Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X jvms.exe jvms.exe"Added by the ORCU.B TROJAN!"
X JW Manager jwmngr.exe"Added by the DELBOT-G WORM!"
X jxef1104 jxef1104.exe"Added by the XIPI-A WORM!"
X JXL Radio jxl.exe"Added by the RBOT-EBE WORM!"
X jysyqm [random filename]"ZenoSearch adware"
? Jzi16 jzi16.exe"??"
X K2ps_full.task K2ps_full.exe"Added by the JUNTADOR.K TROJAN!"
N K6CPU.EXE K6CPU.EXEAuthenticates CPU as K6 in system properties
X Kadoc [random filename].exe"Added by the STAPREW TROJAN!"
U KADxMain KADxMain.exe"System Tray access to IntelliSonic Speech Enhancement - by Knowles Acoustics. Designed to render speech from a user selectable direction while canceling interfering speech from other directions thus minimizing the effects of environmental noise and eliminating acoustic echo feedback. Found on some Dell and Fujitsu Seimens laptops"
X kak kak.hta"Added by the KAKWORM WORM!"
U Kalender Kalender.exe"UK's Kalender ""helps you organizing your dates and tasks and reminds you of upcoming events"""
U Kalibump Kalibump.exe"Used with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy"
X kalvsys kalv****.exe [* = random char]"EliteBar adware"
X kalvsys kalv***32.exe [* = random char]"EliteBar adware"
N Kana Reminder Reminder.exe"Kana Reminder is a program which can be used to set a reminder to be triggered at a specified time"
U Karen's Once-A-Day II PTOAD.exe"""Have a job that should be run exactly once each day? Karen's Once-A-Day II is just what you need!"" Scheduler that lets you specify progams web pages and files that be run or opened automatically the first time"
U KASP OESpamTest.exe"Kaspersky Anti-Spam"
X Kasper Antivirus KASPERANTIVIRUS.EXE"Added by a variant of the SPYBOT WORM!"
Y Kaspersky Anti-Hacker KAVPF.exe"Kaspersky Anti-Hacker firewall"
X Kaspersky Antivirus KasperskyAV.exe"Added by a variant of the RBOT WORM!"
X kaspersky32 kasperskyLabs32.exe"Added by the RBOT-GOT WORM!"
X KasperskyAv kaspersky.exe"Added by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky anti-virus"
X KasperskyAVEng Kasperskyaveng.exe"Added by the NETSKY.V WORM!"
X KAT KAT.vbs"Added by the SOAD-D WORM!"
U KatMouse KatMouse.exe"KatMouse - utility to enhance the functionality of mice with a scroll wheel offering 'universal' scrolling etc"
Y kav avp.exe"Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
X kava kavo.exe"Added by the LINEAG-GLG TROJAN!"
X KAVFOX win1ogoin.exe"Added by the GWGHOST-M TROJAN!"
X kavir kavir.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
X KAVPersonal svchost.exe"Added by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
Y KAVPersonal50 Kav.exe"Kaspersky Anti-Virus Personal 5.0"
X KAVPersonal90 wscntfy.exe"Added by the BANKER-FZ TROJAN!"
Y KavPFW KavPFW.exe"KingSoft Personal Firewall"
X KavRuns Windll.exe"Added by the TRYNOMA TROJAN!"
Y KavStart KAVStart.exe"KingSoft Personal Firewall"
Y kavsvc kavsvc.exe"Kaspersky antivirus"
X KavSvc ******.exe reg_run [* = random char]"Added by the QOOLOGIC TROJAN!"
X kavsvc [random 6 char filename]"Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe rzazzi.exe ivpaan.exe)"
X KAVutil [worm filename]"Added by the WINTOO.B WORM!"
N KAZAA kazaa.exe"KAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it"
X Kazaa Download Accelerator Updater (required) regsvr32 kdp****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
X Kazaa lptt01 kazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
X Kazaa ml097e kazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
X KAZAACuf 9"Added by the KITRO.D (or ARGEN.A) WORM!"
N kazaalite kazaalite.exe"Kazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original this one does not contain any advertising or tracking mechanisms"
N KaZooM KaZooM.Exe"KaZoom from Blue Haven Media - ""add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches"""
X kb AUTO.txt"Added by the BRONTOK-CV WORM!"
