is launched, the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess, a keyed program cannot run, so license control is very secure" |
| X | Keybdcntl | keybdcntl.exe | Added by a variant of the CRYPTER.C TROJAN! |
| ? | KeybdUtility | HotKey.exe | Located in a LG Software\LG OSD directory. Related to function keys on and LG Electronics system? |
| U | KeyBoard | Keyboard.exe | Labtec keyboard utility |
| X | keyboard | keyboard*.exe [* = number] | Detected by Kaspersky as the VB.ZG TROJAN! |
| X | keyboard | [spyware filename] | DollarRevenue spyware. The file is located in %Root% (i.e. C:\ D:\, etc) |
| X | keyboard | [path to trojan] | Added by the DLOADR-AOZ TROJAN! |
| X | Keyboard | lsass.exe | Added by the AGENT.US WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %CommonAppData%\Fearghus |
| N | Keyboard Customizer | TpKmapAp.exe | Part of the Keyboard Customizer Utility for IBM/Lenovo Thinkpad notebooks. This is the main user interface for the utility but it doesn't normally seem to be running if enabled at startup. Also, it doesn't appear to need to be running for custom key combinations to work (via TpKmapMn.exe) |
| U | Keyboard Lauchpad | Keys.exe | Keyboard Launchpad from Stardock Corporation - "can create keyboard short-cuts for your programs, saved clipboards, URLs, system commands, and more." Required if you want to use the custom keyboard shortcuts. Also part of the Object Desktop suite |
| U | Keyboard Logger | Logger.exe | Keyboard Logger keystroke logger/monitoring program - remove unless you installed it yourself! |
| U | Keyboard Manager | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
| Y | Keyboard Preload Check | Preload.exe | Millenium Multi-Function Keyboard driver |
| ? | Keyboard Status | KeyStat.exe | Multimedia keyboard manager for Medion desktop and notebook PCs? Located in %ProgramFiles%\Medion\KeyStat |
| X | keyboard_enum | keyboard_enum.exe | Added by the BDOOR-GP BACKDOOR! |
| U | keyhook | keyhook.exe | Hotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeys |
| U | KeyLogger | syssafe.exe | GhostLog surveillance software. Uninstall this software unless you put it there yourself |
| U | KeyMaestro | kmaestro.exe | Multimedia keyboard manager. Required if you use the multimedia keys |
| U | keymap | keymap.exe | System Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game |
| X | keymgrldr | rundll32 setupapi, InstallHinfSection... keymgr3.inf | CoolWebSearch Oemsyspnp parasite variant |
| Y | KeyPatrol | KeyPatrol.exe | KeyPatrol - keylogger detector using both behavioral and pattern-matching algorithms. Part of the original anti-malware program by PestPatrol, Inc. Acquired by CA where it became eTrust PestPatrol Anti-Spyware and then CA Anti-Spyware - which is now included in CA AntiVirus Plus |
| U | keyplusplus | startk.exe | Key++ Invisible Spy Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! |
| Y | KeyScrambler | keyscrambler.exe | KeyScrambler from QFX Software Corporation - "encrypts your keystrokes deep in the kernel, foiling keylogging attacks with scrambled, undecipherable data" |
| X | keyserv | keyserv.exe | KeyThief spyware |
| U | Keyspan Digital Media Remote | KDMRdmn.exe | Remote control driver for Keyspan Digital Media Remote devices |
| U | keystroke | keystroke.exe | QuickLaunch surveillance software. Uninstall this software unless you put it there yourself |
| U | KeyWallet | KWallet.exe | "KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins, passwords and other personal data manually" |
| X | KeywordSearchUpdater | KeywordSearchUpdater.exe | Keyword Search adware |
| X | Kf3pn4 | myclient.exe | Added by the VBINJ-S TROJAN! |
| X | kfienq | masbl.bat | Added by the KIFER TROJAN! |
| X | kgjdi27 | kgjdie27.exe | Added by the SDBOT.AP BACKDOOR! |
| X | Kgjg | rnnypbw.exe | Added by the QuickLinks/Forethought adware |
| U | KHALMNPR | KHALMNPR.EXE | Part of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). When using SetPoint to adjust the mouse sensitivity it is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, this entry sets the Windows setting to 0 so it doesn't affect the one you set in SetPoint and then unloads. A separate instance of KHALMNPR.EXE loads via the main Setpoint.exe program to control communication between your radio/bluetooth wireless mouse/keyboard and SetPoint |
| X | KHATARNAK Loader | KHATARNAK.exe | Added by the AUTORUN.ACO WORM! |
| N | khooker | khooker.exe | SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required |
| X | Kiamat Sudah Dekat_16_04 | ISASS.exe | Added by the PAHATIA.B WORM! |
| U | KICKMON.EXE | KICKMON.EXE | KeepItClean - utility that deletes safe to remove files, cookies, browsing history, etc. This is the scheduler - if you don't schedule clean-ups it isn't required |
| U | Kies | KiesHelper.exe | Installed with the SAMSUNG Kies mobile device management software. Preloads part of Kies into memory to speed up the loading time of the main program and exits after running. Tested without a supported device on a system with more than 1GB of memory it took twice as long for Kies to start with this entry disabled |
| N | Kies TrayAgent | KiesTrayAgent.exe | SAMSUNG Kies mobile device management software which also allows you to view apps in full screen on your PC, no matter what network you're on. Allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Only required if you want to autostart Kies when your device is connected |
| U | KiesHelper | KiesHelper.exe | Installed with the SAMSUNG Kies mobile device management software. Preloads part of Kies into memory to speed up the loading time of the main program and exits after running. Tested without a supported device on a system with more than 1GB of memory it took twice as long for Kies to start with this entry disabled |
| N | KiesTrayAgent | KiesTrayAgent.exe | SAMSUNG Kies mobile device management software which also allows you to view apps in full screen on your PC, no matter what network you're on. Allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Only required if you want to autostart Kies when your device is connected |
| U | Kill Popup | KillPopup.exe | KillPopup - pop-up stopper |
| X | KillAndClean | KillAndClean.exe | KillAndClean rogue spyware remover - not recommended, removal instructions here |
| X | kimochiz.exe | kimochiz.exe | Added by the MDROP-BB TROJAN! |
| N | Kinberlink | Kinberlink.exe | Kinberlink network messaging. Available via Start -> Programs |
| X | King_ar | arking.exe | Added by the PWS-BOS TROJAN! |
| X | king_hg | hgking.exe | Added by the AUTORUN-BMQ WORM! |
| X | king_jp | jpking.exe | Added by the AGENT-POO TROJAN! |
| X | King_ko | koking.exe | Added by the AUTORUN-BMU WORM! |
| X | king_mg | mgking.exe | Added by the AGENT-PGG TROJAN! |
| X | Kinofilmoff.Net | Reklamer.exe | Added by the AGENT-NGX TROJAN! |
| Y | kis | avp.exe | System Tray access to and notifications for Kaspersky Internet Security 6.0 from Kaspersky Lab. Runs together with a related service - AVP - which runs a separate instance of the same file. Also Steganos Internet Security 2007 - by Kaspersky and now discontinued. Found in either a Kaspersky or Steganos sub-directory |
| X | kiss | pingy.exe | Added by a variant of the IRCBOT BACKDOOR! The file is located in a random subfolder of %ProgramFiles% |