| X | keyboard | keyboard*.exe [* = number] | "Detected by Kaspersky as the VB.ZG TROJAN!"
|
| X | keyboard | kybrdef_7.exe | "DollarRevenue adware"
|
| X | keyboard | [path to trojan] | "Added by the DLOADR-AOZ TROJAN!"
|
| X | Keyboard | lsass.exe | "Added by the AGENT.US WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %CommonAppData%\Fearghus"
|
| N | Keyboard Customizer | TpKmapAp.exe | "Part of the Keyboard Customizer Utility for IBM/Lenovo Thinkpad notebooks. This is the main user interface for the utility but it doesn't normally seem to be running if enabled at startup. Also |
| U | Keyboard Manager | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys
|
| Y | Keyboard Preload Check | Preload.exe | Millenium Multi-Function Keyboard driver
|
| ? | Keyboard Status | KeyStat.exe | "Multimedia keyboard manager for Medion desktop and notebook PCs? Located in %ProgramFiles%\Medion\KeyStat"
|
| X | keyboard_enum | keyboard_enum.exe | "Added by the BDOOR-GP BACKDOOR!"
|
| U | keyhook | keyhook.exe | "Hotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeys"
|
| U | KeyMaestro | kmaestro.exe | Multimedia keyboard manager. Required if you use the multimedia keys
|
| U | keymap | keymap.exe | System Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game
|
| X | keymgrldr | "rundll32 setupapi | InstallHinfSection... keymgr3.inf" |
| U | KeyPatrol | KeyPatrol.exe | "KeyPatrol - key logger detector using both behavioral and pattern-matching algorithms that used to be part of PestPatrol before CA's aquisition"
|
| U | keyplusplus | startk.exe | "Key++ Invisible Spy Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| X | keyserv | keyserv.exe | "KeyThief spyware"
|
| U | Keyspan Digital Media Remote | KDMRdmn.exe | "Remote control driver for Keyspan Digital Media Remote devices"
|
| U | keystroke | keystroke.exe | "QuickLaunch surveillance software. Uninstall this software unless you put it there yourself"
|
| U | KeyWallet | KWallet.exe | ""KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins |
| U | KLog | Keyspy.exe | "KeyLoggPro.B keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | KM9801U | MMHotKey.exe | Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
|
| U | LaoKey | LaoKey.exe | "Lao Script for Windows (LSWin) is an extension to the Windows operating system to allow Lao language to be used with many different Windows-based applications"
|
| U | ledpointer | CNYHKey.exe | Chicony Electronics Multimedia Keyboard Hotkey Driver
|
| X | livekey | webgrade.exe | "LiveKeys adware. File located in %Program Files%\livekey\livekeys"
|
| X | livekeys | webgrade.exe | "LiveKeys adware. File located in %Program Files%\livekey\livekeys"
|
| U | LManager | HotkeyApp.exe | "Programmable keys on Acer |
| Y | load= | hotkey.exe | Solo 5300 display driver for Win2K on some Gateway laptops
|
| U | LWBKEYBOARD | KbdAp32A.exe | Keyboard utility for a Labtec brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
|
| U | MagicKeyboard | PreMKBD.exe | "Related to Samsung laptops. Provides ability to program keys to perform specific functions"
|
| U | MediaKey | MediaKey.exe | "Multimedia keyboard manager. Required if you use the multimedia keys"
|
| X | Mickey Mouse Cereal | [random filename].exe | "Added by the RANKY.Q TROJAN!"
|
| X | Microsoft ConfgKeys | wurmgrd32.exe | "Added by the RBOT-ARX WORM!"
|
| U | Microsoft Intellitype Pro | speedkey.exe | Additional keyboard shortcuts on MS programmable keyboard
|
| X | Microsoft Keyboard Enhance 2.0. | iasrecst.exe | "Added by the BCKDR-QIL BACKDOOR!"
|
| X | Microsoft Keyboard Enhance V2.0 | iasrecst.exe | "Detected by F-Prot as the DOWNLOADER2.AILI TROJAN!"
|
| X | Microsoft System Checkup | Keymgr.exe | "Added by the DONK.M WORM!"
