| Name | Status | Filename | Description |
|---|
| 00DSKSVR00 | N | desksaver.exe | Related to Advanced_Desktop_Shield |
| 00DSKSVR01 | N | desksaver.exe | Related to Advanced_Desktop_Shield |
| 00ERSRRRNKY | U | eraser.exe | Related to Evidence_Exterminator from Softstack.com Allows for complete removal of data from your hard drive. Note: Located in \%Program Files%\Evidence Exterminator\ More here |
| 00ERSRRRNKY | U | erasrv.exe | Related to Evidence_Exterminator from Softstack.com Allows for complete removal of data from your hard drive. Note: Located in \%Program Files%\Evidence Exterminator\ More here |
| 00PCTFW | Y | FirewallGUI.exe | Related to PC_Tools Firewall. Note: Located in \%Program Files%\PC Tools Firewall Plus\ |
| 00TCrdMain | Y | TCrdMain.exe | Related to flash_card slot on the Toshiba laptop. Ending this process will disable access to the flash cards. Note: located in %ProgramFiles%\TOSHIBA\FlashCards\ |
| 00THotkey | U | 00THotKey.exe | For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev. |
| 00THotkey | U | system32THotkey.exe | For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev. |
| 0190 Warner | U | WARN0190.EXE | Anti-dialer program (Germany) |
| 0900 Warner | U | WARN0900.EXE | Anti-dialer program (Germany) |
| 0mcamcap | X | 0mcamcap.exe | Added by Troj/Cosiam-H TROJAN! Prevx identifies it has Haxdoor Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| 0utlook Express | X | *****.exe (where * = random char) | Added by the W32/RBOT-CC WORM! |
| 1 | X | 1.exe | Added by the ESTEEMS TROJAN! |
| 1 | X | svchost.scr | Added by PWSteal.Bancos.X Trojan. Read the link, keylogger/password stealing TROJAN(S) involved.
|
| 1 | X | lsass.scr | Added by the PWSteal.Bancos.V TROJAN! Read the link, keylogger/password stealing TROJAN(S) involved.
|
| 1&1 EasyLogin | U | EasyLogin.exe | Related to 1&1_EasyLogin an Internet Provider. Note: Located in \%Program Files%\1&1\1&1 EasyLogin\ |
| 101Clips | U | 101Clips.exe | Related to 101Clips 101 is the simplest of all multi-clipboard programs. Just have it running minimized and it captures everything you cut or copy from other programs. Note: Located in \%Program Files%\101 Clips\ |
| 1029BB4B-16A9-4E77-AA3D-96930BD68EEC | X | sysockeu.exe | Added by the SmitFraud Trojan |
| 108Mbps Wireless LAN Adapte | U | TRENDnet.exe | Related to TRENDnet Wireless LAN Adapter. Note: Located in \%Program Files%\TRENDnet\Model number\ |
| 11 | X | faxcomdos.exe | Added by the Tuimer TROJAN! |
| 1111swapmgr.exe | X | 1111swapmgr.exe | Added by the BDOOR-IC TROJAN! |
| 123456 | X | rundll32.exe shell32.dll, Control_RunDLL ...123456.cpl | Added by the KITRO.C (or DANDI.A) VIRUS! 123456 can be any random 3 to 6 digit number |
| 1234567 | X | svcost.exe | Added by the Backdoor.Bifrose.YA family of trojan. Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) |
| 1234klsjdc uiar924c af | X | sxgnsvuxct.exe | Added by the Smitfraud Trojan |
| 1290A33C-85F5-4164-A1BE-7DD299D4986A | U | PBKScheduler.exe | Scheduler for CyberLink PowerBackup - archiving/backup utility |