Y KB891711 KB891711.exe"Installed by the Windows KB891711 critical update see this security bulletin - this file reportedly needs to continue running in order to patch the vulnerability at least until a more practical solution is found. There have however been reports of fatal exception errors in systems running Windows 98 and in such a case Microsoft advises to either uninstall the patch (Add/Remove Programs) or prevent it from running at startup"
Y KB918547 KB918547.EXE"Bug-fix for a Microsoft graphics rendering engine vulnerability - see here. Windows 98/Me only"
Y KB926239 rundll32.exe apphelp.dll ShimFlushCache"Microsoft KB926239 fix. Windows Media Player 10 may close unexpectedly on a Windows XP-based computer"
U KBD KBD.EXEMultimedia keyboard manager. Required if you use the multimedia keys
U KBD KbdStub.EXEKey Watcher from HP - watches for Multimedia Keys on HP keyboards
U KBD MediaCenter MEDIACTR.EXEMultimedia keyboard manager. Required if you use the multimedia keys
X kbddrv32 kbddrv32.exe"Added by the CRYPTER.A TROJAN!"
X kbddrvinf kbddrvinf.exe"Added by the CRYPTER.A TROJAN!"
N KCeasy KCeasy.exe"KCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella"
U KClient kstatus.exeKClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet
X kdmsx [8 random letters].exe"Detected by Kaspersky as the SDBOT.AIJ BACKDOOR! See here"
N kdx KHost.exe"Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops"
U KE9801 DriBat32.exeKE9801 multimedia keyboard driver - required if you use the multimedia keys
X Keenvalue Keenvalue.exe"KeenVal adware"
U KEMailKb KEMailKb.EXE"Controls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down"
? Kemet kemet.exe"??"
U KeNotify KeNotify.exeToshiba utility found on their laptops. This program is responsible for the Toshiba LapTop Help 'FlashCards' utility that sits at the top of the screen giving easy access to the 'F keys' alternative functions such as LockPower ModeSleep etc
X kERe kERe.exe"Added by the BRONTOK-BT WORM!"
U Kerio VPN Client kvpnclient.exe"Kerio VPN Client"
X kern64dll [random filename]"Added by the TARNO.J TROJAN!"
X Kernal Fault Check ntosrkl.exe"Added by a variant of the SDBOT WORM!"
X kernctl32 rundll32 kctl32.dll initializeAdded by the AGENT.AT TROJAN!
X Kerne0223 Kerne0223.exe"Added by the LEGMIR-ZA TROJAN!"
X Kernel bboy.exe"Added by the MUMU.B WORM!"
X Kernel services.exe"Added by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder"
X kernel kernel.exe"Added by the MATCASH.CF TROJAN!"
X KERNEL 32 SKERNEL32.com"Added by the SEMAPI-A WORM"
U Kernel and Hardware Abstraction Layer KHALMNPR.EXEPart of the Logitech Setpoint software for their wired and wireless mice and trackballs. Sets the Windows mouse sensitivity to minimum. The idea is that you will use the SetPoint Control Panel to adjust your mouse sensitivity. This setting is maintained separately from the Windows setting but is combined with the Windows setting to determine the final sensitivity. For this reason KHALMNPR sets the Windows setting to 0 so it doesn't alter the one you set in SetPoint
X Kernel Faults ftphost.exe"Added by the RBOT.BHU WORM!"
X Kernel Loader ntkrnl.exe"Added by the CERVIVEC.A WORM!"
X Kernel Manager krnlmgr.exe"Added by the JUNY.A TROJAN!"
X Kernel Safe Mode smss.exe"Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X Kernel Services service32.exe"Added by the PRX-B TROJAN!"
X kernel system daemon ACTIVAT0R.exe"Added by the RANDEX.AW WORM!"
X kernel12.exe kernel12.exeAdded by an unidentified WORM or TROJAN!
X kernel32 kern32.exe"Added by the BADTRANS.A WORM!"
X Kernel32 Kernel32.exeAdded by a number of VIRUSES WORMS and TROJANS!
X kernel32 kernel.dli"Added by the NETDEVIL.B TROJAN!"
X Kernel32 Kernel.dll"Added by the REDLOF.M VIRUS!"
X kernel32 kernel32.dlI"Added by the NETDEVIL.15 TROJAN!"
X Kernel32 krnl32.exe"Added by the EPON WORM!"
X Kernel32 Kernel32.win"Added by the GAGGLE.D or GAGGLE.E WORMS!"
