Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista General Discussion > usrclass.dat

Reply
 
 
user@domain.tld
Guest
Posts: n/a

 
      05-16-2008
Good afternoon,

Yesterday, I noticed that my HDD light was flashing about twice a
second, every second, even while the computer was idle.

While I got to wondering, I decided to open Vista's Resource Monitor,
and I looked at the "Disk" section.

Sitting at the top, when sorted in Write >> ascending, sits Explorer.exe
writing to c:\users\[uname]\AppData\Local\Microsoft\usrclass.dat.

In third place sits rundll32.exe, writing to the same file.

I was just wondering what this file was, and why my computer continues
to write to the file, and how much damage this constant writing may do
to my hard drive.

Thank you,


 
Reply With Quote
 
 
 
 
tazwmg3
Guest
Posts: n/a

 
      05-18-2008
I had the same thing happen to me a couple of days ago. would love to see an
answr to this please.

"" wrote:

> Good afternoon,
>
> Yesterday, I noticed that my HDD light was flashing about twice a
> second, every second, even while the computer was idle.
>
> While I got to wondering, I decided to open Vista's Resource Monitor,
> and I looked at the "Disk" section.
>
> Sitting at the top, when sorted in Write >> ascending, sits Explorer.exe
> writing to c:\users\[uname]\AppData\Local\Microsoft\usrclass.dat.
>
> In third place sits rundll32.exe, writing to the same file.
>
> I was just wondering what this file was, and why my computer continues
> to write to the file, and how much damage this constant writing may do
> to my hard drive.
>
> Thank you,
>
>
>

 
Reply With Quote
 
mad_dogu
Guest
Posts: n/a

 
      06-24-2008

Same problems... even worst... HDD temperature: 58 degrees. I'm runnin
Win Vista Ultimate 32bit, up-2-date. I have also another prb: When
open my browser and I type an URL(I tried Mozilla, IE5, Opera), proces
explorer.exe crashes, taskbar dissappears, and I have to reopen th
explorer manually. From time to time, this message appears
'[image: http://i140.photobucket.com/albums/r...Dogu/pic1.jpg]
(http://i140.photobucket.com/albums/r..._Dogu/pic1.jpg

and I still receive messages like this one but from different source
like WinAnonimously... :

Any option I choose, this URL is opened
hxxp://antimalwareguard.com/2009/10/?rff=http%3A%2F%2Fad.yieldmanager.com%2Fst%3Fad_ty pe%3Diframe%26ad_size%3D180x150%26site%3D140464%26 section_code%3D12708330%26cb%3D1214333197848002%26 ycg%3Dm%26yyob%3D1988%26pub_redirect_unencoded%3D1 %26pub_redirect%3Dhttp%3A%2F%2Fus.ard.yahoo.com%2F SIG%3D14vk09l6s%2FM%3D619213.12708330.13016353.122 27498%2FD%3Dmail%2FS%3D398300009%3AREC%2FY%3DYAHOO %2FEXP%3D1214340397%2FL%3DS0i2utG_T4lT5eCxSGFBDAJB UbUieEhhQQ0ADKvV%2FB%3DX_8nQ9j8Yn4-%2FJ%3D1214333197848002%2FA%3D5366722%2FR%3D0%2F%2 A&tmn=tmnanmagua&a=nm_ridmm2_ma_kw1&l=yahoo.com&f= nm_156801_563c4322413d11ddb25d156801cfffff_d70f817 4f2524dbeb4f8727899fd0261&ax=1&ex=1&ed=2&h=10&mt_i nfo=5723_0_22800:6051_0_20770&rdr=2&tmn=null&mt_in fo=5723_0_22800:6051_0_2077

Can someone please help!.
HDD still write/read in alert mood.. :-

--
mad_dogu
 
Reply With Quote
 
Hiren
Guest
Posts: n/a

 
      06-25-2008
I have little doubt that your p. c. is infected.If you can use Windows
Update,update Windows Defender with the latest definitions and run a
complete system-wide full scan thoroughly.If you cannot,download the Windows
Malicious Software removal tool from the Microsoft download center from some
other machine where you can browse properly and run it locally on your
system.

"mad_dogu" <> wrote in message
news:...

Same problems... even worst... HDD temperature: 58 degrees. I'm running
Win Vista Ultimate 32bit, up-2-date. I have also another prb: When I
open my browser and I type an URL(I tried Mozilla, IE5, Opera), process
explorer.exe crashes, taskbar dissappears, and I have to reopen the
explorer manually. From time to time, this message appears:
'[image: http://i140.photobucket.com/albums/r...Dogu/pic1.jpg]'
(http://i140.photobucket.com/albums/r..._Dogu/pic1.jpg)

and I still receive messages like this one but from different sources
like WinAnonimously... :|

Any option I choose, this URL is opened :
hxxp://antimalwareguard.com/2009/10/?rff=http%3A%2F%2Fad.yieldmanager.com%2Fst%3Fad_ty pe%3Diframe%26ad_size%3D180x150%26site%3D140464%26 section_code%3D12708330%26cb%3D1214333197848002%26 ycg%3Dm%26yyob%3D1988%26pub_redirect_unencoded%3D1 %26pub_redirect%3Dhttp%3A%2F%2Fus.ard.yahoo.com%2F SIG%3D14vk09l6s%2FM%3D619213.12708330.13016353.122 27498%2FD%3Dmail%2FS%3D398300009%3AREC%2FY%3DYAHOO %2FEXP%3D1214340397%2FL%3DS0i2utG_T4lT5eCxSGFBDAJB UbUieEhhQQ0ADKvV%2FB%3DX_8nQ9j8Yn4-%2FJ%3D1214333197848002%2FA%3D5366722%2FR%3D0%2F%2 A&tmn=tmnanmagua&a=nm_ridmm2_ma_kw1&l=yahoo.com&f= nm_156801_563c4322413d11ddb25d156801cfffff_d70f817 4f2524dbeb4f8727899fd0261&ax=1&ex=1&ed=2&h=10&mt_i nfo=5723_0_22800:6051_0_20770&rdr=2&tmn=null&mt_in fo=5723_0_22800:6051_0_20770

Can someone please help!..
HDD still write/read in alert mood.. :-s


--
mad_dogu

 
Reply With Quote
 
mad_dogu
Guest
Posts: n/a

 
      06-28-2008

Win Defender up-dated made a full system scan and did not find an
threats. I've scanned with nod32, lavasoft ad-ware pro 2008, and bot
of them found that in C:\users\username\appdata\local\temp were som
.dll files that cannot be deleted. And they start at win start-up
However, both progs found that this files were trojans :| I figured ou
somehow and I deleted them, and now my HDD is in normal state. I thin
it was a prb with those files.. i don`t know exactly. But still m
explorer.exe process is killed from time to time when I surf the web

--
mad_dogu
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off




1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59