kernel fault check: Not Malware
Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out.
You could also have HJT fix the entry. HJT log looks clean. Let me know if you have any other questions.
thanks for your quick response to my queries. I followed the instructions you gave me but when i restarted my computer, kernel fault check was still present in my HJT log even though i have fixed it…i also tried to delete the kernel fault check using regedit but it always comes back…Even though this is not malware i am very bothered because it always appears at startup and is somehow suspicious…thanks for giving attention to my problem and more power to you
Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on this:
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
Then close all windows except this one and press Fix checked.
good day,yes i have used HJT to fix the problem but it always comes back everytime i restart my computer..this day i have installed Ad-Aware SE Personal and Spybot - Search & Destroy, and the programs found and removed a keylogger..but even though the keylogger was removed, kernel fault check still keeps coming back…to be more secure i also installed Zone Alarm firewall but i am still bothered by kernel fault check entry in my HJT log and i also see it when i go to msconfig…even when untick it in msconfig it always comes back even if i fix it using HJT…i hope you could help me with my problem because i think that it is unusual…thanks and Godbless!
Hmm…that is interesting
Which program found the keylogger? Spybot or Adaware, or both? Do you have any information from them as to what it was? And are you sure it was removed?
Sorry, a lot of questions but it is interesting and worth looking into.
Dave
the keylogger was found by both programs and it was auto-quarantined by Ad-Aware. here is the auto-quarantine log from Ad-Aware:
ArchiveData(auto-quarantine- 2007-04-04 16-26-31.bckp)
Referencefile : SE1R148 29.01.2007
======================================================
H@TKEYSH@@K
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=File : C:\WINDOWS\system32\h@tkeysh@@k.dll
i think that my computer is infected by a rootkit because i've heard that rootkits have the ablility to avoid detection…my zone alarm firewall says that 25 intrusion attempts have been blocked and three of them are high-rated.i have just installed zone alarm last hour. Is there a possibility that my pc is infected by a rootkit?
Download and Save blacklight to your desktop.
F-Secure Blacklight: https://europe.f-secure.com/blacklight/try.shtml
Double-click blbeta.exe then accept the agreement.
click > scan then > next,
You'll see a list of all items found.
Don't choose for rename yet! I want to see the log first, because legit items can also be present there…
There must be also a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers)
Post the contents of the log in your next reply.
ok, i've downloaded and installed blacklight but it didn't find any problems,here is the log:
04/05/07 00:28:46 [Info]: BlackLight Engine 1.0.61 initialized
04/05/07 00:28:46 [Info]: OS: 5.1 build 2600 (Service Pack 2)
04/05/07 00:28:47 [Note]: 7019 4
04/05/07 00:28:47 [Note]: 7005 0
04/05/07 00:28:53 [Note]: 7006 0
04/05/07 00:28:53 [Note]: 7011 1248
04/05/07 00:28:53 [Note]: 7026 0
04/05/07 00:28:54 [Note]: 7026 0
04/05/07 00:28:59 [Note]: FSRAW library version 1.7.1021
04/05/07 00:34:56 [Note]: 7007 0
i also used Helios lite but it also didn't detect any problems, but i found some suspicious looking registry items in the scan result:
1, SOFTWARE\Microsoft\Cryptography\RNG, Seed, Data Differs
2, SECURITY\Policy\Secrets\SAC, , Access Denied
3, SECURITY\Policy\Secrets\SAI, , Access Denied
4, .DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon, ParseAutoexec, Data Differs
5, S-1-5-21-527237240-1993962763-1202660629-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count, HRZR_EHACNGU, Data Differs
6, S-1-5-21-527237240-1993962763-1202660629-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count, HRZR_HVFPHG, Data Differs
7, S-1-5-21-527237240-1993962763-1202660629-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count, HRZR_EHACNGU:P:\Qbphzragf naq Frggvatf\Qntnzv Snzvyl\Qrfxgbc\Uryvbf Yvgr.rkr, Data Differs
i also found some suspicous improperly terminated processes:
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\dumprep.exe
i hope this can somehow help you in analyzing my problem
good day, i found out that i got the keylogger from a trainer that i used recently, and i was surprised that i was able to prevent kernel fault check from running at startup simply by unticking it (unlike before) and now it does not come back anymore..thanks for helping me and giving me tips on how to solve my problem, the tools you have recommended are surely useful for users who are conscious about security issues.more power to you and may you help many more people in solving security problems.
sir may i know your email address or other means to contact you because i'm currently working on something that will improve the security of our computer so i would like to seek your advice…thanks for your time in reading this post and more power to you..
What are you looking to implement?
If it's going to be a week or two I can keep this thread open and you can post back here to contact me. You can also contact me through my website that is in my signature.
Let me know,
Dave
ok sir i'm planning to do this as soon as possible,so here's the scenario:
in our house we have 4 computer users including me, one of them just love to play pc games and emulators, and the other two loves two surf the internet, and i am the one who is in charge of keeping the computer at its optimal gaming performance and safety in the internet. since one of the users turns off the firewall and antivirus when he is playing, i created a batch file that launches spyware blaster and zonelabs firewall whenever they open mozilla firefox. i would greatly appreciate if you can give me some ideas on how to run my zone alarm firewall, spyware blaster, and activate the avast resident scanner automatically whenever the other users connect to the internet using a dial-up connection, and deactivate them whenever i disconnect.. i am doing this for the other two users because they are not that good in understanding things about security and safety.
i am currently using mozilla firefox browser with the following extensions: noscript, adblock plus, adblock filterset G updater, adblock plus element hiding helper, dr. web antivirus link checker, fasterfox, and mcafee siteadvisor.
i hope that you can give me some tips so that i can help the users in our house who like gaming, and the users who like surfing the internet.thank you and more power!
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI