UPnPframework.exe

D

drhell

When i log off my pc, i get the message that UPnPframework.exe could
not be read in memory something like that after 3 times i click ok it
closes the alert message, i did the Hijackthis and here is what i get,
please help me out, thank you for ur time. Have a nice day, please
write to my email if possible thanks.....

Logfile of HijackThis v1.97.7
Scan saved at 12:40:20 AM, on 2/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\SYSTEM32\GEARSEC.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
D:\Pc-cillin\Tmntsrv.exe
D:\Pc-cillin\tmproxy.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
C:\Program Files\Sony\giga pocket\GPVSvr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media
Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media
Platform\SV_Httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media
Platform\SV_Httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media
Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media
Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media
Platform\UPnPFramework.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
D:\logitech\MouseWare\system\em_exec.exe
D:\Pc-cillin\pccguide.exe
D:\Pc-cillin\PCClient.exe
D:\Pc-cillin\TMOAgent.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
D:\spyware microsoft\gcasServ.exe
D:\pocket pc hp\WCESCOMM.EXE
D:\spyware microsoft\gcasDtServ.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Canon\MultiPASS4\MPDBMgr.exe
C:\WINDOWS\hh.exe
D:\SPYBOT\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\ADWARE\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = ;localhost;<local>
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext =
http://www.meninblack.com/game10
R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7}
- (no file)
R3 - URLSearchHook: (no name) - _{0FA33B6C-71BC-69D3-DB7A-472A4D6F3452}
- (no file)
R3 - URLSearchHook: (no name) - _{9368D063-44BE-49B9-BD14-BB9663FD38FC}
- (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
D:\SPYBOT\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px]
C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH
Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [pccguide.exe] "D:\Pc-cillin\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "D:\Pc-cillin\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "D:\Pc-cillin\TMOAgent.exe" /run
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH
Jukebox\mmtask.exe
O4 - HKLM\..\Run: [gcasServ] "D:\spyware microsoft\gcasServ.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\pocket pc
hp\WCESCOMM.EXE"
O4 - HKLM\..\RunOnce: [SpybotSnD] "D:\SPYBOT\Spybot - Search &
Destroy\SpybotSD.exe" /autocheck
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZNxdm885XXUS
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Descargas (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient
Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab28578.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine
Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update
Installation Engine) -
http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
-
http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1099085375250
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -
http://www.netvenda.com/sites/games-intl/ww/games3.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com/binary/ZIntro.cab28578.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service
Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{351D68FB-758A-4836-8BA3-9BA81D798DC9}:
NameServer = 168.243.165.225,168.243.165.226
O17 -
HKLM\System\CCS\Services\Tcpip\..\{4E2B4154-061F-4A0A-8A12-67D68B242877}:
NameServer = 168.243.89.66,168.243.81.70
 
D

David H. Lipman

drhell:

This is not the best place to post HiJackThis logs, the following are more apropos...

The following are more apropos...
microsoft.public.security.virus
alt.comp.anti-virus
alt.privacy.spyware

UPnPframework.exe is a Sony uPnP helper application so contact Sony for support.

