Name Filename Status Description
*JanisRuckenbrodII janis.com X Added by the POPS WORM!
Creata Mail JMSrvr.exe U Creata_Mail. Smileys, stationary and more for you email. Required if you want to access the program from Outlook or Outlook Express
Etraffic JavaRun.exe X Marketing software from TopMoxie
Game Device JOYUPDRV.EXE N Genius game controller profile activator
Jammer jammer.exe U Jammer by Agnitum - "Jammer is the last word in Internet security. It combines a user-friendly interface with very sophisticated and powerful security measures that protect your Windows system while you are surfing the web"
Jammer2nd Jammer2nd.exe X Added by the NETSKY.Z WORM!
JavaVM java.exe X Added by the MYDOOM.M or MYDOOM.N WORMS! Note - not to be confused with the valid Windows "java.exe" which resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP) as this resides in C:\Windows or C:\Winnt
jawa32 jawa32.exe X Added by the AGENT.BG WORM!
JB Jiffybar.exe N "Get Paid As You surf" application
JobHisInit JobHisInit.exe U Used by Ricoh network printers to enable network printing from the client
Jog Serve JogServ2.exe U "Jog Dial" on a Sony Vaio laptop.  The dial can select various functions such as control audio. Needed if you use its features
JogServ2 JogServ2.exe U "Jog Dial" on a Sony Vaio laptop.  The dial can select various functions such as control audio. Needed if you use its features
Jreg Jreg2b.exe X BroadcastPC adware variant
jusched jusched.exe Y Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel

We specify that this entry should be allowed to run due to the security risks involved with not updating Java when a new version is released.
jushed32.exe jushed32.exe X CoolWebSearch parasite variant
jutsu jutsu.exe X Added by the RBOT-LS WORM!
Jv16pt Network Resident jv16pt_network.exe U jv16 PowerTools' network resident program. Only needed if you are using the program's network features
Jzi16 jzi16.exe ? ??
MSAdmin jdbgmrg.exe X Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here
MSConfigr jdbgmrg.exe X Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here
SunJavaUpdateSched jusched.exe Y

Checks with Sun's Java updates site to see if newer Java versions are available. Visit Sun's Java page or just run the Java Plug-In Control Panel. With this version of the file path and command, the version number in the path will change depending on the version of the software installed.

Please note that prior to version Version 6 Update 18, the file path and command includes the version. For example:

C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe

We specify that this entry should be allowed to run due to the security risks involved with not updating Java when a new version is released.

