| N | j2 Tray Menu | HotTray.exe | eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here |
| U | Jammer | jammer.exe | Jammer by Agnitum - "Jammer is the last word in Internet security. It combines a user-friendly interface with very sophisticated and powerful security measures that protect your Windows system while you are surfing the web" |
| X | Jammer2nd | Jammer2nd.exe | Added by the NETSKY.Z WORM! |
| X | Java Runtimes | iexplore.exe | Added by the KILLAV.B TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
| X | JavaScript Debugging Service | JsDbgMan.exe | Added by the DERDEO.E WORM! |
| X | JavaUpdate0.07 | [filename] | Added by the JUPDATE TROJAN! |
| X | JavaVM | java.exe | Added by the MYDOOM.M or MYDOOM.N or other variants of the MYDOOM WORMS! Note - not to be confused with the valid Windows "java.exe" which resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) as this resides in C:Windows or C:Winnt |
| X | jawa32 | jawa32.exe | Added by the AGENT.BG WORM! |
| X | Jawa322 | jawa32.exe | Added by a variant of the AGENT.BG trojan |
| N | JB | Jiffybar.exe | "Get Paid As You surf" application |
| N | Jet Detection | ADGJDet.exe | Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection |
| Y | JetAdmin Discovery Indicator | HPJETDSC.EXE | HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry, and remains active to control the Discovery Indicator |
| X | jijbl | ezlwy.bat | Added by the REDDW WORM! |
| U | JobHisInit | JobHisInit.exe | Used by Ricoh network printers to enable network printing from the client |
| U | Jog Serve | JogServ2.exe | "Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features |
| U | JogServ2 | JogServ2.exe | "Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features |
| ? | jotl | millenzje.exe | ?? |
| X | Jreg | Jreg2b.exe | BroadcastPC adware variant |
| N | jusched | jusched.exe | Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel |
| X | jushed32.exe | jushed32.exe | CoolWebSearch parasite variant |
| X | jutsu | jutsu.exe | Added by the RBOT-LS WORM! |
| U | jv16 PT TempFileTool | TempTool.exe | jv16 PowerTools' temporary file remover |
| U | Jv16pt Network Resident | jv16pt_network.exe | jv16 PowerTools' network resident program. Only needed if you are using the program's network features |
| X | jvdnlssn | fljzsshc.exe | Flingstone.com adware - and its Golden Palace Casino program |
| ? | Jzi16 | jzi16.exe | ?? |
| X | K2ps_full.task | K2ps_full.exe | Added by the JUNTADOR.K TROJAN! |
| N | K6CPU.EXE | K6CPU.EXE | Authenticates CPU as K6 in system properties |
| X | Kadoc | [random filename].exe | Added by the STAPREW TROJAN! |
| X | kak | kak.hta | Added by the KAKWORM WORM! |
| U | Kalibump | Kalibump.exe | Used with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy |
| X | kalvsys | kalv****.exe [* = random char] | EliteBar/SearchMiracle adware installer |
| X | kalvsys | kalv***32.exe [* = random char] | EliteBar/SearchMiracle adware installer |
| N | Kana Reminder | Reminder.exe | Kana Reminder is a program which can be used to set a reminder to be triggered at a specified time |
| X | Kasper Antivirus | KASPERANTIVIRUS.EXE | Added by the SPYBOTER.GEN TROJAN! |
| X | Kaspersky Antivirus | KasperskyAV.exe | Added by a variant of the RBOT WORM! |
| X | KasperskyAv | kaspersky.exe | Added by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky AntiVirus |
| X | KasperskyAVEng | Kasperskyaveng.exe | Added by the NETSKY.V WORM! |
| Y | KAVPersonal50 | Kav.exe | Kaspersky Anti-Virus Personal 5.0 |
| X | KavRuns | Windll.exe | Added by the TRYNOMA TROJAN! |
| X | KAVutil | [worm filename] | Added by the WINTOO.B WORM! |
| N | KAZAA | kazaa.exe | KAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it |
| X | Kazaa Download Accelerator Updater (required) | regsvr32 [path] kdp****.dll [* = random char] | SafeguardProtect/Veevo hijacker |
