KernelFaultCheck and dumprep.exe in 2026: Safe or Not?

KernelFaultCheck in 2026: the short answer
KernelFaultCheck is a startup entry that runs dumprep.exe, the Windows Error Dump Reporting Tool, after a serious crash.[1][2] It is part of the error reporting system of Windows XP era computers, and on its own it is not malware.
In 2026 the entry matters mostly on old machines. Microsoft ended Windows XP support on April 8, 2014, so those systems get no security updates.[3] Newer Windows versions report errors through WerFault.exe.[4] If KernelFaultCheck appears on a modern PC, or dumprep.exe runs from a strange folder, check it for malware.
| Question | Answer |
|---|---|
| What runs | dumprep.exe with the switches 0 -k[1] |
| What -k means | Kernel fault check; -u means user fault check[1] |
| Where it starts from | HKLM Run registry key, system32 folder[1] |
| What it does | Creates memory dump reports that can be sent to Microsoft[2] |
| Safe to remove the entry | Yes, forum answers call it non-essential[1] |
| Modern counterpart | WerFault.exe, Windows Error Reporting[4] |
Timeline: dumprep.exe from Windows XP to 2026

| Date | Event |
|---|---|
| December 30, 2009 | A user reports a KernelFaultCheck startup item after a failed game install crashed the PC[1] |
| December 31, 2009 | A forum answer explains the -k switch and how to disable the entry[1] |
| April 8, 2014 | Windows XP goes out of support; no more security updates[3] |
| November 8, 2017 | 2-Spyware publishes the original report below |
| October 2026 | This update; we found no new Microsoft guidance on dumprep.exe |
What changed since 2017
The process itself did not change. What changed is the world around it. Windows XP, the system where dumprep.exe and KernelFaultCheck were common, has been out of support since April 8, 2014.[3] A computer that still runs it has no security fixes, so any crash on it deserves a closer look.
On current Windows, error reports come from WerFault.exe, which Microsoft Q&A answers describe as the Windows Error Reporting utility.[4] So if a security tool flags KernelFaultCheck on a Windows 10 or 11 machine, it is not the normal pattern. A leftover registry value from an old migration is possible, but so is a fake process name.
The old advice in our 2017 report still holds. Remove the startup entry if it bothers you, keep the real file in system32, and find out why the system crashed in the first place.
Risks and fakes around dumprep.exe (our analysis)
Malware often borrows the names of real Windows files so that people leave it alone. Based on the cases we see, these are the signs to watch for:
- A dumprep.exe file outside C:\Windows\System32, for example in AppData, Temp or a Downloads folder.
- A file named dumprep.exe or KernelFaultCheck attached to an email, a chat message or a download. Windows never sends it that way.
- High CPU use that never ends, even when no crash happened before the restart.[2]
- A KernelFaultCheck entry that comes back on every start although the PC has not crashed.
- Fake "system repair" sites that use the name to sell cleaner tools or to push you into calling a support number.
How to check and remove KernelFaultCheck safely