--
Dave




| When i log off my pc, i get the message that UPnPframework.exe could
| not be read in memory something like that after 3 times i click ok it
| closes the alert message, i did the Hijackthis and here is what i get,
| please help me out, thank you for ur time. Have a nice day, please
| write to my email if possible thanks.....
|
| Logfile of HijackThis v1.97.7
| Scan saved at 12:40:20 AM, on 2/22/2005
| Platform: Windows XP SP2 (WinNT 5.01.2600)
| MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
|
| Running processes:
| C:\WINDOWS\System32\smss.exe
| C:\WINDOWS\system32\winlogon.exe
| C:\WINDOWS\system32\services.exe
| C:\WINDOWS\system32\lsass.exe
| C:\WINDOWS\system32\svchost.exe
| C:\WINDOWS\System32\svchost.exe
| C:\WINDOWS\system32\spoolsv.exe
| C:\WINDOWS\System32\cisvc.exe
| C:\WINDOWS\SYSTEM32\GEARSEC.EXE
| C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
| C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
| C:\WINDOWS\System32\nvsvc32.exe
| C:\WINDOWS\System32\svchost.exe
| D:\Pc-cillin\Tmntsrv.exe
| D:\Pc-cillin\tmproxy.exe
| C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
| C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
| C:\Program Files\Sony\giga pocket\GPVSvr.exe
| C:\WINDOWS\System32\MsPMSPSv.exe
| C:\Program Files\Common Files\Sony Shared\VAIO Media
| Platform\sv_httpd.exe
| C:\Program Files\Common Files\Sony Shared\VAIO Media
| Platform\SV_Httpd.exe
| C:\Program Files\Common Files\Sony Shared\VAIO Media
| Platform\SV_Httpd.exe
| C:\Program Files\Common Files\Sony Shared\VAIO Media
| Platform\UPnPFramework.exe
| C:\Program Files\Common Files\Sony Shared\VAIO Media
| Platform\UPnPFramework.exe
| C:\Program Files\Common Files\Sony Shared\VAIO Media
| Platform\UPnPFramework.exe
| C:\WINDOWS\Explorer.exe
| C:\WINDOWS\System32\ezSP_Px.exe
| C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
| C:\Program Files\QuickTime\qttask.exe
| C:\WINDOWS\system32\RUNDLL32.EXE
| C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
| C:\WINDOWS\system32\rundll32.exe
| D:\logitech\MouseWare\system\em_exec.exe
| D:\Pc-cillin\pccguide.exe
| D:\Pc-cillin\PCClient.exe
| D:\Pc-cillin\TMOAgent.exe
| C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
| D:\spyware microsoft\gcasServ.exe
| D:\pocket pc hp\WCESCOMM.EXE
| D:\spyware microsoft\gcasDtServ.exe
| C:\WINDOWS\system32\wscntfy.exe
| C:\WINDOWS\system32\cidaemon.exe
| C:\WINDOWS\system32\cidaemon.exe
| C:\Program Files\Canon\MultiPASS4\MPDBMgr.exe
| C:\WINDOWS\hh.exe
| D:\SPYBOT\Spybot - Search & Destroy\SpybotSD.exe
| C:\Program Files\Internet Explorer\iexplore.exe
| D:\ADWARE\HijackThis.exe
|
| R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
| Settings,ProxyOverride = ;localhost;<local>
| R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext =
| http://www.meninblack.com/game10
| R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7}
| - (no file)
| R3 - URLSearchHook: (no name) - _{0FA33B6C-71BC-69D3-DB7A-472A4D6F3452}
| - (no file)
| R3 - URLSearchHook: (no name) - _{9368D063-44BE-49B9-BD14-BB9663FD38FC}
| - (no file)
| O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
| C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
| O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
| D:\SPYBOT\SPYBOT~1\SDHelper.dll
| O4 - HKLM\..\Run: [ezShieldProtector for Px]
| C:\WINDOWS\System32\ezSP_Px.exe
| O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH
| Jukebox\mm_tray.exe
| O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe
| O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
| Files\QuickTime\qttask.exe" -atboottime
| O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
| C:\WINDOWS\System32\NvCpl.dll,NvStartup
| O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
| O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
| C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
| O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
| Files\Java\j2re1.4.2_06\bin\jusched.exe
| O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
| O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
| Files\Real\Update_OB\realsched.exe" -osboot
| O4 - HKLM\..\Run: [pccguide.exe] "D:\Pc-cillin\pccguide.exe"
| O4 - HKLM\..\Run: [PCClient.exe] "D:\Pc-cillin\PCClient.exe"
| O4 - HKLM\..\Run: [TM Outbreak Agent] "D:\Pc-cillin\TMOAgent.exe" /run
| O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH
| Jukebox\mmtask.exe
| O4 - HKLM\..\Run: [gcasServ] "D:\spyware microsoft\gcasServ.exe"
| O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\pocket pc
| hp\WCESCOMM.EXE"
| O4 - HKLM\..\RunOnce: [SpybotSnD] "D:\SPYBOT\Spybot - Search &
| Destroy\SpybotSD.exe" /autocheck
| O8 - Extra context menu item: &Search -
| http://bar.mywebsearch.com/menusearch.html?p=ZNxdm885XXUS
| O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
| O9 - Extra button: Create Mobile Favorite (HKLM)
| O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
| O9 - Extra button: Research (HKLM)
| O9 - Extra button: Descargas (HKLM)
| O9 - Extra button: Messenger (HKLM)
| O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
| O12 - Plugin for .spop: C:\Program Files\Internet
| Explorer\Plugins\NPDocBox.dll
| O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
| O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient
| Class) -
| http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab28578.cab
| O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine
| Advantage Validation Tool) -
| http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
| O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update
| Installation Engine) -
| http://office.microsoft.com/officeupdate/content/opuc.cab
| O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
| -
|
http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1099085375250
| O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -
| http://www.netvenda.com/sites/games-intl/ww/games3.cab
| O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
| http://messenger.zone.msn.com/binary/ZIntro.cab28578.cab
| O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
| http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
| O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service
| Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab
| O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
| Object) -
| http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
| O17 -
| HKLM\System\CCS\Services\Tcpip\..\{351D68FB-758A-4836-8BA3-9BA81D798DC9}:
| NameServer = 168.243.165.225,168.243.165.226
| O17 -
| HKLM\System\CCS\Services\Tcpip\..\{4E2B4154-061F-4A0A-8A12-67D68B242877}:
| NameServer = 168.243.89.66,168.243.81.70
|
 
