| Type |
Caption |
Section |
File name |
Description |
 |
tour |
|
regedit ..tour.reg |
Edits registry values to keep the WinMe tour in Task Scheduler |
 |
tourpath |
|
regedit /s [path] tour.reg |
Edits registry values to keep the Win 2000 "tour" in Task Scheduler |
 |
DJREGFIX |
|
regedit /s c:\hpdjregfix.reg |
DJRegFix showed up first in WinME as a "clever" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This "utility" adds the functionality and compatibility HP forgot to add in its WinME drivers |
 |
sys |
|
regedit /s sys.reg |
Hijacker |
 |
@ |
|
regedit -s ..win.dll |
Added by the SEEKER.K TROJAN! Read more |
 |
win |
|
regedit -s ..win.dll |
Read more |
 |
spp |
|
regedit -s spp.reg |
IE search hijacker - changes the default search to http://www.hotsearchbox.com/ie/ |
 |
system |
|
regedit -s system.dll |
Homepage hijacker |
 |
NeroCheck |
|
regedit.exe |
Added by the DOOMJUICE.B WORM! Note - this is not the valid Ahead Nero CD burning program. Also it is not the valid Windows registry editor which resides in C:\Windows or C:\Winnt wheras this version resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP) Read more |
 |
regedit |
|
regedit.exe |
Added by the BRID.A WORM! Note - resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP). The valid "regedit.exe" resides in C:\Windows (Win9x/Me/XP) or C:\Winnt (WinNT/2K) Read more |
 |
Registry Editor |
|
regedit.exe |
Added by the W32/Codbot-U backdoor Trojan. Read more |
 |
System Registry Settings |
|
regedit.exe |
Added by the W32/Rbot-WL WORM/backdoor Trojan and allows unauthorised remote access to infected computers via the IRC network. Read more |
 |
Data789 |
|
Regedit.exe ....data789.tmp |
Homepage hijacker |
 |
Internal |
|
regedit.exe /s %windir%c:\[month number] |
Added by the FORTNIGHT.D TROJAN! Read more |
 |
PowerSet |
|
Regedit.exe /s ...PowerSet_8100_CU.REG |
Appears to be Toshiba power management related |
 |
OPQFile |
|
regedit.exe /s ...rad03FA6.tmp |
Unsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit |
 |
SysSearch |
|
Regedit.exe -s [path] pcsearch.reg |
Added by the StartPage-FN browser hijacker Read more |
 |
SysSearch |
|
REGEDIT.EXE -s [path] sysreg.reg |
Added by the STARTPA-ME TROJAN! Read more |
 |
setupuser |
|
regedit.exe setupuser.log |
Regfile in disguise - another CoolWebSearch parasite variant Read more |
 |
RegEdit32 |
|
RegEdit32.exe |
Added by the W32/Voumit-A P2P worm. Read more |
 |
Service Registry NT Save |
|
regeditnt.exe |
Added by Troj/Bancos-BM TROJAN to steal passwords and download code from websites. Read more |