1. Check the location. Open Task Manager, right-click the process and open its file location. The genuine file sits in the Windows system32 folder, and the entry points there.[1] Anything else is a red flag.
2. Look for a crash. KernelFaultCheck is created after the system recovers from a serious error.[1] If you remember a blue screen or a sudden restart, the entry is expected.
3. Remove the entry. Run msconfig and untick the item, or open regedit, go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and delete the KernelFaultCheck value. Then restart.[1]
4. Keep the file. Do not delete dumprep.exe from system32. Removing the startup value is enough, and the file belongs to Windows.
5. Scan the PC. If the file was in another folder or kept using the CPU, scan the system with an up to date security tool. Our virus removal guides explain what to do with trojans that hide behind system names.
6. Fix the cause. Update drivers, test memory and disks, and remove software that crashed the system. If the PC still runs Windows XP, plan an upgrade, because it has not had security updates since 2014.[3]
What is still unknown
- Whether any current malware family uses the KernelFaultCheck name. We found no 2026 report that names it.
- Whether Microsoft still ships dumprep.exe in any supported Windows version. We found no current Microsoft page that says so.
- How many Windows XP computers that could create this entry are still online.
Our original 2017 report
The text below is our report as first published in 2017. We keep it unchanged for the record; the sections above bring it up to date.
KernelFaultCheck is the name of a process associated with a dumprep.exe file. The latter is known as Windows Error Reporting Dump Reporting Tool and is classified to legitimate Windows processes.
The command appears as a result of a system crash or serious damage to system files. In some cases, the entry appears after the system recovers from Blue Screen of death (BSOD). Dumprep.exe writes the information about an occurred issue in a text file and then urges you to send the report to Microsoft.
In some cases, users, who tend to survey their startup processes, might notice this task. Alternatively, the error might bother them by appearing every few minutes:
"Resident denied the change of KernelFaultCheck (category system Startup global entry) based on your black list."
There are two possible explanations to the occurred system crash:
- damaged hardware
- malware intervention
Speaking of the latter, complex computer trojans are capable of inflicting such damage. Therefore, it is necessary to identify it and apply specific elimination measures. In that case, simply scanning the system with malware elimination is not enough. Check the section about trojans in the article about Malware to find out more information.
While usually, KernelFaultCheck is not malicious process, it might signal the presence of malware in your system, In that case, you need to scan the system with multiple security tools. In addition, you should not exclude the possibility that KernelFaultCheck might be the veneer for malware.
Regarding the rise of ransomware as well as Emotet and QakBot trojans, it is not difficult for malware developers to foist viruses in disguise of legitimate system process. You might suspect its malicious origin, if the task consumes an unusual amount of CPU, e.g., more than 30%. In that case, you need to disable the command, delete its entry from Registry Editor, and scan the system with malware elimination tool.
Command Termination
Note that legitimate version of this file is an integral element of Windows. In other words, if you notice dumprep.exe in a received email attachment, do not open it, as it is most likely corrupted.
In some cases this KernelFaultCheck command may appear after you attempt and fail to install computer games. In that case, make sure the game is not infected with malware and is compatible with the system.
All in all, this command is not a crucial element of the system, so you might delete it. In order to remove KernelFaultCheck fully, launch Registry Editor:
- Click on Windows+R, type in regedit and click OK.
- When it opens, go to the following location: HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run
- Find KernelFaultCheck entry, right-click on it and choose Delete.
Windows 7 users may also disable the functionality of this file:
- Go to Control Panel, navigate to System and then Advanced tab.
- Choose Settings button for Startup and Recovery.
- At write debugging information, expand the menu, choose (none) and click OK.
- Next, click the Error Reporting button and choose Disable error reporting.
- You may leave But notify me when critical errors occur checked. Click OK to close the window.
After you complete the steps, update your cybersecurity applications and scan the system. In this case, FortectIntego or MalwarebytesMalwarebytes might come in handy.
Related guides on 2-Spyware
Frequently asked questions
What is KernelFaultCheck?
KernelFaultCheck is a startup entry that runs dumprep.exe with the -k switch after a serious system crash. In a Microsoft forum answer, -k is described as a kernel fault check and -u as a user fault check.{1} The entry sits in the HKLM Run key and points to the system32 folder.{1} Its job is to prepare an error report about the crash.
What is dumprep.exe?
Dumprep.exe is the Windows Error Dump Reporting Tool. A Microsoft Q&A answer says it creates memory dump reports that you can send back to Microsoft.{2} It belongs to the error reporting system of older Windows versions such as Windows XP. The genuine file lives in the Windows system32 folder, not in a user or temp folder.
Is dumprep 0 -k a virus?
Usually no, the command dumprep 0 -k is the normal way Windows starts the kernel fault check after a crash.{1} It becomes suspicious when the file sits outside system32, when it keeps using a lot of CPU, or when it arrives as an email attachment. In those cases scan the computer with an up to date security tool.
Can I delete the KernelFaultCheck entry?
Yes, you can delete the startup entry, because Microsoft forum answers describe dumprep.exe as a non-essential process.{1} Remove the KernelFaultCheck value from the HKLM Run key or disable it in msconfig, then restart. Do not delete the dumprep.exe file itself from system32. Removing the entry does not fix the crash that created it.
Why does dumprep.exe use 100% CPU?
Dumprep.exe can use a lot of CPU while it builds a memory dump report after a crash.{2} If the load lasts for a long time or returns after every start, the report may be stuck, or the process may not be genuine. Check the file location, scan for malware, and look for the cause of the original crash.
Is KernelFaultCheck still relevant in 2026?
Only on old Windows XP era systems, which Microsoft stopped supporting on April 8, 2014.{3} Newer Windows versions use WerFault.exe for error reporting, according to Microsoft Q&A answers.{4} If you see KernelFaultCheck on a current PC, treat the entry as unusual and check where the file really is.
Log in to comment
No comments yet. Be the first.