Jump to content

Tarun

Experienced Members
  • Posts

    2,122
  • Joined

  • Last visited

Posts posted by Tarun

  1. O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

    ^^ This item is safe to remove using HJT, and usually won't come back, unless you get another 'serious error' from Windows to report.

     

     

     

    Right click My Computer, Properties, Advanced , Startup and Recovery Settings, Uncheck "Write an event to the system log".

     

    I'd like Dj to verify that though. ;)

  2. May i ask why Tarun, iv never heard of removing the reg entries causing problems  :rolleyes:  (but they say you learn something everyday  :D  )

     

    --lee

     

     

     

    That's something I'm going to have to ask DjLizard.

     

    do not ever use msconfig to disable services, only use services.msc (start, run, services.msc). and for some services, it is better to use standard UI to disable them instead of using services.msc, such as with System Restore (only disable it through My Computer-> Properties)

     

    Though that was for services, it's still a good question.

  3. Hi steve,

     

    In addition to what Tarun analyzer has said (i'm impressed with that analyzer Tarun  ;) ), its safe to remove these as they slow down boot up,

    This just creates logs of errors, and can only help you if you can read the logs it creates:

     

    O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

     

    This just starts up MSN Messenger every boot up, it can still be started via the icon though:

     

    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

    BTW, the latest MSN Messenger is MSN 7, you can get it from here: http://imagine-msn.com/messenger/en-us/  (click "Get it now")

     

    --lee

     

     

     

    It's better to disable those via GUI, thus why I left them alone until his next reply. ;)

  4. Enumeration of existing IE's BHO's. Safe to remove:

    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

     

    Enumeration of suspicious auto-loading registry entries. Safe to remove:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

     

    Extra 'Tools' menu items and buttons. Safe to remove:

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\PROGRA~1\Agnitum\OUTPOS~1\TRASH.EXE (HKCU)

    O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\PROGRA~1\Agnitum\OUTPOS~1\TRASH.EXE (HKCU)

     

    Download Program Files item. Safe to remove:

    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

    O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...463/mcfscan.cab

     

    Domain hijack, safe to remove. Safe to remove:

    O17 - HKLM\System\CCS\Services\Tcpip\..\{4F2A6F5F-8BAF-4972-ABC6-DA099E47B685}: NameServer = 202.188.0.133 202.188.1.5

     

    Look into Real Alternative if you haven't already. ;)

  5. I did a scan several times with spybot S&D & even tried couple of times on reboot.

     

    There are items unable to be removed:-

     

    My Soft

    Redirect host

    desktop.kazaa.com=127.0.0.1

     

    another one

     

    Log

    Activity.SchedLgu.Txt

    C:\Windows|SchedLgu.Txt

     

    Please guide me how to remove the above.

     

    Thanks

     

    Steve

     

     

     

    The log you don't need to worry about. As for the redirect host, where did Spybot say it's located?

     

    If I was you I would download and run Ad-Aware also. Ad aware covers the other problems that SpyBot doesn't. Also while you are at it, download and run SpywareBlaster. It runs in the background and stops items BEFORE they get to your computer.

     

     

     

     

    I do believe he has all of those applications already. Ad-Aware can get pieces Spybot misses, and Spybot can get pieces Ad-Aware misses. Just one Anti-Malware utility is never enough.

  6. Tarun u post 500 so fast!!! I see u changed ur member title to Power Member

     

     

     

    It auto changed on me. Post 501 unlocked the title change ability.

     

    Having that many posts on such a small forum is a great thing. But a bad thing would be if it was all spam, I hate spam. Thankfully the majority is helping people. Keep it up Tarun! B)

     

     

     

    Gotta try and help people, otherwise it's no fun!

     

    This entire thread is spam.

     

     

     

    Well aren't you just a such a happy person! ;D

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.