Suspicious startup program

LuDaCriS66

Platinum Member
Nov 21, 2001
2,057
0
0
I've got this program in my Startup in msconfig on Windows XP Home Edition that says
%systemroot%/system32 instead of an actual directory. Its called "dumprep 0 -k"
Have I been hacked? What the heck is it? I just realized it today.

And if I disable it in Msconfig, when I reboot and reach the desktop, it just tells me to change it back to normal startup. So if it is indeed something bad, how should I properly disable it?

Also, it runs itself through HKEY/Local Machine/Software/Microsoft/Windows/Current Version/Run/

It's associated with "KernelFaultCheck"

I've got about 5 different people using this computer but everyone has on their own account. Any ideas?

I've also run Norton Anti Virus and scanned the system but nothing came up..
 

Apatewnas

Member
Mar 31, 2002
57
0
0
I have found this file in my computer too (c:\windows\system32\dumprep.exe) running Win Xp corporate. It appears to be a legit file with the description "Windows Error Reporting Dump Reporting Tool". If u check Control Panel/system/advanced/startup and recovery/settings u will notice at the bottom that there is a function called "write debugging onformation" and it's really a typical function for serious OSes after winNT. If a severe crash happens the system automatically dumps a pre-selected area of the main memory to help debug the error. Note that i use the setting "small memory dump 64k" and the referenced file is NOT loaded at startup. I hope this info cames handy...:cool:
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0


<< oooooh i got called mr. ... i feel like somebody special #)



hehehe
>>



Nah, he just said you are old ;)