| Status | Autorun name | Command | Description |
| N | j2 Tray Menu | HotTray.exe | eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here |
| X | j6GgCXwtFM | control.exe [path] j6ggcxwtfm.cpl | Added by the SEFNIT.K TROJAN! The "j6ggcxwtfm.cpl" file is located in %ProgramFile%\anouicgfwkkv1v |
| X | JA Cfg Util v2 | jacfg2.exe | Added by the RBOT-AL WORM! |
| X | JA Config 32 | Awesome32.exe | Added by a variant of the SDBOT WORM! |
| U | Jammer | jammer.exe | Jammer by Agnitum - "Jammer is the last word in Internet security. It combines a user-friendly interface with very sophisticated and powerful security measures that protect your Windows system while you are surfing the web" |
| X | Jammer2nd | Jammer2nd.exe | Added by the NETSKY.Z WORM! |
| X | java | remote.cmd | Added by the BANKER-EHG TROJAN! |
| X | java | system.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Java (VM) v6.9 | jav.bat | Added by the AGENT-GZK TROJAN! |
| X | Java applet | javaup.exe | Added by the SDBOT-ACF WORM! |
| X | Java Application | vssmf32.exe | Added by the SPIGOT BACKDOOR! |
| X | Java Auto Update | ujm.exe | Added by the SDBOT-ADH WORM! |
| X | Java Configuration Loader | spoolsvfix.exe | Added by the SDBOT.CA WORM! |
| X | Java developer Script Browse | jusched.exe | Added by the VB-ESK TROJAN! Note that this is not the legitimate Oracle (was Sun Microsystems) file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %Windir% |
| X | Java Express | sjehost.exe | Added by the SDBOT-DNJ WORM! |
| X | Java Runtime Environment | jbuild.exe | Added by the DELBOT-J WORM! |
| X | Java Runtime Value | runjava.exe | Added by the RBOT-DDJ WORM! |
| X | Java Runtimes | iexplore.exe | Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in a %Windir%\Java\Java folder |
| X | Java Softe | Java32.com | Added by the RBOT.ECN WORM! |
| X | Java update | javaqs.exe | Added by the SWARLEY.A WORM! |
| X | Java Update | keeper.exe | Added by the AGENT-DIS TROJAN! |
| X | Java Update | svchost.exe.exe | Added by the AGENT-LBS TROJAN! |
| X | Java Update | hostwww.exe.exe | Added by the AGENT-MFH TROJAN! |
| X | Java Update Checker | JavaUpdate.jar | Added by the INCRAT HACKTOOL! |
| X | Java Update Manager | jutched.exe | Added by the VB.AJYQ TROJAN! |
| X | Java Update Manager | jstchde.exe | Added by the SMALL.AWBM TROJAN! |
| X | Java Update Manager | jusched.exe | Added by the FKFLDR-C MALWARE! Note that this is not the legitimate Oracle (was Sun Microsystems) file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %AppData%\HEX-5823-6893-6818 |
| X | Java Virtual Machine | javaw.exe | Added by a variant of the RBOT WORM! |
| X | Java VM v6.9.2 | jav.bat | Added by the DWNLDR-HLM TROJAN! |
| X | Java VM v6.91 | jav.bat | Added by the DWNLDR-HLL TROJAN! |
| N | Java(TM) Platform SE 6 | jusched.exe | Checks with Oracle's (was Sun Micrsosystems) Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now |
| N | Java(TM) Platform SE 6 U* | jusched.exe | Checks with Oracle's (was Sun Micrsosystems) Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now |
| N | Java(TM) Platform SE Auto Updater 2 0 | jusched.exe | Checks with Oracle's (was Sun Micrsosystems) Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now |
| X | Java**.exe [* = random char] | Java**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Java**32.exe [* = random char] | Java**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | java-plugin | javasctp.exe | Added by the VB.AMX TROJAN! |
| X | Java32 Configuration Loader | msnmesgr.exe | Added by a variant of the RBOT WORM! |
| X | JavaCore | JavaCore.exe | Added by the MATCASH TROJAN! |
| X | javadoc | javadoc.exe | Added by the AGENT.CE BACKDOOR! |
| X | Javascript | jscript.exe | Added by the DELBOT-AD WORM! |
| X | JavaScript Debugging Service | JsDbgMan.exe | Added by the DERDERO.E WORM! |
| X | JavaScriptMs | Mwsx.exe | Added by the BANCOS.CNH TROJAN! |
| X | JavaScriptMsxrs | Msxrs.exe | Added by the VB.BL WORM! |
| X | JavaTray | traymgr.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | JavaUpdate0.07 | [filename] | Added by the JUPDATE TROJAN! |
| X | JavaUpdateSched | jusched32.exe | Added by the BCKDR-CKB BACKDOOR! |
| X | JavaVM | java.exe | Added by the MYDOOM.M WORM and variants! Note - not to be confused with the valid Windows "java.exe" which is located in %System% as this is located in %Windir% |
| X | javawsa.exe | javawsa.exe | Added by the BANK-Y TROJAN! |
| X | jawa32 | jawa32.exe | Added by the AGENT.BG WORM! |
