View all database entries

ALL  PP  F0  F1  F2  F3  R0  R1  N1  N2  N3  N4  O1  O2  O3  O4  O5  O6  O7  O8  
O9  O10  O11  O12  O13  O14  O15  O16  O17  O18  O19  O20  O21  O22  O23  CHR  FF  

View MDO database (ALL)

Showing entries 16326 to 16350 of 18323.

Go directly to page: 1  647  648  649  650  651  652  653  654  655  656  657  658  659  660  661  733

(X) R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchmaid.com/search.php?qq=%s
Searchmaid hijacker
Fix / Info: HijackThis, delete file,
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.security2k.net/search.php?qq=%1
Blocked by the HOSTS file. See URL
Fix / Info: HijackThis
http://www.mvps.org/winhelp2002/hosts.htm
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.startsearches.net/search.php?qq=%1
Related to Secretmaker tool.
Fix / Info: Removal see Topic below
http://spywareinfoforum.com/index.php?act=ST&f=6&t=45833&st=15
Windows ALL; discovered by Nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.updatesearches.com/search.php?qq=%1
Smitfraud family of trojans
Fix / Info: Fix if you have access: http://spywareinfoforum.com/index.php?act=ST&f=6&t=45833&st=15
http://www.sophos.com/virusinfo/analyses/trojpupere.html
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
Related to Spyware ShopNav as reported in this host file http://www.mvps.org/winhelp2002/hosts.htm
Fix / Info: HijackThis
http://www.doxdesk.com/parasite/ShopNav.html
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.shopnav.com/q.cgi?q=
ShopNav Malware.
Fix / Info: HijackThis, AwAware tool
http://www.doxdesk.com/parasite/ShopNav.html
Windows ALL; discovered by Nasdaq
(U) R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = www.dogpile.com
Set by user
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = www.searchant.com/r=6&s=%s
Blocked by the HOSTS file. See URL
Fix / Info: HijackThis
http://www.mvps.org/winhelp2002/hosts.htm
Windows ALL; discovered by nasdaq
(X) R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://s-redirect.com/?a=2&b=n-glx-2
CoolWebSearch variant
Fix / Info: Cwshredder tool
http://xblock.com/product_show.php?id=930
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\nternet Explorer\Main,Search Bar = res://C:Program FilesCopernic AgentCopernicAgentExt.dll/INTEGRATION_BAND_SEARCHBAR_HTML
Set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\WindowsCurrentVersion\Internet Settings,AutoConfigURL = file://C:/program files/neopets/HSClient/proxy.pac
Set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\WindowsCurrentVersion\Internet Settings,ProxyOverride = local;localhost
Set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\WindowsCurrentVersion\Internet Settings,ProxyOverride = localhost
Set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://D:/My DownloadsC/Streamy4_0/workspace/.metadata/.plugins/com.migniot.streamy.Browser/proxy.pac
Set by user
http://www.migniot.com/matrix/projects/streamy/
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://inet-pac.sabr...sabre-proxy.pac
set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://stlkc1svwsus....net/pacfile.pac
set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = www.comcast.net
Set by user
Windows ALL; discovered by nasdaq
(Q) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
indicates that Internet Explorer will not use the proxy for all internal network addresses.
Windows ALL; discovered by nasdaq
(Q) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
Could be related to malware
Fix / Info: Fix only if you find traces of MySpace/FaceBook worm on the log. Read the link.
http://miekiemoes.blogspot.com/2008/10/myspacefacebook-worm-causes-confusion.html
Windows ALL; discovered by nasdaq
(Q) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
Check if required. Could be associated with a Rogue Fakealert infection
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;
Set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
Set by user
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
Do not remove.
Windows ALL; discovered by nasdaq
(U) R1 - HKCU\Software\Microsof\Internet Connection Wizard,ShellNext = http://qca10.hpwis.com/
Set by user
Windows ALL; discovered by nasdaq
(X) R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://103.nowfind.biz/pps.php
blocked by this hosts file. Adware NowFind.
Fix / Info: HijackThis, AwAware tool
http://www.mvps.org/winhelp2002/hosts.htm
Windows ALL; discovered by nasdaq

This is a list of items that is designed to help with the analysis of HijackThis, DDS, OTL and FRST logs.
It is by no means exhaustive (in fact it is being added to all the time), and is intended to complement other legitimate online lists.