X Kernel32 kernel32s.exe"Added by the BCKDR-CIC BACKDOOR!"
X kernel32 kernel32.dll.vbs"Added by the WEKODE-A WORM!"
X Kernel32 svchosts.exeAdded by an unidentified WORM or TROJAN!
X kernel32dll guardpc.exe"Added by the FORBOT-CU WORM!"
X kernel44.dll "taskkill /f /fi ""PID ge 0"" /im *""Added by the VBS.LIDO WORM!"
X KernelCheck sys****.exe [* = digit]Added by an unidentified TROJAN!
X KernelCheck winser.exe"Added by the TSPY_LMIR.SL TROJAN!"
X KernelConfig destiny32.exe"Added by the AGOBOT.AMB WORM!"
N kernelfaultcheck dumprep 0 -kUsed in connection with memory dumps - you can disable these by - right clicking on My Computer selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
N kernelfaultcheck dumprep 0 -uUsed in connection with memory dumps - you can disable these by - right clicking on My Computer selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
X KernelFaultCheck ptool32.exe"Added by the LEGMIR-BN TROJAN!"
X KernelFaultChk sms.exe"Added by the DEADHAT WORM! Do not confuse with the valid ""kernelfaultcheck"" which runs ""dumprep 0 -k"" or ""dumprep 0 -u"""
X Kernell systems.exe"Added by the TARNO.C TROJAN!"
X Kernell32 Kernell.dll"Added by the DESTINY.A TROJAN!"
X KernellApps csrss.exe"Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""System"" subfolder"
X KernellApps lexplore.exe"Added by the BANCBAN-BS TROJAN! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
X KernellApps32 smss.exe"Added by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X KernelRuntime [path to worm]"Added by the MYTOB-JO WORM!"
X Kernelw Kernelw32.exe"Added by the INDOR.E WORM!"
X Kernel_check wmiprvse.exe"Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the System32wbem folder and should not normally figure in Msconfig/Startup!"
X key sysxp.exe"Added by the BEAGLE.AB WORM!"
X key sys_xp.exe"Added by the BEAGLE.AC WORM!"
X key winxp.exe"Added by the BEAGLE.AG WORM!"
X Key Logger csrss.exe"Added by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie C:\)"
N Key Text KeyText.exe"Key Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs"
X Key1 Rlid.exe"Added by the LIXY TROJAN!"
? Key2 serve.exe"??"
X key2 winlog.exe"Added by the BAGLEDI-AL TROJAN!"
Y KeyAccess keyacc32.exe"KeyServer KeyAccess client software - ""when the KeyServer program is launched the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess a keyed program cannot run so license control is very secure"""
X Keybdcntl keybdcntl.exe"Added by a variant of the CRYPTER.C TROJAN!"
U KeyBoard Keyboard.exe"Labtec keyboard utility"
X keyboard keyboard*.exe [* = number]"Detected by Kaspersky as the VB.ZG TROJAN!"
X keyboard kybrdef_7.exe"DollarRevenue adware"
X keyboard [path to trojan]"Added by the DLOADR-AOZ TROJAN!"
U Keyboard Manager MMKeybd.exeMultimedia keyboard manager. Required if you use the additional keys
Y Keyboard Preload Check Preload.exeMillenium Multi-Function Keyboard driver
X keyboard_enum keyboard_enum.exe"Added by the BDOOR-GP BACKDOOR!"
U KeyMaestro kmaestro.exeMultimedia keyboard manager. Required if you use the multimedia keys
U keymap keymap.exeSystem Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game
X keymgrldr rundll32 setupapi InstallHinfSection... keymgr3.inf"CoolWebSearch Oemsyspnp parasite variant"
U KeyPatrol KeyPatrol.exe"KeyPatrol - key logger detector using both behavioral and pattern-matching algorithms that used to be part of PestPatrol before CA's aquisition"
X keyserv keyserv.exe"KeyThief spyware"
U Keyspan Digital Media Remote KDMRdmn.exe"Remote control driver for Keyspan Digital Media Remote devices"
U keystroke keystroke.exe"QuickLaunch surveillance software. Uninstall this software unless you put it there yourself"
U KeyWallet KWallet.exe""KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins passwords and other personal data manually""
X kfienq masbl.bat"Added by the KIFER TROJAN!"
