Arcade File Downloads UsenetGeeks
Email
Confirm email
Articles Spyware Removal File Help Startup DB Tips Service DB News Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X jutsu jutsu.exe"Added by the RBOT-LS WORM!"
U jv16 PT TempFileTool TempTool.exe"jv16 PowerTools' temporary file remover"
U jv16PT - Privacy Protector Task.jvb"jv16 PowerTools 2005 - Privacy Protector allows you to protect your privacy by clearing the unwanted history items and cookies from you computer every time you startup your computer"
U Jv16pt Network Resident jv16pt_network.exe"jv16 PowerTools' network resident program. Only needed if you are using the program's network features"
X jvdnlssn fljzsshc.exeFlingstone.com adware - and its Golden Palace Casino program
X JVM0.12 [random filename]"Added by the TEADOOR-A TROJAN!"
X JVM0.14 [random filename]"Added by the TEADOOR-B TROJAN!"
X jxef1104 jxef1104.exe"Added by the XIPI-A WORM!"
? Jzi16 jzi16.exe"??"
X K2ps_full.task K2ps_full.exe"Added by the JUNTADOR.K TROJAN!"
N K6CPU.EXE K6CPU.EXEAuthenticates CPU as K6 in system properties
X Kadoc [random filename].exe"Added by the STAPREW TROJAN!"
X kak kak.hta"Added by the KAKWORM WORM!"
U Kalibump Kalibump.exe"Used with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy"
X kalvsys kalv****.exe [* = random char]"EliteBar adware"
X kalvsys kalv***32.exe [* = random char]"EliteBar adware"
N Kana Reminder Reminder.exe"Kana Reminder is a program which can be used to set a reminder to be triggered at a specified time"
U Karen's Once-A-Day II PTOAD.exe"""Have a job that should be run exactly once each day? Karen's Once-A-Day II is just what you need!"" Scheduler that lets you specify progams
U KASP OESpamTest.exe"Kaspersky Anti-Spam"
X Kasper Antivirus KASPERANTIVIRUS.EXE"Added by a variant of the SPYBOT WORM!"
Y Kaspersky Anti-Hacker KAVPF.exe"Kaspersky Anti-Hacker firewall"
X Kaspersky Antivirus KasperskyAV.exe"Added by a variant of the RBOT WORM!"
X KasperskyAv kaspersky.exe"Added by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky AntiVirus"
X KasperskyAVEng Kasperskyaveng.exe"Added by the NETSKY.V WORM!"
X KAVFOX win1ogoin.exe"Added by GWGHOST-M TROJAN!"
X KAVPersonal svchost.exe"Added by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
Y KAVPersonal50 Kav.exe"Kaspersky Anti-Virus Personal 5.0"
X KAVPersonal90 wscntfy.exe"Added by the BANKER-FZ TROJAN!"
Y KavPFW KavPFW.exe"KingSoft Personal Firewall"
X KavRuns Windll.exe"Added by the TRYNOMA TROJAN!"
Y KavStart KAVStart.exe"KingSoft Personal Firewall"
Y kavsvc kavsvc.exe"Kaspersky antivirus"
X kavsvc [random 6 char filename]"Qoologic downloader trojan variant using random file names (examples: nzkklz.exe
X KavSvc ******.exe reg_run [* = random char]"Added by the QOOLOGIC TROJAN!"
X kavsvc [random 6 char filename]"Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe
X KAVutil [worm filename]"Added by the WINTOO.B WORM!"
N KAZAA kazaa.exe"KAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it"
X Kazaa Download Accelerator Updater (required) regsvr32 [path] kdp****.dll [* = random char]"SafeguardProtect/Veevo hijacker"
X Kazaa lptt01 kazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
X Kazaa ml097e kazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
X KAZAACuf 9"Added by the KITRO.D (or ARGEN.A) WORM!"