| X | Kazaa lptt01 | kazaa.exe | Variant of the RapidBlaster parasite (in a "kazaa" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name |
| X | Kazaa ml097e | kazaa.exe | Variant of the RapidBlaster parasite (in a "kazaa" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name |
| X | KAZAACuf | 9 | Added by the KITRO.D (or ARGEN.A) WORM! |
| N | kazaalite | kazaalite.exe | Kazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original, this one does not contain any advertising or tracking mechanisms |
| N | KaZooM | KaZooM.Exe | KaZoom from Blue Haven Media - "add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches" |
| U | KBD | KBD.EXE | Multimedia keyboard manager. Required if you use the multimedia keys |
| U | KBD MediaCenter | MEDIACTR.EXE | Multimedia keyboard manager. Required if you use the multimedia keys |
| X | kbddrv32 | kbddrv32.exe | Added by the CRYPTER.A TROJAN! |
| X | kbddrvinf | kbddrvinf.exe | Added by the CRYPTER.A TROJAN! |
| N | KCeasy | KCeasy.exe | KCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella |
| U | KClient | kstatus.exe | KClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet |
| N | kdx | KHost.exe | KonTiki Secure Delivery Plug In related. "The Kontiki Delivery Management System (DMS) is a secure delivery network for distribution of video, software, audio, documents, and other digital media. The Kontiki DMS enables enterprises to efficiently publish, secure, deliver and track digital media to employees, partners, and customers" |
| U | KE9801 | DriBat32.exe | KE-9801 multimedia keyboard - required if you use the multimedia keys |
| X | Keenvalue | Keenvalue.exe | Keenvalue spyware - see here |
| U | KEMailKb | KEMailKb.EXE | Controls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down |
| ? | Kemet | kemet.exe | ?? |
| X | kern64dll | [random filename] | Added by the TARNO.J TROJAN! |
| X | kernctl32 | rundll32 kctl32.dll, initialize | Added by the AGENT.AT TROJAN! |
| X | Kernel | bboy.exe | Added by the MUMU.B WORM! |
| X | Kernel Loader | ntkrnl.exe | Added by the CERVIVEC.A WORM! |
| X | kernel system daemon | ACTIVAT0R.exe | Added by the RANDEX.AW WORM! |
| X | kernel32 | kern32.exe | Added by the BADTRANS.A WORM! |
| X | Kernel32 | Kernel32.exe | Added by a number of VIRUSES, WORMS and TROJANS! |
| X | kernel32 | kernel.dli | Added by the NETDEVIL.B TROJAN! |
| X | Kernel32 | Kernel.dll | Added by the REDLOF.M VIRUS! |
| X | kernel32 | kernel32.dlI | Added by the NETDEVIL.15 TROJAN! |
| X | Kernel32 | krnl32.exe | Added by the EPON WORM! |
| X | Kernel32 | Kernel32.win | Added by the GAGGLE.D or GAGGLE.E WORMS! |
| X | Kernel32 | kernel32s.exe | Added by the SDBOT-PU TROJAN! |
| X | kernel32dll | guardpc.exe | Added by the FORBOT-CU WORM! |
| N | kernelfaultcheck | dumprep 0 -k | Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out |
| N | kernelfaultcheck | dumprep 0 -u | Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out |
| X | KernelFaultChk | sms.exe | Added by the DEADHAT WORM! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k" or "dumprep 0 -u" |
| X | Kernell | systems.exe | Added by the TARNO.C TROJAN! |
| X | Kernell32 | Kernell.dll | Added by the DESTINY.A TROJAN! |
| X | KernellApps | csrss.exe | Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| X | Kernelw | Kernelw32.exe | Added by the INDOR.E WORM! |
| X | Kernel_check | wmiprvse.exe | Added by the SONEBOT-B WORM! |
| X | key | sysxp.exe | Added by the BEAGLE.AB WORM! |
| X | key | sys_xp.exe | Added by the BEAGLE.AC WORM! |
| X | key | winxp.exe | Added by the BEAGLE.AG WORM! |
| X | Key Logger | csrss.exe | Added by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| N | Key Text | KeyText.exe | Key Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs |
| X | Key1 | Rlid.exe | Added by the LIXY TROJAN! |
| ? | Key2 | serve.exe | ?? |
