View all database entries

ALL  PP  F0  F1  F2  F3  R0  R1  N1  N2  N3  N4  O1  O2  O3  O4  O5  O6  O7  O8  
O9  O10  O11  O12  O13  O14  O15  O16  O17  O18  O19  O20  O21  O22  O23  CHR  FF  

View MDO database (O4)

Showing entries 76 to 100 of 167.

Go directly to page: 1  2  3  4  5  6  7  

(X) O4 - HKLM\..\Run: [farkle-checkrun] c:\winnt\system32\eliteljt32.exe
EliteBarToolBar Program.
Fix / Info: Download miekiemoes' LQfix batch removal tool.
http://www.spywareguide.com/product_show.php?id=1124
Windows ALL; discovered by nasdaq
(L) O4 - HKLM\..\Run: [FileZilla Server Interface] "C:\Program Files\FileZilla Server\FileZilla Server Interface.exe"
Related to FileZilla Server FTP server - from the Open Source Technology Group.
http://sourceforge.net/projects/filezilla/
Windows ALL; discovered by nasdaq
(X) O4 - HKLM\..\Run: [foefzi] c:\windows\system32\nkohpc.exe
The Nail.exe (Aurora/abetterinternet/Transponder) infection
Fix / Info: Hjt - run this removal tool - http://www.ewido.net/en/download/
Windows ALL; discovered by nasdaq
(X) O4 - HKLM\..\Run: [hgfedcba] c:\windows\system32\hgfedcba.exe /install
Uncategorized malware threat process. Contains missing/deceptive version information and no company information.
Fix / Info: HijackThis - AdAware tool
http://www.superadblocker.com/H/HGFEDCBA.EXE-4718.html
Windows ALL; discovered by nasdaq
(L) O4 - HKLM\..\Run: [HyperappelPL] C:\Program Files\Larousse\Petit Larousse 2005\bin\HIPL2002Popup.exe
French Larousse dictionary.
Windows ALL; discovered by nasdaq
(L) O4 - HKLM\..\Run: [IMAQBoot] C:\Program Files\National Instruments\NI-IMAQ\bin\ImaqBoot.exe
Related to National Instruments Corp.
http://www.ni.com/
Windows ALL; discovered by nasdaq
(L) O4 - HKLM\..\Run: [IMSCMIG40W] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40W\IMSCMIG.EXE /SetPreload /Log
Microsoft Pinyin IME Installer
http://www.superadblocker.com/I/IMSCMIG.EXE-3554.html
Windows ALL; discovered by nasdaq
(L) O4 - HKLM\..\Run: [IMWEBSTA.EXE] IMWEBSTA.EXE START
Intel High Rate Wireless LAN Settings application for 802.11b wireless cards.
http://www.what-process.com/process-info.aspx?p=IMWEBSTA.exe
Windows ALL; discovered by Nasdaq
(L) O4 - HKLM\..\Run: [InkSaver] C:\Program Files\InkSaver\InkSaver.exe hide
Related to Software Imaging Limited.
http://softwareimaging.com/index.html
Windows ALL; discovered by nasdaq
(L) O4 - HKLM\..\Run: [iPCCheck] "C:\Program Files\iPass\iPassConnect\downloader\ipccheck.exe" /startup
Related to Ipass Inc.
http://www.ipass.com/
Windows ALL; discovered by nasdaq
(X) O4 - HKLM\..\Run: [iWon Messenger Pipe] C:\Program Files\iWon\Messenger\bin\i1IMPipe.exe
Iwon Malware.
Fix / Info: Hijackthis
http://www.systemlookup.com/search.php?type=name&client=malwaresearch-chrome&search=iWon
Windows ALL; discovered by nasdaq
(X) O4 - HKLM\..\Run: [jnrcfwvah] C:\WINDOWS\SYSTEM\tgmzart.exe
Google reports many references with [random name] service key.
Fix / Info: HijackThis, delete file, AwAware tool
Windows ALL; discovered by nasdaq
(L) O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
Lexmark printer driver.
Windows ALL; discovered by nasdaq
(L) O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
Lexmark printer driver.
Windows ALL; discovered by nasdaq
(X) O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "c:\documents and settings\all users\_qbothome\_qbotinj.exe"
Added by the Troj/Dloadr-BLP TROJAN!
Fix / Info: Hijackthis
http://www.bleepingcomputer.com/startups/_qbotinj.exe-22966.html
Windows ALL; discovered by nasdaq
(U) O4 - HKLM\..\Run: [MacroVirus] C:\Program Files\MacroVirus\MacroVirus.exe -boot
Free version will not fix any problems, $20.00 to buy
Fix / Info: NA
Virustotal clean-MD5: c09b6aedd859d51a5706c6a359f810dc -Mar07
Windows ALL; discovered by Basementgeek
(U) O4 - HKLM\..\Run: [Microsoft WebServer] C:\Program Files\WebSvr\System\svctrl /init
Personal web server program which enables you to create and host a web server from your computer. Not required for most people
http://www.bleepingcomputer.com/startups/svctrl.exe-3077.html
Windows ALL; discovered by Nasdaq
(L) O4 - HKLM\..\Run: [Microtek_Scanner_Server] C:\Program Files\Microtek\ScanWizard Pro\LANServer.exe
Related to Microtek International, Inc.
http://www.microtek.com/
Windows ALL; discovered by Nasdaq
(L) O4 - HKLM\..\Run: [Modem Update Reminder] C:\WINNT\MWW32\manager\mwremind.exe autorun
Related to IBM ThinkPad modem.
Windows ALL; discovered by nasdaq
(L) O4 - HKLM\..\Run: [NNTray] C:\Program Files\Net Nanny\nnstart.exe
Related to net-nanny protection software for the kids.
http://www.net-nanny-software.com/
Windows ALL; discovered by Nasdaq
(X) O4 - HKLM\..\Run: [NUB] C:\WINNT\NUB.exe
Virus - trojan.
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100930
Windows ALL; discovered by nasdaq
(L) O4 - HKLM\..\Run: [Panda Controller Client] "C:\Program Files\Panda Software\AVNT\PSCtrlC.exe"
Related to Panda security Software
http://www.pandasoftware.com/
Windows ALL; discovered by Nasdaq
(L) O4 - HKLM\..\Run: [PD6000StatusMonitor] C:\WINDOWS\System32\PD6000SM.EXE
Related to : B & C Data Systems
Fix / Info: n/a
http://bcdata.com/pd6000.html
Windows ALL; discovered by nasdaq
(L) O4 - HKLM\..\Run: [Perfect Process shield] C:\Programme\Perfect Process\ppshield.exe
Perfect Process shield is designed to run silently in the background. Catching hostile Programs & processes in Memory and in the startup.
http://www.veloci.dk/index.asp?visnu=ppdownl.htm
Windows ALL; discovered by nasdaq
(L) O4 - HKLM\..\Run: [PopUpInspector.exe] "C:\Program Files\GIANT Company Software inc\PopUp Inspector\PopUpInspector.exe"
Related to GIANT Company Software (Now Microsoft)
http://www.giantcompany.com/
Windows ALL; discovered by nasdaq

This is a list of items that is designed to help with the analysis of HijackThis, DDS, OTL and FRST logs.
It is by no means exhaustive (in fact it is being added to all the time), and is intended to complement other legitimate online lists.