Reply
Regular Contributor
Posts: 56
Registered: ‎08-20-2005
.. scans and tells me objects shown here are not considered to be a threat:

MRU LIST
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj=MRU FileReference : C:\Documents and Settings\A Non\recent\Create new folder.lnk
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\adobe\acrobat reader\6.0\avgeneral\crecentfiles\c1
obj=MRU FileReference : C:\Documents and Settings\A Non\recent\Forum post Monday.lnk
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\google\navclient\1.1\history
obj=MRU RegReference : software\microsoft\direct3d\mostrecentapplication name
obj=MRU RegReference : software\microsoft\direct3d\mostrecentapplication name
obj=MRU RegReference : software\microsoft\directdraw\mostrecentapplication name
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\directinput\mostrecentapplication name
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\directinput\mostrecentapplication id
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\internet explorer download directory
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\internet explorer\typedurls
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\mediaplayer\player\recentfilelist
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\mediaplayer\preferences lastplaylistindex
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\mediaplayer\preferences lastplaylist
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\search assistant\acmru\5001
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\search assistant\acmru\5603
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\search assistant\acmru\5604
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\windows\currentversion\explorer\recentdocs\.cpl
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\windows\currentversion\explorer\recentdocs\.eml
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\windows\currentversion\explorer\recentdocs\.inf
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\windows\currentversion\explorer\recentdocs\.log
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\windows\currentversion\explorer\recentdocs\.txt
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\windows\currentversion\explorer\recentdocs\.zip
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\windows\currentversion\explorer\recentdocs\Folder
obj=MRU RegReference : .DEFAULT\software\microsoft\windows media\wmsdk\general computername
obj=MRU RegReference : S-1-5-18\software\microsoft\windows media\wmsdk\general computername
obj=MRU RegReference : S-1-5-21-3300948778-2103487653-3197608383-1005\software\microsoft\windows media\wmsdk\general computername

I get nervous anytime I see a search assistant, don't know if this stuff is harmless or not. I googled the search assistant and got:

http://www.wilderssecurity.com/archive/index.php/t-35098

"For the last several days I have been at war with the Blazefind Search Assistant toolbar, a notorious little doodjimahickey that hooked itself onto my Windows taskbar and won't let go... because it had taken over my Userinit registry key (renaming the original as "Olduserinit")."

"Following the instructions of several people on this board I was able to identify two programs that were launching this toolbar: C:\WINDOWS\system32\wsaupdater.exe, and C:\WINDOWS\2_0_1browserhelper2.dll. I found them, and killed them. I enjoyed watching them die."

"However -- and I'm also posting this as a warning to people who may be trying to remove wsaupdater.exe from their systems -- the next time I booted the system, it would not let me log on. I would be shoved right back out to the login screen again. Using the remote registry editor on another system, I found that in HKEY_LOCAL_MACHINE/Software/Windows NT/CurrentVersion/Winlogon, the Userinit key had been renamed Olduserinit, and and replaced with a Userinit containing the value -- you guessed it -- C:\WINDOWS\system32\wsaupdater.exe. When I removed this program, Windows couldn't find anything with which to log me onto the system, and I got a revolving door as a result."

"Switching the offending key with the original gave me back my computer."

User goes on to post a HijackThis log. I was just wondering if anyone has an opinion. I always delete everything, but my latest problem is my computer doesn't want to shut down. Once something starts I never know if it's sick or just reacting from a tweak.

Appreciate any input -

Sui
Regular Contributor
Posts: 56
Registered: ‎08-20-2005

Re: AdAware

In fact, it took about 5 minutes to shut down just now. Error mssg: Application failed to initialize - windows station shutting down - rundll32.exe dll initialization failed. I realize this isn't Comcast specific, but once again any thoughts are appreciated.

:smileyhappy:
Most Valued Poster
jw50
Posts: 1,674
Registered: ‎12-29-2003

Re: AdAware

MRUs are Most Recently Used lists and are not malware. No need to worry about those although it doesn't hurt anything if you have Ad-Aware remove them.

As far as the shutdown problem goes check your Event Viewer (Control Panel, Administrative Tools, Event Viewer) for application errors around the time you are shutting down. If you find any double click on them and see what it says under Description.
Regular Contributor
Posts: 56
Registered: ‎08-20-2005

Re: AdAware

Thank you. Hate to be a worry-wart but it seems like you can't be too careful these days. I really appreciate all of the info this forum provides.