| Y | KeyAccess | keyacc32.exe | KeyServer KeyAccess client software - "when the KeyServer program is launched, the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess, a keyed program cannot run, so license control is very secure" |
| X | Keybdcntl | keybdcntl.exe | Added by a variant of the CRYPTER.C TROJAN! |
| U | Keyboard Manager | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
| Y | Keyboard Preload Check | Preload.exe | Millenium Multi-Function Keyboard driver |
| U | KeyMaestro | kmaestro.exe | Multimedia keyboard manager. Required if you use the multimedia keys |
| U | keymap | keymap.exe | System Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game |
| X | keymgrldr | rundll32 setupapi, InstallHinfSection... keymgr3.inf | CoolWebSearch parasite variant |
| U | KeyPatrol | KeyPatrol.exe | KeyPatrol - detects Key Loggers ("keyboard loggers" or "keyloggers") using both behavioral and pattern-matching algorithms |
| U | KeyWallet | KWallet.exe | "KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins, passwords and other personal data manually" |
| X | kfienq | masbl.bat | Added by the KIFER TROJAN! |
| N | khooker | khooker.exe | SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required |
| U | KICKMON.EXE | KICKMON.EXE | KeepItClean - utility that deletes safe to remove files, cookies, browsing history, etc. This is the scheduler - if you don't schedule clean-ups it isn't required |
| U | Kill Popup | KillPopup.exe | KillPopup - pop-up stopper |
| N | Kinberlink | Kinberlink.exe | Kinberlink network messaging. Available via Start -> Programs |
| U | KK Loader | loadkk.exe | KeyKey XP Professional from KeyKey.com. "Monitor Instant Messages, Chats, Emails, Web Site URLs, Passwords, Computer Programs, Start Up and Shut Down time and much more completely undetected to the user." |
| U | klp | run32dll.exe | PAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online |
| U | KM9801U | MMHotKey.exe | Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen |
| U | kmw_run.exe | kmw_run.exe | Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features |
| U | kmw_show.exe | kmw_show.exe | Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features |
| N | Kodak Batch Transfer | pezdow1.exe | Part of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC |
| U | Kodak EasyShare software | EasyShare.exe | Software bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually |
| N | Kodak Picture Transfer Software | pts.exe | Looks for Kodak camera connection and media insertion. Available via Start -> Programs |
| N | Kodak Software Updater | backweb*****.exe | Software updater for Kodak Easyshare digital cameras |
| Y | KodakCCS | KodakCCS.exe | Kodak DC File System Driver |
| N | Konni Symbol Autostart | KonniSymbol.exe | Gives configuration access to RagTime Solo professional business publishing software. RagTime Solo is the private user version of RagTime 5 |
| N | kontiki | kontiki.exe | Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops |
| U | KREC32 | krec32.exe | StarrCommander Pro Keystroke logging software |
| U | Krnlmod | Krnlmod.exe | Keylogger - see here. Given a "U" recommendation because it depends if you intentionally installed it. If you didn't, treat it as "X" and uninstall or remove via Spybot S&D (for example) |
| U | ktchnsnk | ktchnsnk.exe | HP program found with the Office Jet 500/600/700 series which initializes the Office Jet manager each time the computer is booted up or rebooted |
| X | kv3000 | lover.vbe | Added by the ZSYANG.B WORM! |
| X | kvern16.dll | regsvr32.exe [path] kvern16.dll | DailyWinner adware |
| X | kw3eef76 | rundll32.exe [path] kw3eef76.dll, EnableRunDLL32 | LZIO.com adware downloader |
| N | kX Mixer | kxmixer.exe | Provides Mixer and Control functionality to KxProject Audio driver for EMU10k based soundcards |