PC Review
Startup Files Database
Letter k
Powered By Pac's Startup list
Startup Files Database
Letter k
Startup Files Database
[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z]
Yes |
No |
Users Choice |
Warning |
Unknown |
| Normally leave to run at startup | Not Required, often infrequently run tasks that can be run manually. | Depends if the task is deemed necessary | Typically viruses, spyware, adware and resource hogs | An unknown item |
| Required | Process Name / Details | Startup File |
![]() |
Added by the JUNTADOR.K TROJAN! |
K2ps_full.exe |
![]() |
Authenticates CPU as K6 in system properties |
K6CPU.EXE |
![]() |
Added by the STAPREW TROJAN! |
[random filename].exe |
![]() |
Added by the KAKWORM WORM! |
kak.hta |
![]() |
Used with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy |
Kalibump.exe |
![]() |
EliteBar adware |
kalv****.exe [* = random char] |
![]() |
EliteBar adware |
kalv***32.exe [* = random char] |
![]() |
Kana Reminder is a program which can be used to set a reminder to be triggered at a specified time |
Reminder.exe |
![]() |
Have a job that should be run exactly once each day? Karen's Once-A-Day II is just what you need! Scheduler that lets you specify progams, web pages and files that be run or opened automatically, the first time |
PTOAD.exe |
![]() |
Kaspersky Anti-Spam |
OESpamTest.exe |
![]() |
Added by a variant of the SPYBOT WORM! |
KASPERANTIVIRUS.EXE |
![]() |
Kaspersky Anti-Hacker firewall |
KAVPF.exe |
![]() |
Added by a variant of the RBOT WORM! |
KasperskyAV.exe |
![]() |
Added by the RBOT-GOT WORM! |
kasperskyLabs32.exe |
![]() |
Added by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky AntiVirus |
kaspersky.exe |
![]() |
Added by the NETSKY.V WORM! |
Kasperskyaveng.exe |
![]() |
Added by the SOAD-D WORM! |
KAT.vbs |
![]() |
AOL's Active Virus Shield |
avp.exe |
![]() |
Added by the LINEAG-GLG TROJAN! |
kavo.exe |
![]() |
Added by GWGHOST-M TROJAN! |
win1ogoin.exe |
![]() |
Added by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
svchost.exe |
![]() |
Kaspersky Anti-Virus Personal 5.0 |
Kav.exe |
![]() |
Added by the BANKER-FZ TROJAN! |
wscntfy.exe |
![]() |
KingSoft Personal Firewall |
KavPFW.exe |
![]() |
Added by the TRYNOMA TROJAN! |
Windll.exe |
![]() |
KingSoft Personal Firewall |
KAVStart.exe |
![]() |
Kaspersky antivirus |
kavsvc.exe |
![]() |
Qoologic downloader trojan variant using random file names (examples: nzkklz.exe, rzazzi.exe, ivpaan.exe) - do not confuse with the Kaspersky antivirus startup item, as described here |
[random 6 char filename] |
![]() |
Added by the QOOLOGIC TROJAN! |
******.exe reg_run [* = random char] |
![]() |
Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe, rzazzi.exe, ivpaan.exe) |
[random 6 char filename] |
![]() |
Added by the WINTOO.B WORM! |
[worm filename] |
![]() |
KAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it |
kazaa.exe |
![]() |
SafeguardProtect/Veevo hijacker |
regsvr32 [path] kdp****.dll [* = random char] |
![]() |
RapidBlaster variant (in a "kazaa" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name |
kazaa.exe |
![]() |
RapidBlaster variant (in a "kazaa" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name |
kazaa.exe |
![]() |
Added by the KITRO.D (or ARGEN.A) WORM! |
9 |
![]() |
Kazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original, this one does not contain any advertising or tracking mechanisms |
kazaalite.exe |
![]() |
KaZoom from Blue Haven Media - "add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches" |
KaZooM.Exe |
![]() |
Installed by the Windows KB891711 critical update, see this security bulletin - this file reportedly needs to continue running in order to patch the vulnerability, at least until a more practical solution is found. There have however been reports of fatal exception errors in systems running Windows 98, and in such a case Microsoft advises to either uninstall the patch (Add/Remove Programs) or prevent it from running at startup |