J

Jon Kennedy

As David mentioned, this is not really the place to post HijackThis logs.
You'll need to post them where the real experts live:
Tutorial on how to use HijackThis:
http://www.spywareinfo.com/~merijn/htlogtutorial.html
Then post it's output log to the forum here for analysis and feedback by the
parasite experts:
http://www.spywareinfo.com/forums/
Or the other HijackThis Logs forums listed here:
http://www.spywareinfo.com/~merijn/forums.html

--

Jon R. Kennedy
Charlotte, NC, USA
(e-mail address removed)

drhell said:
When i log off my pc, i get the message that UPnPframework.exe could
not be read in memory something like that after 3 times i click ok it
closes the alert message, i did the Hijackthis and here is what i get,
please help me out, thank you for ur time. Have a nice day, please
write to my email if possible thanks.....

Logfile of HijackThis v1.97.7
Scan saved at 12:40:20 AM, on 2/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\SYSTEM32\GEARSEC.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
D:\Pc-cillin\Tmntsrv.exe
D:\Pc-cillin\tmproxy.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
C:\Program Files\Sony\giga pocket\GPVSvr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media
Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media
Platform\SV_Httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media
Platform\SV_Httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media
Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media
Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media
Platform\UPnPFramework.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
D:\logitech\MouseWare\system\em_exec.exe
D:\Pc-cillin\pccguide.exe
D:\Pc-cillin\PCClient.exe
D:\Pc-cillin\TMOAgent.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
D:\spyware microsoft\gcasServ.exe
D:\pocket pc hp\WCESCOMM.EXE
D:\spyware microsoft\gcasDtServ.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Canon\MultiPASS4\MPDBMgr.exe
C:\WINDOWS\hh.exe
D:\SPYBOT\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\ADWARE\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = ;localhost;<local>
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext =
http://www.meninblack.com/game10
R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7}
- (no file)
R3 - URLSearchHook: (no name) - _{0FA33B6C-71BC-69D3-DB7A-472A4D6F3452}
- (no file)
R3 - URLSearchHook: (no name) - _{9368D063-44BE-49B9-BD14-BB9663FD38FC}
- (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
D:\SPYBOT\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px]
C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH
Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [pccguide.exe] "D:\Pc-cillin\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "D:\Pc-cillin\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "D:\Pc-cillin\TMOAgent.exe" /run
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH
Jukebox\mmtask.exe
O4 - HKLM\..\Run: [gcasServ] "D:\spyware microsoft\gcasServ.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\pocket pc
hp\WCESCOMM.EXE"
O4 - HKLM\..\RunOnce: [SpybotSnD] "D:\SPYBOT\Spybot - Search &
Destroy\SpybotSD.exe" /autocheck
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZNxdm885XXUS
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Descargas (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient
Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab28578.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine
Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update
Installation Engine) -
http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
-
http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1099085375250
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -
http://www.netvenda.com/sites/games-intl/ww/games3.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com/binary/ZIntro.cab28578.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service
Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{351D68FB-758A-4836-8BA3-9BA81D798DC9}:
NameServer = 168.243.165.225,168.243.165.226
O17 -
HKLM\System\CCS\Services\Tcpip\..\{4E2B4154-061F-4A0A-8A12-67D68B242877}:
NameServer = 168.243.89.66,168.243.81.70
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top