X Kgjg rnnypbw.exe"Added by the QuickLinks/Forethought adware"
X KHATARNAK Loader KHATARNAK.exe"Added by the AUTORUN.ACO WORM!"
N khooker khooker.exeSiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
X Kiamat Sudah Dekat_16_04 ISASS.exe"Added by the PAHATIA.B WORM!"
U KICKMON.EXE KICKMON.EXEKeepItClean - utility that deletes safe to remove files cookies browsing history etc. This is the scheduler - if you don't schedule clean-ups it isn't required
U Kill Popup KillPopup.exe"KillPopup - pop-up stopper"
X KillAndClean KillAndClean.exe"KillAndClean spyware remover - not recommended see here"
X kimochiz.exe kimochiz.exe"Added by the MDROP-BB TROJAN!"
N Kinberlink Kinberlink.exe"Kinberlink network messaging. Available via Start -> Programs"
X kiss pingy.exe"Added by a variant of the IRCBOT BACKDOOR! The file is located in a random subfolder of %ProgramFiles%"
X KIT3 hpprintqueue.exe"Added by the ADCLICK-DS TROJAN!"
U KK Loader loadkk.exe"KeyKey XP Professional from KeyKey.com. "Monitor Instant Messages Chats Emails Web Site URLs Passwords Computer Programs Start Up and Shut Down time and much more completely undetected to the user.""
X KKM Service kkm.exe"Added by the NANPY-I WORM!"
X KL AntiFunLove flcss.exe"Added by the FUNLOVE.4099 VIRUS!"
U KLog Keyspy.exe"KeyLoggPro.B keystroke logger/monitoring program - remove unless you installed it yourself!"
X klop [path to file]"Added by the AGENT-WQ TROJAN!"
X klop [random].tmp"Found with Trojan.Win32.StartPage.aw. Possibly a variant of the AGENT-WQ TROJAN!"
U klp run32dll.exe"PAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online"
U klp explorer.exe"ComSurveilSys keystroke logger/monitoring program - remove unless you installed it yourself!"
U KM9801U MMHotKey.exeMultimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
U kmw_run.exe kmw_run.exeKensington MouseWorks - mouse/trackball software. Not required unles you use any special features
U kmw_show.exe kmw_show.exeKensington MouseWorks - mouse/trackball software. Not required unles you use any special features
X KnowledgeBase GUI wppewafaj.exe"Added by the RBOT-GRZ WORM!"
U KN_PanelApp PanelApp.exe"KnowledgePanel online survey software"
N Kodak Batch Transfer pezdow1.exePart of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC
U Kodak EasyShare software EasyShare.exeSoftware bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually
N Kodak Picture Easy *.* Batch Transfer PezDownload.exe"Part of ""Kodak Picture Easy"" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the version"
N Kodak Picture Transfer Software pts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
N Kodak Software Updater backweb*****.exe"Software updater for Kodak Easyshare digital cameras"
N KODAK Software Updater Kodak Software Updater.exe"Software updater for Kodak Easyshare digital cameras"
Y KodakCCS KodakCCS.exeKodak DC File System Driver
U Komunikator tlen.exe"Tlen - a Polish language instant messaging client"
U KONICA MINOLTA magicolor 2400W STD MSTMON_S.EXEKonica Minolta Magicolor 2400W colour printer monitor
N Konni Symbol Autostart KonniSymbol.exe"Gives configuration access to RagTime Solo professional business publishing software. RagTime Solo is the private user version of RagTime 5"
N kontiki kontiki.exe"Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops"
Y KPDrv4XP KPDrv4XP.exeMediaKey USB Keypad Driver
Y KPFW32.EXE KPFW32.EXE"KingSoft Personal Firewall"
Y KPFWSvc.EXE KPFWSvc.EXE"KingSoft Personal Firewall"
X Kr0n1C Kr0n1C.exe"Added by the BRONTOK-BO WORM!"
X krag krag.exe"Added by the AGENT-FOW WORM!"
U Kraidman Kraidman.exe"""Toshiba RAID Support is a Toshiba EasyGuard feature that uses RAID Level 1 technology to minimise downtime by protecting against data loss and ensuring quick data recovery"" - for Toshiba laptops"
Y Krait razerhid.exe"Razer Krait mouse driver"
U KREC32 krec32.exeStarrCommander Pro Keystroke logging software
X KRNL Kernl32.exe"Added by the ZOMBY.B TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list