View all database entries

ALL  PP  F0  F1  F2  F3  R0  R1  N1  N2  N3  N4  O1  O2  O3  O4  O5  O6  O7  O8  
O9  O10  O11  O12  O13  O14  O15  O16  O17  O18  O19  O20  O21  O22  O23  CHR  FF  

View MDO database (R1)

Showing entries 326 to 350 of 1011.

Go directly to page: 1  7  8  9  10  11  12  13  14  15  16  17  18  19  20  21  41

(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.quicknavigate.com/search.php?qq=%1
Smitfraud family of trojans
Fix / Info: Fix if you have access: http://spywareinfoforum.com/index.php?act=ST&f=6&t=45833&st=15
http://www.sophos.com/virusinfo/analyses/trojpupere.html
Windows ALL; discovered by Nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.searchmaid.com/search.php?qq=%s
Searchmaid hijacker
Fix / Info: HijackThis
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.security2k.net/search.php?qq=%1
Blocked by the HOSTS file. See URL
Fix / Info: HijackThis
http://www.mvps.org/winhelp2002/hosts.htm
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.startsearches.net/search.php?qq=%1
Related to the new Smitfraud family of trojans
Fix / Info: Removal see Topic below
http://spywareinfoforum.com/index.php?act=ST&f=6&t=45833&st=15
Windows ALL; discovered by Nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.updatesearches.com/search.php?qq=%1
SmitFraud family of trojan.
Fix / Info: See fix at the suggested URL
http://spywareinfoforum.com/index.php?act=ST&f=6&t=45833
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http:://www.quicknavigate.com/search.php?qq=%1
Smitfraud / Quicknavigate / VirtualMaid
Fix / Info: Various tools; please see InfoURL
http://www.bleepingcomputer.com/forums/How_to_remove_the_Smitfraud_Quicknavigate_VirtualMaid-t17258.html
Windows ALL; discovered by Angoid
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
Adware-WinActive
Fix / Info: HijackThis - AdAware tool
http://vil.nai.com/vil/content/v_125025.htm
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.hotmail.com
Set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://home.excite.com
Set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
Set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.sky.com
set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = res://shdoclc.dll/softAdmin.htm
Set by user
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP
Adware.Raxums - Found also with the Smithfraud infection.
Fix / Info: HijackThis
http://www.symantec.com/avcenter/venc/data/pf/adware.raxums.html
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
CWS SE dll infection
Fix / Info: See fix at the suggested URL
http://spywareinfoforum.com/index.php?act=ST&f=6&t=48493
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = C:\Program Files\Copernic 2000 Pro\Search Bar.htm
Set by user
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\sb.htm
Related to IEDriver ADWARE! variant.
Fix / Info: HijackThis
http://www.symantec.com/security_response/writeup.jsp?docid=2004-012411-3821-99&tabid=2
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = h**p://google.icq.com/search/search_frame.php
set by user
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://103.nowfind.biz/pps.php
blocked by this hosts file. Adware NowFind.
Fix / Info: HijackThis, AwAware tool
http://www.mvps.org/winhelp2002/hosts.htm
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://69.50.182.88/?qq=
Trojan.Magise
Fix / Info: HJT and Virus/trojan removal programs.
http://www.sarc.com/avcenter/venc/data/pf/trojan.magise.html
Windows ALL; discovered by Nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://balabolka.biz/start.html
Blocked by the HOSTS file. See URL
Fix / Info: HijackThis
http://www.mvps.org/winhelp2002/hosts.htm
Windows ALL; discovered by nasdaq
(O) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com...de_srchlft.html
Now owned by Ask.com
http://vil.mcafeesecurity.com/vil/content/v_134251.htm
Windows ALL; discovered by nasdaq
(O) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
Now owned by Ask.com
http://vil.mcafeesecurity.com/vil/content/v_134251.htm
Windows ALL; discovered by Nasdaq
(U) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.a....0&bm=ho_search
Set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
Set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://dellsearchedi...ebar.jhtml?p=DW
Set by user
Windows ALL; discovered by nasdaq

This is a list of items that is designed to help with the analysis of HijackThis, DDS, OTL and FRST logs.
It is by no means exhaustive (in fact it is being added to all the time), and is intended to complement other legitimate online lists.