KB891711.exe |
![]() |
Bug-fix for a Microsoft graphics rendering engine vulnerability - see here. Windows 98/Me only |
KB918547.EXE |
![]() |
Microsoft KB926239 fix. Windows Media Player 10 may close unexpectedly on a Windows XP-based computer |
rundll32.exe [path] apphelp.dll, ShimFlushCache |
![]() |
Multimedia keyboard manager. Required if you use the multimedia keys |
KBD.EXE |
![]() |
Multimedia keyboard manager. Required if you use the multimedia keys |
MEDIACTR.EXE |
![]() |
Added by the CRYPTER.A TROJAN! |
kbddrv32.exe |
![]() |
Added by the CRYPTER.A TROJAN! |
kbddrvinf.exe |
![]() |
KCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella |
KCeasy.exe |
![]() |
KClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet |
kstatus.exe |
![]() |
Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops |
KHost.exe |
![]() |
KE9801 multimedia keyboard driver - required if you use the multimedia keys |
DriBat32.exe |
![]() |
eUniverse/KeenValue adware |
Keenvalue.exe |
![]() |
Controls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down |
KEMailKb.EXE |
![]() |
?? |
kemet.exe |
![]() |
Kerio VPN Client |
kvpnclient.exe |
![]() |
Added by the TARNO.J TROJAN! |
[random filename] |
![]() |
Added by a variant of the SDBOT WORM! |
ntosrkl.exe |
![]() |
Added by the AGENT.AT TROJAN! |
rundll32 kctl32.dll, initialize |
![]() |
Added by the LEGMIR-ZA TROJAN! |
Kerne0223.exe |
![]() |
Added by the MUMU.B WORM! |
bboy.exe |
![]() |
Added by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
services.exe |
![]() |
Added by the SEMAPI-A WORM |
SKERNEL32.com |
![]() |
Part of the Logitech Setpoint software for their wired and wireless mice and trackballs. Sets the Windows mouse sensitivity to minimum. The idea is that you will use the SetPoint Control Panel to adjust your mouse sensitivity. This setting is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, KHALMNPR sets the Windows setting to 0 so it doesn't alter the one you set in SetPoint |
KHALMNPR.EXE |
![]() |
Added by the RBOT.BHU WORM! |
ftphost.exe |
![]() |
Added by the CERVIVEC.A WORM! |
ntkrnl.exe |
![]() |
Added by the JUNY.A TROJAN! |
krnlmgr.exe |
![]() |
Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
smss.exe |
![]() |
Added by the PRX-B TROJAN! |
service32.exe |
![]() |
Added by the RANDEX.AW WORM! |
ACTIVAT0R.exe |
![]() |
Added by an unidentified WORM or TROJAN! |
kernel12.exe |
![]() |
Added by the BADTRANS.A WORM! |
kern32.exe |
![]() |
Added by a number of VIRUSES, WORMS and TROJANS! |
Kernel32.exe |
![]() |
Added by the NETDEVIL.B TROJAN! |
kernel.dli |
![]() |
Added by the REDLOF.M VIRUS! |
Kernel.dll |
![]() |
Added by the NETDEVIL.15 TROJAN! |
kernel32.dlI |
![]() |
Added by the EPON WORM! |
krnl32.exe |
![]() |
Added by the GAGGLE.D or GAGGLE.E WORMS! |
Kernel32.win |
![]() |
Added by the SDBOT-PU TROJAN! |
kernel32s.exe |
![]() |
Added by the WEKODE-A WORM! |
kernel32.dll.vbs |
![]() |
Added by an unidentified WORM or TROJAN! |
svchosts.exe |
![]() |
Added by the FORBOT-CU WORM! |
guardpc.exe |
![]() |
Added by the VBS.LIDO WORM! |
taskkill /f /fi "PID ge 0" /im * |
![]() |
Added by an unidentified TROJAN! |
sys****.exe [* = digit] |
![]() |
Added by the TSPY_LMIR.SL TROJAN! |
winser.exe |
![]() |
Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out |
dumprep 0 -k |
![]() |
Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out |
dumprep 0 -u |
![]() |
Added by the LEGMIR-BN TROJAN! |
ptool32.exe |
![]() |
Added by the DEADHAT WORM! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k" or "dumprep 0 -u" |
sms.exe |
![]() |
Added by the TARNO.C TROJAN! |