N kazaalite kazaalite.exe"Kazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original
N KaZooM KaZooM.Exe"KaZoom from Blue Haven Media - ""add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches"""
Y KB891711 KB891711.exe"Installed by the Windows KB891711 critical update
Y KB918547 KB918547.EXE"Bug-fix for a Microsoft graphics rendering engine vulnerability - see here. Windows 98/Me only"
U KBD KBD.EXEMultimedia keyboard manager. Required if you use the multimedia keys
U KBD MediaCenter MEDIACTR.EXEMultimedia keyboard manager. Required if you use the multimedia keys
X kbddrv32 kbddrv32.exe"Added by the CRYPTER.A TROJAN!"
X kbddrvinf kbddrvinf.exe"Added by the CRYPTER.A TROJAN!"
N KCeasy KCeasy.exe"KCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella"
U KClient kstatus.exeKClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet
N kdx KHost.exe"KonTiki Secure Delivery Plug In related. ""The Kontiki Delivery Management System (DMS) is a secure delivery network for distribution of video
U KE9801 DriBat32.exe"KE-9801 multimedia keyboard - required if you use the multimedia keys"
X Keenvalue Keenvalue.exe"eUniverse/KeenValue adware"
U KEMailKb KEMailKb.EXE"Controls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down"
? Kemet kemet.exe"??"
U Kerio VPN Client kvpnclient.exe"Kerio VPN Client"
X kern64dll [random filename]"Added by the TARNO.J TROJAN!"
X Kernal Fault Check ntosrkl.exe"Added by a variant of the SDBOT WORM!"
X kernctl32 "rundll32 kctl32.dll initialize"
X Kerne0223 Kerne0223.exe"Added by the LEGMIR-ZA TROJAN!"
X Kernel bboy.exe"Added by the MUMU.B WORM!"
X Kernel services.exe"Added by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder"
X KERNEL 32 SKERNEL32.com"Added by the SEMAPI-A WORM"
X Kernel Faults ftphost.exe"Added by the RBOT.BHU WORM!"
X Kernel Loader ntkrnl.exe"Added by the CERVIVEC.A WORM!"
X Kernel Manager krnlmgr.exe"Added by the JUNY.A TROJAN!"
X Kernel Services service32.exe"Added by the PRX-B TROJAN!"
X kernel system daemon ACTIVAT0R.exe"Added by the RANDEX.AW WORM!"
X kernel12.exe kernel12.exeAdded by an unidentified WORM or TROJAN!
X kernel32 kern32.exe"Added by the BADTRANS.A WORM!"
X Kernel32 Kernel32.exe"Added by a number of VIRUSES
X kernel32 kernel.dli"Added by the NETDEVIL.B TROJAN!"
X Kernel32 Kernel.dll"Added by the REDLOF.M VIRUS!"
X kernel32 kernel32.dlI"Added by the NETDEVIL.15 TROJAN!"
X Kernel32 krnl32.exe"Added by the EPON WORM!"
X Kernel32 Kernel32.win"Added by the GAGGLE.D or GAGGLE.E WORMS!"
X Kernel32 kernel32s.exe"Added by the SDBOT-PU TROJAN!"
X kernel32 kernel32.exe"Added by the CHODE-I WORM!"
X kernel32dll guardpc.exe"Added by the FORBOT-CU WORM!"
X KernelCheck sys****.exe [* = digit]Added by an unidentified TROJAN!
N kernelfaultcheck dumprep 0 -k"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
N kernelfaultcheck dumprep 0 -u"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
X KernelFaultCheck ptool32.exe"Added by the LEGMIR-BN TROJAN!"
X KernelFaultChk sms.exe"Added by the DEADHAT WORM! Do not confuse with the valid ""kernelfaultcheck"" which runs ""dumprep 0 -k"" or ""dumprep 0 -u"""
X Kernell systems.exe"Added by the TARNO.C TROJAN!"
X Kernell32 Kernell.dll"Added by the DESTINY.A TROJAN!"