Swap Nut javaw.exe N SwapNut is a peer-to-peer file sharing and searching utility developed and marketed by File Metrics, Inc. Users can search for and find almost any type of digital file (audio, video, photos etc.) through a secure peer-to-peer network
topmoxie JavaRun.exe X Marketing software from TopMoxie
USB SECURITY DEVICE CoInstaller JupitCo.exe Y ButterflyMedia USB Flash drive related - required for the password security feature to work
msjava critical update jjfixer.exe X Troj/Hector-A is a downloader Trojan.
JavaScript Debugging Service JsDbgMan.exe X Added by the DERDEO.E mass-mailing worm.
Microsoft Java Virtual Machine javavm.exe X Added by a variant of the WIN32.RBOT WORM!
SunJavaUpdateSched javamx.exe X Added by the W32/Sdbot-WI WORM!
Service Registry NT Save jdbgmgrnt.exe X Added by the Troj/Bancos-CG TROJAN!
Jumper Defualt jumsvc32.exe X Added by the W32/Sdbot-TM WORM/IRC backdoor trojan!
wmon jusched.exe X Added by the W32/Agobot-OW WORM/IRC backdoor trojan and using a new servicename called wsaconfig.
[unknown] JACFG2.EXE X Added by the W32/Rbot-AL trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection also attempts to terminate known AV software so that it remains undetected.
JC Services jcsvc32.exe X Added by the W32/Sdbot-TT network worm. When the infection starts it connects to an IRC server where it waits for remote commands to execute.
Microsoft Synchronization Manager java.exe X Added by a variant of the W32/SDBOT WORM!
Daemons Updates Services jkiw.exe X Added by the W32/Rbot-RJ worm. This infection connects to an IRC server where it waits for remote commands.
ja cfg util v2 jacfg2.exe X Added by the W32/RBOT-AL WORM!
JuPo jupos.exe X Added by the W32/Sdbot-CAG backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Systes jrdtifkkxbbsa.exe X Added by the W32/Rbot-ADC worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
jawa322 jawa32.exe X Added by a variant of the Backdoor.Agent.bg trojan
WINTASK DLL jusched32.exe X Added by the W32.Mytob.AI@mm worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
javaupdatesched jusched32.exe X Added by the Troj/Bckdr-CKB
Microsoft Word Profissional Java Plug In close.exe X Added by the Troj/Banker-EL password-stealing trojan.
jxef1104 jxef1104.exe X Added by the W32/Xipi-A P2P worm.
efax dllcmd J2GDllCmd.exe U eFax_Messenger fax software
efax tray menu J2GTray.exe U eFax_Messenger fax software tray menu
Java applet javaup.exe X Added by the W32/Sdbot-ACF worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Enables Javascript Support javascript.exe X Added by the W32/Codbot-V worm.
microsoft corporation jview.exe X Added by the W32/Rbot-AOD
JavaVM java.exe X Added by the W32.Mydoom.CI@mm mass-mailing worm.
a jesse.exe X Added by the W32/Melo-A worm.
Service Monitor javams32.exe X Added by the Troj/Delf-NK backdoor Trojan.
java virtual machine javaw.exe X Added by a variant of the WIN32.RBOT WORM!
[various names] JAguAr.exe X TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
jkhhg jkhhg.dll X Added by the Troj/ConHook-N Trojan.
Launch Norton AntiVirus 2000 jorgf.exe X Added by the W32/Rbot-AUI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Service Monitor javams64.exe X Added by the W32/Sdbot-AFO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WINDOWS jif.exe X Added by the WORM_MYTOB.NE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
(78E611A2-E484-4A0D-811E-C40100A3F452) jajlee.dll X Added by the Troj/Fasong-B Trojan.
(78E611A2-E484-4A0D-811E-C40100A3F452) jknla.dll X Added by the Troj/Fasong-C Trojan.
Jufualt j2.exe X Added by the W32/Sdbot-ALJ worm and IRC backdoor.
[Various Names] jopplerg.exe X Part of the Wareout infection as described here.
Sun jusched.exe X Identified as the Codbot-Y worm and IRC backdoor. This should not be confused with the legitimate file found here in the C:\Program Files\Java\jre\bin folder.
MICROSFT NT SUPPORT jtzbpfnkxk.EXE X Added by the W32/Rbot-CMI worm and IRC backdoor.
wintask32 Jwintask.com X Added by the W32/Nafbot-A P2P worm. This infection will also modify your hosts file so that you are unable to reach various antivirus vendor's web sites.
jussdroputility JussDrop.exe U Related to DropShots Inc. A subscription based service for family to connect, converse and share photos and videos.
jb???.exe jb???.exe X The ??? in the file name are three random letters. Added by the Troj/Jubik-A Trojan.
JavaPlatform64 JavaPlatform X Added by the W32/Kassbot-M backdoor worm.
N2913c j[RANDOM].exe X Added by the W32.Rontokbro.X@mm mass-mailing worm.
jusched jusched.exe X Added by the Troj/Banker-BOV Spyware Trojan. This file should not be confused with the legitimate Sun Javaj file of the same name. The legitimate file will usually be under a sun folder in the Program Files directory.
A5118r j6321422.exe X Added by the W32/Brontok-AK mass-mailing worm.
JXL Radio jxl.exe X Added by the W32/Rbot-EBE worm and IRC backdoor.
juschedjava jusjava.exe X Added by the Troj/Banker-CLH. If you are infected with this Trojan you should immediately change all of your online banking passwords and information.
RPC Service jgszznv.exe X Added by the W32/Rbot-EMS worm and IRC backdoor.
javastr jucshed.exe X Added by the W32.Sixem.C@mm mass-mailing worm that sends email messages regarding the World Cup.
{5839511e-ec1b-4f91-ace3-fb88e52f5239} jevtxpg.dll X A file used by the rogue antispyware app, SpywareQuake, to issue fake security alerts on your taskbar.
Windows MS Update 32 jebote.exe X Added by the W32/Forbot-GK worm and IRC backdoor.
deterioraton jpqet.dll X A file used by the rogue antispyware app, SpywareQuake, to issue fake security alerts on your taskbar.
MS Java for Windows XP & NT javanet.exe X Added by the W32/Vanebot-A worm and IRC backdoor.
MS Java Applets for Windows NT & XP javaapplet.exe X Added by the W32/Vanebot-B worm and IRC backdoor.
Sun Java Console for Windows NT & XP jconsole.exe X Added by the W32/Vanebot-C worm and IRC backdoor.
Win Update justchd.exe X Added by the Troj/Banker-DLG Trojan.
Java Sun Scheduler jusched.exe X Added by the W32/Sdbot-CQC worm and IRC backdoor.

