Information and startup locations can be examined on this page: verify all your files to make sure that they are legitimate, digitally signed and from the company Microsoft Corporation to which they should belong.
mdm.exe security and file info
Machine Debug Manager
- Microsoft® Visual Studio .NET
- Microsoft Corporation
 |
 |
 |
| Filetype : executable |
An executable file is a program that can be executed in your windows environment.
|
|
What is mdm.exe?
Mdm.exe is the Windows Machine Debug Manager. It is used for debugging scripts in Internet Explorer, as well as debugging code in Microsoft Visual Studio and other Microsoft development environments.
This process is a nonessential process and can safely be killed and disabled. By killing the machine debug manager, however, you will lose the ability to debug scripts in Internet Explorer. The screenshot below illustrates how this process should appear in the task manager:

In the above screenshot, mdm.exe is running as the current user (Mike); however, it can be run as any user.
Dangers of mdm
As this is a relatively common legitimate process with a cryptic name, it is common for virus writers and spyware vendors to disguise their malware as the genuine one.
Some malicious files will have the same name but will be stored somewhere other than in %SystemRoot%\System32. Other malware will use a name that appears similar to it but with slight differences in spelling or with appended digits. The following malware is known to disguise itself as mdm.exe:
- W32.Sdbot.APE (%SystemRoot%)
- Sdbot is an IRC backdoor Trojan that spreads via common buffer overlow vulnerabilities.
- W32.Unubot.B (%SystemRoot%)
- This is an IRC backdoor Trojan that allows a remote attacker to take over an infected system.
- W32.Bckdr-QJR (%SystemRoot%)
- This is an IRC backdoor Trojan that allows a remote attacker to take over an infected system.
- W32.Agobot.AQ (%SystemRoot%\System32\mdm32.exe)
- W32.Rbot.AIJ (%SystemRoot%\System32\mdm32.exe)
There is often only one instance of this process running at a given time; however, the presence of multiple instances is not necessarily an indicator of a malware infection.
Common problems
- You are prompted to debug when browsing some web pages
- This is normal behavior. If you do not do any debugging, you can safely uninstall the Machine Debug Manager.
- This process uses 100% CPU time
- According to Microsoft, this is a known issue. Kill any instances of mdm.exe and delete all TMP files from your Windows directory.
- If the problem persists, it is safe to uninstall or kill the Machine Debug Manager.
|
|
|
|
|
|
| MD5 File security rating |
A MD5 hash is a unique fingerprint of a file.
Different files/versions can have the same filenames. The MD5 hash verifies that the legitimate file is not altered.
Runscanner (Freeware) can help you checking the file's MD5 hashes
| Mdm.exe files in Runscanner database |
 |
|
1147 different item(s) in database |
 |
|
1 different item(s) in database |
 |
|
4 different item(s) in database |
 |
|
8 different item(s) in database |
|
 |
Green items are verified safe to use |
 |
Unrated items are not yet checked for safety. |
 |
Red items are not safe (typically virusses, spyware or other malware) |
 |
This file is digitally signed by it's publisher.
This means that the file is from the company claiming to created it, this does not mean by default that the file is safe
|
|
|
|
| General file info |
| Product name: |
Microsoft® Visual Studio .NET
|
| Description: |
Machine Debug Manager
|
| Company: |
Microsoft Corporation
|
| Fix MDM.EXE errors: Free registry scan |
|
|
|
| Pacman startup database |
|
Added by the IRCBOT.AKZ WORM! |
|
Added by the LCJUMP-A WORM! Note - this is not the valid Machine Debug Manager which shares the same filename |
|
Added by the PROXY-GG TROJAN! |
| info provided by sysinfo.org |
|
|
|
Automatic startup locations
 |
| |
 |
001 Running Processes |
| |
 |
002 Autorun registry entries local machine |
| |
 |
003 Autorun registry entries Current User |
| |
 |
008 Autorun registry entries Default user |
| |
 |
009 Autorun registry entries SYSTEM user |
| |
 |
010 Installed services |
User comments for this file
 |
Microsoft Visual Studio |
 |
This was installed when I installed Office 2003. It is part of the Microsoft Script Editor installation. More info can be found at http://support.microsoft.com/kb/321410/en-us |
|
|
|
More system processes
|
|
| Filename / Process |
|
| Guid / CLSID |
|
| MD5 hash |
|
|
|
1160 MD5 version(s) found
only top 10 displayed
|
|
|
| Check your autostart files
|
|
|
|