Are any of these possibly DANGEROUS processes?

By HiFi ยท 7 replies
Apr 2, 2006
  1. I just recovered from that infamous worm that blocks off Task Manager, and regedit. I wanted to know which one of my processes seems out of place and/or dangerous. I now about the ones I need, but the following are ones that I am not sure about. Thanks.

    svchost.exe (x4)
  2. Peddant

    Peddant TS Rookie Posts: 1,446

    Some people would describe Norton as a dangerous process,other than that though,those are safe.
  3. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    They all seem fine. However, rundll32.exe can be used by some malware.

    Go HERE and follow the instructions.

    Then post a HJT log.

    Regards Howard :wave: :wave:
  4. Mictlantecuhtli

    Mictlantecuhtli TS Evangelist Posts: 4,345   +11

    Well, at least jusched.exe is unnecessary, if you ask me. It just sits there and checks for Sun Java updates.

    Java isn't updated often, so I wouldn't keep the updater / scheduler running all the time.
  5. HiFi

    HiFi TS Rookie Topic Starter

    Here is my HJT log, some said they wanted to see it

    Attached Files:

  6. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Can`t see your HJT log HiFi.

    Regards Howard :)
  7. HiFi

    HiFi TS Rookie Topic Starter

    Okay, I put it up now. Its in my message above.
  8. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Boot into safe mode. See how HERE.

    Turn off system restore.(XP/ME only) See how HERE.

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.

    Click start/run and type services.msc into the run box and press the enter key.

    When the window appears, maximise it. Double click on the following services(if there), and select stop if they are running. Set the startup type to disabled.

    Registry System16 Checkup Monitor
    MSN Messenge <No this isn`t a type`o.

    Click apply/ok.

    Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

    Click on the processes tab and end process for(if there).

    winlogin.exe < Not to be confused with winlogon.exe which is legit.

    Close task manager.

    Run HJT with no other programmes open. Have HJT fix the following, by placing a tick in the little box next to(if there).

    O4 - HKLM\..\Run: [Registry System16 Checkup Monitor] SystemReg16.exe

    O4 - HKLM\..\Run: [MSN Messenge] winlogin.exe

    O4 - HKLM\..\RunServices: [Registry System16 Checkup Monitor] SystemReg16.exe

    O4 - HKLM\..\RunServices: [MSN Messenge] winlogin.exe

    O4 - HKCU\..\Run: [MSN Messenge] winlogin.exe

    O4 - HKCU\..\Run: [Registry System16 Checkup Monitor] SystemReg16.exe

    O4 - HKCU\..\RunServices: [MSN Messenge] winlogin.exe

    Click on the fix checked button.

    Close HJT.

    Locate and delete the following bold files(if there).


    Reboot into normal mode.

    Now go and follow The instructions in the How to remove trojans and it`s ilk! Thread.

    Once you`ve done that, turn system restore back on.

    Regards Howard :)
Topic Status:
Not open for further replies.

Similar Topics

Add your comment to this article

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...