W32/Sdbot-CQC spreads to other network computers by exploiting common buffer
overflow vulnerabilities, including: SRVSVC (MS06-040), WKS (MS03-049)
(CAN-2003-0812), PNP (MS05-039) and ASN.1 (MS04-007). The worm may also spread
via network shares and MSSQL servers protected by weak passwords.
jmudkve.dll jmudkve.dll X Added by the Troj/Agent-DJD Trojan.
<not used> JGMDMSXM.DLL X Added by the WORM_STRAT.BR mass-mailing worm.
<not used> jfeee.exe X Added by the DoDoor adware.
JVMO JVMO.exe X Added by the Troj/BankDl-BJ downloader Trojan.
<not used> jjakarta.exe X Added by the Troj/VB-CRT Trojan.
jgsdrpcn jgsdrpcn.dll X Added by the W32/Stratio-BH worm.
winupdate jusched.exe X Added by the Troj/DwnLdr-FUX Trojan.
{ab340860-fd81-4a65-b345-82eb77a66b5e} jbtazy.dll X A Trojan used by the rogue anti-spyware program VirusBursters. This Trojan, when installed, will display fake security alerts on your taskbar and install the VirusBursters program on your computer. This infection also loads under the featherweed value in the ShellServiceObjectDelayLoad registry key.
{55667788-ABCD-1234-5678-00C04FD8DBD8} jbloader.dll X Added by the Troj/MMThief-P password-stealing Trojan.
JVM0 JVM0.EXE X Added by the Troj/Banloa-AX downloader Trojan.
Casino Royale jamesbond.exe X Added by the W32/Rbot-FZO worm and IRC backdoor.
JW Manager jwmngr.exe X Added by the W32/Delbot-G worm and IRC backdoor.
Java Runtime Environment jbuild.exe X Added by the W32/Delbot-J worm and IRC backdoor.
Javascript jscript.exe X Added by the W32/Delbot-AD worm and IRC backdoor.
{4bf41072-b2b1-21c1-b5c1-0305f4155515} JK.exe X Added by the W32/RabbitLuv-A worm. W32/RabbitLuv-A spreads by copying itself to network shares.
<not used> jpgstat.dll X Added by the W32/Stration-AN mass-mailing worm.
jpgdiag jpgconf.exe X Added by the W32/Stration-AN mass-mailing worm.
Microsoft Update Machine jkfrnz.exe X Added by the W32/Rbot-GOZ worm and IRC backdoor.
System Juegs.exe X Added by the W32/Culler-C worm that spreads via MSN Messenger.
jx_Key JXKey.dll U Added by the Spyware.Boolospy surveillance software. If this software is installed with your knowledge, you should immediately uninstall it.
vscan joke.vbs X Added by the VBS/Rookie-A Trojan.
Random Name jnnccy04.sys X Added by the Troj/EverDa-E Trojan downloader. The filename may be random.
dns cache reader j<random numbers>.exe X Added by the Troj/TinyDL-J Trojan. Examples file names are j4281830.exe, j3241437.exe, and j1221230.exe.
pnvifj jusodl.exe X Added by the Troj/QQRob-ADM Trojan.
JvcHost jvcsvc32.exe X Added by the W32/Agobot-AIU worm and IRC backdoor.
j1231336 j1231336.dll X Identified by Kaspersky antivirus as the Trojan-Clicker.Win32.Small.mw Trojan.
ColdFusion Graphing Server JRun.exe Y Provides a Java runtime required for Macromedia Generator (cfgraph) support in ColdFusion. More info about about cfgraph can be found here.
ColdFusion Management Repository Server jrun.exe Y Provides Repository Management facilities for the ColdFusion Management Service.
{C01A46D2-5397-4087-90DD-F44F207F7642} jhgfd.dll X Added by the Troj/Agent-FYS Trojan.
{C9E9A340-D1F1-11D0-821E-BIFROST999999} jhost.exe X Added by the Troj/Agent-FZX Trojan.
Windows Service Agccnt jeqcfyo.exe X Added by the W32/Rbot-GST worm and IRC backdoor. The filename is random.
haruspicy jrpkmgh.dll X Added by a Zlob Trojan which installs AntiVirgear 3.7 and displays fake security alerts in your Windows taskbar.
Windows Service Find jpaiwe.exe X Added by the W32/Rbot-GTX worm and IRC backdoor.
jucheck jucheck.exe X Added by the W32.Scrimge.O worm. W32.Scrimge.O is a worm that spreads through Microsoft instant messaging clients and opens a back door on the compromised computer.
j.exe j.exe X Unknown malware.
Java Softe Java32.com X A variant of the Rbot family of worms and IRC backdoor Trojans.
MS Java Applets for Windows NT, ME & XP javaapplets.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Java javasy.dll X A variant of the IRCBot family of worms and IRC backdoor Trojans.
JaguarsScreenServer JaguarsScreenServer.exe N Software from the MercurySports for streaming information about the Jacksonville Jaguars US Football team. Slightly loose Terms or Use and Privacy policy, so make sure you read it when installing.
JaguarsScreenServerSvc JaguarsScreenServer.exe N Software from the MercurySports for streaming information about the Jacksonville Jaguars US Football team. Slightly loose Terms or Use and Privacy policy, so make sure you read it when installing.
jhvod jhvod.dll X Added by the Troj/BDoor-AHN backdoor Trojan.
jetctrl jetctrl.dll X Added by a variant of the MyGeek/CPVFeed adware.
GBB36X Configure JMRaidTool.exe U Raid software for the JMicron JR036X RAID chipsets.
Print Spooler Service jmq.exe X Added by the Troj/Mailbot-CI backdoor Trojan.
Windows Service Ajav java128.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
jecsst jecsst.sys X Identified as a variant of the Backdoor:Win32/Rustock.gen rootkit.
jnhjkfrn jnhjkfrn X Added by the Backdoor.Rustock backdoor rootkit.
wer32 jkghje.dll X Added by the Backdoor.Rustock backdoor rootkit.
JavaCore JavaCore.exe X Identified as a variant of the TrojanDownloader:Win32/Matcash malware.
inoperable jdxah.dll X Zlob Trojan that infects you with the VirusHeat rogue anti-spyware program. Please use the guide below to remove this infection.
jwlbqzpi jwlbqzpi.dll X Added by the Backdoor.Rustock backdoor rootkit.
Java (VM) v6.9 jav.bat X Added by the Troj/Agent-GZK Trojan.
jwzpqng jwzpqng.sys X Added by the Backdoor.Rustock backdoor rootkit.
Java Quick Starter jqs.exe U Java Quick Starter (JQS) improves the initial startup time of Java applets and applications.
dysmenorrhoea jhzpcn.dll X Zlob Trojan which installs the AntiSpyCheck rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install AntiSpyCheck onto your computer without permissions. This Trojan pretends to be a fake video codec required to watch videos online.
jvsoft j3ewro.exe X Added by the WORM_ONLINEG.AFU worm.
Java Java.scr X Added by the TSPY_BANKER.FVU online banking Trojan.
JMB36X IDE Setup JMInsIDE.exe Y Part of the IDE driver for motherboards using the JMB36x chipsets made by JMicron Technology Corporation. This program should not be used on systems newer than Windows XP. For more information about this product, please read the JMicron FAQ for JMB36x.
SunJavaUpdateSched v3.5 javacq.exe X Added by the W32/Prolaco-A worm.
Java VM v6.91 jav.bat X Added by the Troj/DwnLdr-HLL Trojan.
Java VM v6.9.2 jav.bat X Added by the Troj/DwnLdr-HLM Trojan.
SunJavaUpdater javaw.exe X Added by the WORM_MYTOB.QR mass-mailing worm.
Java update javaqs.exe X Added by the WORM_SWARLEY.A P2P worm.
Sun Java Updater v7.11 jucshed.exe X Added by the W32/Autorun-ABH removable media worm.
jaxk jfxk.exe X Added by the Troj/Agent-JKS Trojan.
jwam jwam.exe X Added by the Troj/Agent-JLC Trojan.
Sun Java Updater v5 javajre.exe X Added by the W32/Autorun-XI removable media worm.
Windows Audio Services jvm.exe X Added by the W32.Ackantta.F@mm mass-mailing worm. W32.Ackantta.F@mm is a mass-mailing worm that spreads through removable drives and sends an email that contains an attachment of itself. It may also download potentially malicious files from the Internet.
SunJavaUpdateSched10 jushed.exe X Added by the W32.Ackantta.F@mm mass-mailing worm. W32.Ackantta.F@mm is a mass-mailing worm that spreads through removable drives and sends an email that contains an attachment of itself. It may also download potentially malicious files from the Internet.
SunJavaUpdateSched16 jvshed.exe X Added by the W32.Ackantta.G@mm worm. W32.Ackantta.G@mm is a mass-mailing worm that spreads through file-sharing programs.
Microsoft Driver Setup Jwrb.exe X Added by the W32/AutoRun-AOB removable media worm.
jswtrayutil jswtrayutil.exe ?

