SysOpt Forums

System Optimization and PC Performance

[ Home | News | Features | User Reviews | Overclocking | Benchmarks | About Us | Forum FAQ

Go Back   SysOpt Forums > General Tech > Applications and Operating Systems

Applications and Operating Systems Discuss any software apps, plus OS's: Win98/95, WinNT, Win2k, WinXP,Linux, BeOS, etc.

Reply
 
Thread Tools Search this Thread Display Modes
Old 11-11-2004, 11:23 PM   #1
The Lodge
Ultimate Member
 
The Lodge's Avatar
 
Join Date: Aug 2003
Location: Crumbling American Empire
Posts: 1,844
upnpclient.exe = Unknown program

This guy I know has this on his system. I had him scan with all the usual programs like adaware, spybot, and av but nothing comes up. In task manager this is running under the applications tab, MSLib16s. When ever he kills the upnpclient.exe service it comes back after a couple of minutes. A search of his files shows it in the prefetch folder. When he deletes that it still comes back. I’ve searched all over the net and have come up empty. He also used one of those reg cleaners and there’s no dice there either. Has anybody come across this?


Edit: XP Pro by the way.

Last edited by The Lodge; 11-11-2004 at 11:28 PM.
The Lodge is offline   Reply With Quote
Old 11-12-2004, 03:56 AM   #2
Strawbs
Ultimate Member
 
Strawbs's Avatar
 
Join Date: Sep 2001
Posts: 4,705
MS' "upnp" is a feature not needed now or ever, it leaves the system open to hacking. Use WinPatrol to try to kill the Active process and remove it from the startup list.

Then use GRC's Un Plug & Pray to disable it! You can read all about it at the same link. You can also look for & disable it in the "services" console in Admin Tools. GRC's little tool confirms the process is dead.

Another thing: AV, Ad & Spyware scanners don't usually catch "Trojans".
__________________
Strawbs is offline   Reply With Quote
Old 11-12-2004, 04:37 AM   #3
fishybawb
Hired Geek
 
fishybawb's Avatar
 
Join Date: Jun 2002
Location: York, UK
Posts: 3,371
Quote:
Originally posted by Strawbs
Another thing: AV, Ad & Spyware scanners don't usually catch "Trojans".
Most AV programs do detect trojans now, as do adware scanners like PestPatrol.
fishybawb is offline   Reply With Quote
Old 11-12-2004, 06:22 AM   #4
The Lodge
Ultimate Member
 
The Lodge's Avatar
 
Join Date: Aug 2003
Location: Crumbling American Empire
Posts: 1,844
Thanks Strawbs. I'll give those a try this evening, hopefully it will work. He's been complaining about port scans and constant norton popups telling him it just blocked an intrusion attempt. Using whois and nortons visual tracking it all points to Korea.
The Lodge is offline   Reply With Quote
Old 11-12-2004, 01:21 PM   #5
G
Ultimate Member
 
G's Avatar
 
Join Date: Nov 2000
Location: United Kingdom
Posts: 3,375
Make sure System Restore is OFF and you have Enabled the Viewing of Hidden Files.

Look in C:\Windows\Prefetch for accdisk and Delete any entries
G is offline   Reply With Quote
Old 11-12-2004, 05:01 PM   #6
The Lodge
Ultimate Member
 
The Lodge's Avatar
 
Join Date: Aug 2003
Location: Crumbling American Empire
Posts: 1,844
Will do G. I don't think he has hidden files shown. That's something I've always got going on with my rig. I didn't get a whole lot of time to mess with his computer. Tonight will be the true test.
The Lodge is offline   Reply With Quote
Old 11-13-2004, 07:16 AM   #7
The Lodge
Ultimate Member
 
The Lodge's Avatar
 
Join Date: Aug 2003
Location: Crumbling American Empire
Posts: 1,844
I went over to his house and he was in the middle of a clean install. Oh well, another bit of info stored in the noggin for future reference.
The Lodge is offline   Reply With Quote
Old 11-13-2004, 08:00 AM   #8
Strawbs
Ultimate Member
 
Strawbs's Avatar
 
Join Date: Sep 2001
Posts: 4,705
You should still have him disable upnp in "admin tools>services" for security reasons.
__________________
Strawbs is offline   Reply With Quote
Old 11-13-2004, 01:12 PM   #9
Rocketmech
Ultimate Member
 
Rocketmech's Avatar
 
Join Date: May 2001
Location: Corpus Christi, Texas
Posts: 5,574
Quote:
You should still have him disable upnp in "admin tools>services" for security reasons.
And also the "SSDP Discovery Service" , both need to be disabled to turn off UPnP.
Be aware that some applications who need NAT traversal and some MS programs may not work , such as MSN Messenger and Remote Connection. I find its not too much of a security problem for home use myself , but it does leave a port open for an extended time when your done using it and my firewall logs get inundated from my WLAN side . Aside from that its safe IMO to disable it at the router and leave it in Manual in Services. Then, if you need it just turn it on at the router.

As to the files upnpclient.exe and MSLib16s , they are suspect. Theres a thread at TomCoyote's Forums , but the threat is new and probably rare and we'll just have to wait till its resolved. Someone will probably need to unpack the files to see whats up.

http://forums.tomcoyote.org/index.ph...62&hl=mslib16s
Rocketmech is offline   Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:06 AM.


  • Biweekly CPU Prices - Week of August 30, 2010
  • Biweekly Memory Prices - Week of August 23, 2010
  • Biweekly CPU Prices - Week of August 16, 2010
  • Biweekly Memory Prices - Week of August 9, 2010
  • Biweekly CPU Prices - Week of August 2, 2010
  • Biweekly CPU Prices - Week of July 19, 2010
  • Biweekly Memory Prices - Week of July 12, 2010
  • Weekly CPU Prices - Week of July 5, 2010




    Security Software Primed for Strong Growth
    SAP Touts 'Unwired' Strategy With Sybase
    Salesforce Q2 Sees SaaS Paying Off
    Linux Distros Wrestle With Security Vulnerability
    Dell: Enterprises Buying More Servers, PCs
    Yahoo Begins Microsoft Search-Ad Integration
    Facebook Places Takes On Location Services
    Intel Acquiring Security Vendor McAfee for $7.7B
    Lyric Semiconductor Touts Probability Processors
    Windows Live Essentials 2011 Heads to Beta


  • Acceptable Use Policy

    Internet.com
    The Network for Technology Professionals

    Search:

    About Internet.com

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | E-mail Offers


    Powered by vBulletin® Version 3.7.3
    Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
    Copyright 2002 Jupitermedia Corporation