X KernellApps csrss.exe"Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process
X KernellApps lexplore.exe"Added by the BANCBAN-BS TROJAN!"
X KernellApps32 smss.exe"Added by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X Kernelw Kernelw32.exe"Added by the INDOR.E WORM!"
X Kernel_check wmiprvse.exe"Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the System32wbem folder and should not normally figure in Msconfig/Startup!"
X key sysxp.exe"Added by the BEAGLE.AB WORM!"
X key sys_xp.exe"Added by the BEAGLE.AC WORM!"
X key winxp.exe"Added by the BEAGLE.AG WORM!"
X Key Logger csrss.exe"Added by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the root folder - normally C:"
N Key Text KeyText.exe"Key Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs"
X Key1 Rlid.exe"Added by the LIXY TROJAN!"
? Key2 serve.exe"??"
X key2 winlog.exe"Added by the BAGLEDI-AL TROJAN!"
Y KeyAccess keyacc32.exe"KeyServer KeyAccess client software - ""when the KeyServer program is launched
X Keybdcntl keybdcntl.exe"Added by a variant of the CRYPTER.C TROJAN!"
U KeyBoard Keyboard.exe"keyboard keyboard*.exe [* = number]"Recognized by Kaspersky antivirus as TrojanDownloader.VB.zg"
X keyboard kybrdef_7.exe"DollarRevenue adware"
U Keyboard Manager MMKeybd.exeMultimedia keyboard manager. Required if you use the additional keys
Y Keyboard Preload Check Preload.exeMillenium Multi-Function Keyboard driver
X keyboard_enum keyboard_enum.exe"Added by the GP TROJAN!"
U KeyMaestro kmaestro.exeMultimedia keyboard manager. Required if you use the multimedia keys
U keymap keymap.exeSystem Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game
X keymgrldr "rundll32 setupapi InstallHinfSection... keymgr3.inf"
U KeyPatrol KeyPatrol.exe"KeyPatrol - detects Key Loggers (""keyboard loggers"" or ""keyloggers"") using both behavioral and pattern-matching algorithms"
X keyserv keyserv.exe"KeyThief spyware"
U Keyspan Digital Media Remote KDMRdmn.exe"Remote control driver for Keyspan Digital Media Remote devices"
U keystroke keystroke.exe"QuickLaunch is a surveillance software program that logs keystrokes and captures screenshots. If you didn't install this yourself remove it"
U KeyWallet KWallet.exe""KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins
X kfienq masbl.bat"Added by the KIFER TROJAN!"
N khooker khooker.exeSiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
U KICKMON.EXE KICKMON.EXE"KeepItClean - utility that deletes safe to remove files
U Kill Popup KillPopup.exe"KillPopup - pop-up stopper"
N KillAndClean KillAndClean.exe"Spyware remover - not recommended
X kimochiz.exe kimochiz.exe"Added by the MDROP-BB TROJAN!"
N Kinberlink Kinberlink.exe"Kinberlink network messaging. Available via Start -> Programs"
U KK Loader loadkk.exe"KeyKey XP Professional from KeyKey.com. "Monitor Instant Messages
X KKM Service kkm.exe"Added by the NANPY-I WORM!"
X KL AntiFunLove flcss.exe"Added by the FUNLOVE.4099 WORM!"
U KLog Keyspy.exe"KeyLoggPro.B keystroke logger/monitoring program - remove unless you installed it yourself!"
X klop [path to file]"Added by the AGENT-WQ TROJAN!"
X klop [random].tmp"Found with Trojan.Win32.StartPage.aw. Possibly a variant of the AGENT-WQ TROJAN!"
U klp run32dll.exe"PAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online"
U klp explorer.exe"ComSurveilSys keystroke logger/monitoring program - remove unless you installed it yourself! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is found in a SystemPALCSS subfolder"
U KM9801U MMHotKey.exeMultimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
U kmw_run.exe kmw_run.exeKensington MouseWorks - mouse/trackball software. Not required unles you use any special features

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list