| X | Jawa322 | jawa32.exe | Added by a variant of the AGENT.BG trojan |
| N | JB | Jiffybar.exe | "Get Paid As You surf" application |
| X | jcidls | [random filename] | Added by a variant of the SLAPER TROJAN! |
| X | JDK55WFMZY | cdx.exe | Added by the MONDER.RON TROJAN! |
| ? | Jessops Insert Detect | InsDetect.exe | Part of Jessops Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted? |
| N | Jet Detection | ADGJDet.exe | Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection |
| Y | JetAdmin Discovery Indicator | HPJETDSC.EXE | HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry, and remains active to control the Discovery Indicator |
| X | jete | yujixit.exe | Added by the SDBOT.BRT WORM! |
| X | Jfwehnrt | ghgfjrs.exe | Added by the SDBOT-IJ WORM! |
| X | jfziem | jfziem.exe | Added by the AGENT-NPL WORM! |
| X | JgUJevQpNnePtDM | JgUJevQpNnePtDM.exe | Windows Recovery rogue security software - not recommended, removal instructions here |
| X | JHWKF | [path to trojan] | Added by the SMALL.MLC TROJAN! |
| X | jiahus | svchqs.exe | Added by the WOWPWS-AL TROJAN! |
| X | jidifedig | xudexoli.exe | Added by the SDBOT-UW WORM! |
| X | jijbl | ezlwy.bat | Added by the REDDW WORM! |
| X | jkdfj94kgdftdf | winlogan.exe | Added by the ZLOB.BZ TROJAN! |
| U | JMB36X Configure | JMRaidTool.exe | JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers |
| Y | JMB36X Configure | JMRaidSetup.exe | JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers |
| U | JMB36X IDE Setup | JMInsIDE.exe | JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers |
| U | JMB36X IDE Setup | xInsIDE.exe | JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidTool |
| U | JmpRes | svcwinra.exe | System Surveillance Pro surveillance software. Uninstall this software unless you put it there yourself |
| X | JmpyxPEOWqPO | JmpyxPEOWqPO.exe | Added by the FAKEAV-DAQ TROJAN! |
| X | jmudkve.dll | rundll32.exe jmudkve.dll,mzrwkwf | Added by the AGENT-DJD TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "jmudkve.dll" file is found in %System% |
| X | Jnskdfmf9eldfd | csrssc.exe | Added by the AGENT.EBC TROJAN! |
| U | Job-oversigt | taskmon.exe | Task Monitor (on Danish language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase) |
| U | JobHisInit | JobHisInit.exe | Used by Ricoh network printers to enable network printing from the client |
| U | JogServ2 | JogServ2.exe | "Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features |
| U | JOGSERV2.EXE | JogServ2.exe | "Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features |
| X | johkjh | srvd.exe | Added by a variant of the SLAPER TROJAN! |
| X | john315 | srrvc.exe | Added by a variant of the MAILBOT-BI TROJAN! |
| X | johnj315 | srvc.exe | Added by a variant of the MAILBOT-BI TROJAN! |
| X | johnj3155 | srvcc.exe | Added by a variant of the MAILBOT-BI TROJAN! |
| X | johnj3cd | srvdc.exe | Added by a variant of the SLAPER TROJAN! |
| U | Jomantha | razerhid.exe | Belkin n52te (powered by Razer) gaming keypad driver - required if you use the additional features and programmed keys/macros |
| X | jon315 | [path to trojan] | Added by the MAILBOT-BI TROJAN! |
| ? | jotl | millenzje.exe | ?? |
| U | JOYTECH USB Neo S Controller | JoytechNeoSTrayIcon.exe | System Tray access to Joytech Neo S PC gamepad controller software |
| X | jpgdiag | [path to worm] | Added by the STRATION-AN WORM! |
| X | jpupd | jpupd.exe | Added by the DIALER.CM TROJAN! |
| X | Jreg | Jreg2b.exe | FlashEnhancer adware |
| X | jucheck | jucheck.exe | Added by the SCRIMGE.O WORM! |
| X | Jufualt | winxp2.exe | Added by the SDBOT-AAB WORM! |
| X | Jufualt | svhost.exe | Added by the SDBOT-ADJ WORM! |
| X | Jufualt | java2.exe | Added by the SDBOT.AOE WORM! |
| X | Jufualt | j2.exe | Added by the SDBOT-ALJ WORM! |
| N | Juice | Juice.exe | Juice - a free utility that "allows you to select and download audio files from anywhere on the Internet to your desktop". This entry is present if you choose the option to add it to the startup group during installation |
| X | JuliaPerez | Tetek_Gede_Julia_Perez.exe | Added by the AUTORUN-BS WORM! |
| N | Juno_uoltray | exec.exe | Juno ISP software - not required |
| X | JuPo | jupos.exe | Added by the SDBOT-CAG WORM! |
| N | jusched | jusched.exe | Checks with Oracle's (was Sun Micrsosystems) Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now |
| X | jusched | [path to trojan] | Added by the BANKER-BWR TROJAN! |