My system [WinXPSP3] shows %programfiles%\Common Files\InstallShield\engine\6\Intel32\knlwrap.exe. It was installed in late 2002, possibly in connection with Roxio ECDC 5. I submitted it to VirusTotal: the SHA1 hash there is the same as on my file; the scan shows that AVG thinks it is a trojan, but no one else dislikes it at all. My Avira AntiVir 8 does not complain. Surely an AVG false positive!