systems.exe |
![]() |
Added by the DESTINY.A TROJAN! |
Kernell.dll |
![]() |
Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
csrss.exe |
![]() |
Added by the BANCBAN-BS TROJAN! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer |
lexplore.exe |
![]() |
Added by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! |
smss.exe |
![]() |
Added by the MYTOB-JO WORM! |
[path to worm] |
![]() |
Added by the INDOR.E WORM! |
Kernelw32.exe |
![]() |
Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the System32wbem folder and should not normally figure in Msconfig/Startup! |
wmiprvse.exe |
![]() |
Added by the BEAGLE.AB WORM! |
sysxp.exe |
![]() |
Added by the BEAGLE.AC WORM! |
sys_xp.exe |
![]() |
Added by the BEAGLE.AG WORM! |
winxp.exe |
![]() |
Added by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the root folder - normally C: |
csrss.exe |
![]() |
Key Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs |
KeyText.exe |
![]() |
Added by the LIXY TROJAN! |
Rlid.exe |
![]() |
?? |
serve.exe |
![]() |
Added by the BAGLEDI-AL TROJAN! |
winlog.exe |
![]() |
KeyServer KeyAccess client software - "when the KeyServer program is launched, the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess, a keyed program cannot run, so license control is very secure" |
keyacc32.exe |
![]() |
Added by a variant of the CRYPTER.C TROJAN! |
keybdcntl.exe |
![]() |
Labtec keyboard utility |
Keyboard.exe |
![]() |
Detected by Kaspersky as the VB.ZG TROJAN! |
keyboard*.exe [* = number] |
![]() |
DollarRevenue adware |
kybrdef_7.exe |
![]() |
Added by the DLOADR-AOZ TROJAN! |
[path to trojan] |
![]() |
Multimedia keyboard manager. Required if you use the additional keys |
MMKeybd.exe |
![]() |
Millenium Multi-Function Keyboard driver |
Preload.exe |
![]() |
Added by the GP TROJAN! |
keyboard_enum.exe |
![]() |
Multimedia keyboard manager. Required if you use the multimedia keys |
kmaestro.exe |
![]() |
System Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game |
keymap.exe |
![]() |
CoolWebSearch Oemsyspnp parasite variant |
rundll32 setupapi, InstallHinfSection... keymgr3.inf |
![]() |
KeyPatrol - key logger detector using both behavioral and pattern-matching algorithms that used to be part of PestPatrol before CA's aquisition |
KeyPatrol.exe |
![]() |
KeyThief spyware |
keyserv.exe |
![]() |
Remote control driver for Keyspan Digital Media Remote devices |
KDMRdmn.exe |
![]() |
QuickLaunch surveillance software. Uninstall this software unless you put it there yourself |
keystroke.exe |
![]() |
KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins, passwords and other personal data manually |
KWallet.exe |
![]() |
Added by the KIFER TROJAN! |
masbl.bat |
![]() |
Added by the QuickLinks/Forethought adware |
rnnypbw.exe |
![]() |
SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required |
khooker.exe |
![]() |
KeepItClean - utility that deletes safe to remove files, cookies, browsing history, etc. This is the scheduler - if you don't schedule clean-ups it isn't required |
KICKMON.EXE |
![]() |
KillPopup - pop-up stopper |
KillPopup.exe |
![]() |
Spyware remover - not recommended, see here |
KillAndClean.exe |
![]() |
Added by the MDROP-BB TROJAN! |
kimochiz.exe |
![]() |
Kinberlink network messaging. Available via Start -> Programs |
Kinberlink.exe |
![]() |
Added by the ADCLICK-DS TROJAN! |
hpprintqueue.exe |
![]() |
KeyKey XP Professional from KeyKey.com. "Monitor Instant Messages, Chats, Emails, Web Site URLs, Passwords, Computer Programs, Start Up and Shut Down time and much more completely undetected to the user." |
loadkk.exe |
![]() |
Added by the NANPY-I WORM! |
kkm.exe |
![]() |
Added by the FUNLOVE.4099 WORM! |
flcss.exe |
![]() |
KeyLoggPro.B keystroke logger/monitoring program - remove unless you installed it yourself! |