This file is the tray utility of the Jumpstart wireless software made by Atheros Communications, Inc. that comes bundled with some Toshiba laptops.

SunJavaUpdateSched132 jschd.exe X Added by the W32/AutoRun-AQY removable media worm.
javawsa.exe javawsa.exe X Added by the Troj/Bank-Y Trojan.
Java developer Script Browse jusched.exe X Added by the Troj/VB-ESK Trojan.
RunJava jcview.exe X Added by the W32/AutoRun-BEL removable media worm.
Java Update Manager jutched.exe X Added by the Mal/FkPhoto-A malware.
SunJavaUpdateSched9 jusched.exe X Added by the Troj/Lolbot-A Trojan.
juzched juzched.exe X Added by the Troj/Zlob-ATO Trojan.
king_jp jpking.exe X Added by the Troj/Agent-POO Trojan.
Microsoft Config Setup jodrive32.exe X Added by the Troj/Backdr-EY Trojan.
Java auto-updater javaw.exe X Added by the Troj/Agent-RUT Trojan.
Windows Defender javacp.exe X Added by the Troj/VB-FLZ Trojan.
SunJavaUpdater v2 javaw.exe X Identified by Kaspersky Antivirus as a variant of the Trojan-Dropper.Win32.Agent.aefe malware.
Java Runtime Update Java Update.exe X Unknown malware
SunUpdater javacpl.exe X Identified by Kaspersky Antivirus as a variant of the Trojan.Win32.Buzus.agev malware.
JmiNET3 jminet7.sys X Added by the RTKT_DUQU.A rootkit.
Java(TM)Update.exe Java(TM)Update.exe X Added by the Mal/VB-TS malware.
Search Startups

Login

Remember Me
Sign in anonymously