|
| X | Microsoft Taskmanager Updater | keyboard.exe | "Added by the RBOT-ALU WORM!"
|
| X | MicroSoft Toolbar | key.exe | "Added by the RBOT-AEW WORM!"
|
| X | Microsoft Windows Keyboard service | keyboard.exe | "Added by the RBOT-CRF WORM!"
|
| X | Microsoft Winedows startup | WinKey.exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Microsoft Winedows Updateing | NinKey.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoftkeysd | systemproc.exe | "Added by the FORBOT-BI WORM!"
|
| X | Microsoftkeysd | systemwin32s.exe | "Added by the WOOTBOT.CO WORM!"
|
| X | Microsoftkeysds | lass32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Mircrosoft Technic Help | EditKey.exe | "Added by the KOLABC.AS WORM!"
|
| X | Mircrosoft Technic Help | RegKey.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| N | MMHotKey | MMHotKey.exe | Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
|
| U | MMKeybd | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys
|
| U | ModPS2 | ModPS2Key.exe | "Hotkey drivers for Chicony keyboard. Required if you use the hotkeys"
|
| X | MS-RunKey | arr.exe | MS-Connect dialler/hijacker
|
| X | mule_st_key | flec006.exe | "Added by the BAGLE.AV TROJAN!"
|
| U | Multi-function keyboard | GWHotkey.exe | "Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail |
| U | Multimedia KBD | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys
|
| U | MULTIMEDIA KEYBOARD | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys
|
| X | MULTIMEDIA KEYBOARD88 | smss.exe | "Added by the SILLYFDC WORM! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
|
| U | My-disgo | MyKey disgo.exe | "Related to disgo pro. Program will synchronize data"
|
| N | Naggerrunkey | nagger.exe | Packard Bell Free Internet Signup screen
|
| U | NBKeyScan | NBKeyScan.exe | "This tool comes with a special version of Nero BackItUp for some external harddisks. Controls two buttons on the drive - one button power off the drive and the other directly calls Nero BackItUp to make a quick backup"
|
| X | NetworkKey | netkey.exe | "Added by the IRCBOT-AJ TROJAN!"
|
| X | NLS Keyboard | keyboard.exe | "Added by a variant of the SPYBOT WORM!"
|
| U | NSRKey | NSRTray.exe | "System Tray access to Norton Save & Restore backup utility"
|
| U | NVHotkey | rundll32.exe nvHotkey.dll | "Enables the use of ""hot keys"" for changing setting on Nvidia graphics"
|
| X | OneMoreKey | xpa.exe | "XP Antivirus rogue security software - not recommended"
|
| U | Panasonic HotKey Manager | HKEYAPP.EXE | HotKey management for Panasonic rugged mobile PCs
|
| U | PC Spy Keylogger | ToolKeylogger.exe | "PCSpyKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | PowerKey | PowerKey.exe | "Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610"
|
| N | Printkey2000 | printkey2000.exe | Screen grabber that intercepts the pressing of the Print Screen (Prn Scrn) key. Start manually when required
|
| U | PrivacyKeyboard | PrivacyKeyboard.exe | "PrivacyKeyboard is a product ""that can provide every computer with strong protection against ALL types of keylogging programs and keylogging hardware devices |
| N | ProdikeysAutorun | Prodload.exe | "Creative Prodikeys software - 'an interactive music entertainment device which not only functions as a full-featured |
| U | pskl | keyspy.exe | "KeyboardLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | RCHotKey | RCHotKey.exe | "Part of RingCentral Call Controller™ which ""turns your PC into your personal business command center. It brings you real time control of your calls |
| X | Regkey for autostart | winservice.exe | "Added by the RBOT-NU WORM!"
|
| X | reg_key | FUKULAMER.exe | "Added by the BEAGLE.AH WORM!"
|
| X | reg_key | loader_name.exe | "Added by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS!"
