PDA

View Full Version : Mysterious MSCONFIG entry...


Über~PhLuBB
12-19-01, 06:37 PM
What the sam hill IS this? In Reg Edit, it says "KernelFaultCheck".

Kingslayer
12-19-01, 08:38 PM
It's either one of two things. A virus or part of the NT Kernel file protection.

Can you copy the entire text for all sections of that entry and put it in your reply to this? That would help tremendously.

Über~PhLuBB
12-19-01, 09:21 PM
Certainly, this is under HKEY_L_M\Software\Microsoft\Windows\Current Version\Run

There is nothing in any of the other Run folders (RunOnce, RunServices, etc) in either this tree, or HKEY_C_U.

Given the lack of a file location (I.E., C:\Windows\whatever), I'm going to guess that it is indeed part of the OS, a standard command.

With that realization, what is this for? Can I remove it? What are the reprocussions?

Yodums
12-19-01, 09:43 PM
Originally posted by Über~PhLuBB
Certainly, this is under HKEY_L_M\Software\Microsoft\Windows\Current Version\Run

There is nothing in any of the other Run folders (RunOnce, RunServices, etc) in either this tree, or HKEY_C_U.

Given the lack of a file location (I.E., C:\Windows\whatever), I'm going to guess that it is indeed part of the OS, a standard command.

With that realization, what is this for? Can I remove it? What are the reprocussions?

I don't think you should it seems like it is part of the Windows Kernal platform and it has something to do with it.

blebs99
12-20-01, 03:13 AM
My guess is that between Kazaa, Newdotnet,webhancer, gator, save now or one of the other things, needs to use it to keep from crashing the Kernel Driver.
There is a lot of spyware listed, some alter .dll files and winsock.

trapper
12-20-01, 04:17 AM
yeah i found a vey similar thing in MSCONFIG but killed it on sight but i see morpheus getting a mention as maybe culprit an i do have a bit spyware (free rip mp3-virtuagirl-morpheus) an it still works mind you i dont get that advert at the bottom of morpheus anymore it always says PAGE UNAVAILABLE or sumfink like that
kill it now!!!an see wot goes surely it can at the worst mean a proggy re-install:burn:

Über~PhLuBB
12-20-01, 04:25 AM
Well, RUNDLL32 is my nVidia clock settings (coolbits).

winFAH is, duh, Folding@Home.

iTouch is for my Logitech keyboard, so's I can use all them nifty one-touch buttons.

AVGCC32 is AVG Anti Virus.

AIM is AOL Instant Messenger

Kazaa was from 5 minutes of use of Kazaa (The uninstall must have missed the startup entry, and now I can't remove it, it's not in RegEdit).

NEWDOT~02, I don't know what that is, hence it being disabled.

SaveNow, again, I don't know.

whAgent is WinHancer Agent, it's a spyware thing that game with Audio Galaxy I think. It, too, is disabled.

Adobe Gamma Loader is self explainitory.

trapper
12-20-01, 04:43 AM
hey tell it to the spyware judge (LOL)