Keyspy.exe |
![]() |
Added by the AGENT-WQ TROJAN! |
[path to file] |
![]() |
Found with Trojan.Win32.StartPage.aw. Possibly a variant of the AGENT-WQ TROJAN! |
[random].tmp |
![]() |
PAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online |
run32dll.exe |
![]() |
ComSurveilSys keystroke logger/monitoring program - remove unless you installed it yourself! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is found in a SystemPALCSS subfolder |
explorer.exe |
![]() |
Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen |
MMHotKey.exe |
![]() |
Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features |
kmw_run.exe |
![]() |
Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features |
kmw_show.exe |
![]() |
Added by the RBOT-GRZ WORM! |
wppewafaj.exe |
![]() |
KnowledgePanel online survey software |
PanelApp.exe |
![]() |
Part of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC |
pezdow1.exe |
![]() |
Software bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually |
EasyShare.exe |
![]() |
Part of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the version |
PezDownload.exe |
![]() |
Looks for Kodak camera connection and media insertion. Available via Start -> Programs |
pts.exe |
![]() |
Software updater for Kodak Easyshare digital cameras |
backweb*****.exe |
![]() |
Software updater for Kodak Easyshare digital cameras |
Kodak Software Updater.exe |
![]() |
Kodak DC File System Driver |
KodakCCS.exe |
![]() |
Tlen - a Polish language instant messaging client |
tlen.exe |
![]() |
Konica Minolta Magicolor 2400W colour printer monitor |
MSTMON_S.EXE |
![]() |
Gives configuration access to RagTime Solo professional business publishing software. RagTime Solo is the private user version of RagTime 5 |
KonniSymbol.exe |
![]() |
Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops |
kontiki.exe |
![]() |
MediaKey USB Keypad Driver |
KPDrv4XP.exe |
![]() |
KingSoft Personal Firewall |
KPFW32.EXE |
![]() |
KingSoft Personal Firewall |
KPFWSvc.EXE |
![]() |
Added by the AGENT-FOW WORM! |
krag.exe |
![]() |
Toshiba RAID Support is a Toshiba EasyGuard feature that uses RAID Level 1 technology to minimise downtime by protecting against data loss and ensuring quick data recovery - for Toshiba laptops |
Kraidman.exe |
![]() |
StarrCommander Pro Keystroke logging software |
krec32.exe |
![]() |
Added by the ZOMBY.B TROJAN! |
Kernl32.exe |
![]() |
Added by the BOTNACHALA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
csrss.exe |
![]() |
Keystroke logger/monitoring program - remove unless you installed it yourself! |
Krnlmod.exe |
![]() |
Kryptel encryption software |
Kicker.exe |
![]() |
Added by the DLOADER-LI TROJAN! |
zxatgso.exe |
![]() |
Added by the AGOBOT-PI WORM! |
Ksrv32.exe |
![]() |
Added by the SDBOT-MZ WORM! |
ktax.exe |
![]() |
HP program found with the Office Jet 500/600/700 series which initializes the Office Jet manager each time the computer is booted up or rebooted |
ktchnsnk.exe |
![]() |
Related to KTP Ware TSR Enhancements from ELANTECH |
ktp.exe |
![]() |
Added by the IW TROJAN! |
word.EXE |
![]() |
Added by the ZSYANG.B WORM! |
lover.vbe |
![]() |
DailyWinner adware |
regsvr32.exe [path] kvern16.dll |
![]() |
Added by the PWS-ANM TROJAN! |
Kvsc3.exe |
![]() |
Added by the LEGMIR-BB TROJAN! |
cxjx.exe |
![]() |
LZIO.com adware downloader |
rundll32.exe [path] kw3eef76.dll, EnableRunDLL32 |
![]() |
Provides Mixer and Control functionality to KxProject Audio driver for EMU10k based soundcards |
kxmixer.exe |
![]() |
Kerberos Secure Authentication for Windows |
kx509_kfwk5.exe |
![]() |
Card reader for memory cards from digital cameras. Is it required? |
shwicon.exe |
![]() |
Added by a variant of the RBOT WORM! |
KYSVCXD.EXE |
![]() |
Added by the RBOT.BQD WORM! |
phqghum.exe |

Main Page 