|
| U | S3Hotkey | s3hotkey.exe | Hotkey system tray icon to enable switching between monitors. Found on laptops with an S3 Twister integrated graphics card
|
| N | ShortKeys 99 | SHORTKEY.EXE | "ShortKeys from Insight Software Solutions - allows you to program keys with text strings"
|
| U | ShortKeys Lite | shklite.exe | "ShortKeys Lite from Insight Software Solutions |
| Y | sHotKey | sHotKey.exe | "Special function key manager for Chicony keyboards - see here"
|
| U | SiS Compatible Super VGA Keyboard Daemon | keyhook.exe | "Hotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeys"
|
| U | SiS Windows KeyHook | keyhook.exe | "Hotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeys"
|
| U | Smart Keyboard | Smartkbd.exe | Netropa Smart Keyboard driver
|
| U | Speedkey | SPEEDKEY.EXE | Additional keyboard shortcuts on MS programmable keyboard
|
| U | Spy-Keylogger | skl.exe | "SpyKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | SpykEy | Spyky.exe | "SpyKy keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | spyshelter | antikeylogger.exe | "SpyShelter - anti-keylogger protects against keylogger programs monitoring your keystrokes"
|
| Y | Start RF Wireless Keyboard | ktrexe.exe | Yuanxun Electronics RF wireless keyboard driver
|
| X | startkey | svcmgr.exe | "Added by the HIPPER-B TROJAN!"
|
| X | startkey | update.exe | "Added by the BIFROSE-DG TROJAN!"
|
| X | startkey | XMCHAI.EXE | "Added by the BIFROSE-AO TROJAN!"
|
| X | startkey | explore32.exe | "Added by the BDOOR-MT BACKDOOR!"
|
| X | startkey | CKOTS.exe | "Added by the BIFROSE-HM TROJAN!"
|
| X | StartKey | pligde.exe | "Added by the BIFROSE.E TROJAN!"
|
| X | startkey | RunWinRaR.exe | Added by a variant of the BIFROSE-LV TROJAN!
|
| X | startkey | Mysia.exe | Added by the CEP TROJAN!
|
| X | startkey | explorer.exe | "Added by the BCKDR-MLD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | startkey | furzi.exe | "Added by the BIFROSE-OK TROJAN!"
|
| X | startkey | krnl.exe | "Added by the BIFROSE-S TROJAN!"
|
| X | startkey | royale.exe | "Added by a variant of the SDBOT WORM!"
|
| X | startkey | rtfmsv.exe | "Added by the EDEPOL-C TROJAN!"
|
| X | startkey | scvhost.exe | "Added by the BIFROSE-PM TROJAN!"
|
| X | startkey | server.exe | "Added by the BIFROSE-DB TROJAN!"
|
| X | startkey | win32i.exe | "Added by the BIFROSE-R TROJAN!"
|
| X | startkey | winampXP.exe | "Added by the BIFROSE-OY TROJAN!"
|
| X | startkey | svchost32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | startkey | winlogin.exe | "Added by the BIFROSE-PM TROJAN!"
|
| X | startkey | antivir.exe | "Added by the BIFROSE-TO TROJAN!"
|
| X | startkey | svchost.exe | "Added by the AGENT-FPL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | StartKey | msnmsie.exe | "Added by the BIFROSE.M BACKDOOR!"
|
| X | startwindowskeyuser | rundle2.exe | "Added by the JAVAKILLER TROJAN!"
|
| U | Sysconfig | Stealth KeySpy.exe | "StealthKeySpy - keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| X | Syskey | sysinit.exe | "Added by the BEAGLE.AX WORM!"
|
| U | SystemKey | rundll32.exe [path] SystemKey.dll rdl | "Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| X | TaskMgr | keymayker.exe | "Added by the LDPINCH-EP TROJAN!"
|
| U | TEscKey | TEscKey.exe | Toshiba Escape Key handler. Enables you to program and use the <FN><Esc> key combination to perform a specific function
|
| U | TFunckey | TFuncKey.exe | Deals with the <Fn> - <Function> key combinations on a Toshiba laptop
|
| U | THOTKEY | THotkey.exe | "Associated with the Fn+ keys on Toshiba laptops. When disabled some keys still worked |
| U | TOSHIBA Accessibility | FnKeyHook.exe | """Allows you to use the Fn key to create a hot key combination with one of the function keys without pressing the two keys simultaneously as is usually required. Using Accessibility lets you make the Fn key a sticky key |
| U | Toshiba Key State | KEYSTATE.EXE | "Displays an icon in the System Tray indicating the state of the CAPS LOCK key. Can be handy on (e.g. |
| U | TPHOTKEY | TPHKMGR.exe | "Hotkey manager for IBM/Lenovo Thinkpad notebooks. Supports the blue ""ThinkVantage"" or ""Access IBM"" help key |
| U | TPHOTKEY | TPOSDSVC.exe | "Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example |
| ? | USB Hub Keyboard Patch | SKBPATCH.EXE | USB HUB Update
|
| U | va10key | va10key.exe | Only required if you use the 10 kay bay unit with a Sony Vaio laptop
|
| U | VC_Log | keylog.exe | "PaqKeylog is a surveillance software program that logs keystrokes and can run in stealth mode. Uninstall this software unless you put it there yourself"
|
| N | WebKey | WebKey.exe | "WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet"
|
| X | WindowRegKey update | wins.exe | "Added by the SPYBOT.I WORM!"
|
| X | windows | hkey.exe | "Added by the GAOBOT.AFW WORM!"
|
| X | Windows Explorer Key | explorer.exe | "Added by the IRCBOT-YB WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Windows Keyboard Services | winkeyboard.exe | "Added by the IRCBOT.AFS WORM!"
|
| X | Windows Keyboard Services | winkeybrd.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Keyboard Services | winkeybrd32.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows XP SP2 KeyGen | Windows XP SP2 KeyGen.exe | "Added by the TIBICK-C WORM!"
|
| X | WindowsKeyUpdate | master.exe | "Added by the JOSAM WORM!"
|
| X | WindowsRegKey Autoupdate | [random filename] | "Added by a variant of the RBOT WORM!"
|
| X | WindowsRegKey upd4te2d4te | *********.exe [* = random char] | "Added by the RBOT.XQ WORM!"
|
| X | WindowsRegKey update | winupdate.exe | "Added by the RBOT-QJ WORM!"
|
| X | WindowsRegKey update | windns.exe | "Added by the RBOT.IE WORM!"
|
| X | WindowsRegKey update | winupdatexx.exe | "Added by the RBOT.LW WORM!"
|
| X | WindowsRegKey update | [random filename] | "Added by the RBOT.QT WORM!"
|
| X | WindowsRegKey update | svchoosts.exe | "Added by the RBOT.ADB WORM!"
|
| X | WindowsRegKey update | svchostc.exe | "Added by the RBOT.IF WORM!"
|
| X | WindowsRegKey update | wdnupdate.exe | "Added by the SDBOT.QX WORM!"
|
| X | WindowsRegKey update | Windowsup.exe | "Added by the SDBOT.PU WORM!"
|
| X | WindowsRegKey update | WINUPDATES.EXE | "Added by the RBOT-MM WORM!"
|
| X | WindowsRegKey update | rkbuouoxfl.exe | "Added by the RBOT-OO WORM!"
|
| X | WindowsRegKey update | winsys.exe | "Added by the RBOT-JY WORM!"
|
| X | WindowsRegKey update | winupdat32.exe | "Added by the RBOT-AGW WORM!"
|
| X | WindowsRegKey update XP | windexv1.exe | "Added by the RBOT-ABM WORM!"
|
| X | WindowsRegKey%$ update | msi332.exe | "Added by the RBOT-IX WORM!"
|
| X | WindowsRegKey%update | ethernet32m.exe | "Added by the RBOT-EN WORM!"
|
| X | WindowsRegKeys update | winsysi.exe | "Added by the SDBOT.WE WORM!"
|
| X | WinEssential | Keyhost.exe | Hijacker - hailing from jraun.com
|
| X | WinEssential | keyword.exe | "Jraun adware"
|
| U | WinKey | winkey.exe | "Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system |
| U | WireLessKeyboard | PS2USBKbdDrv.exe | "Related to WireLess Keyboard Multimedia Combo Set by SANSUN Industries"
|
| X | [various names] | keybdll.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | KeywordFinder.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|