Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 23-08-2005, 01:00 PM   #1 (permalink)
Right Off the Assembly Line
 
Join Date: Mar 2005
Posts: 5
Default Tries to connect automatically after 10 seconds ..why ?


hey guys
I have XP...The problem with my computer is that when i switch it on and start working on anything...immmediately after 30 seconds or so...my computer starts to connect to the internet automatically...since i am using BSNL broadband...it fails to connect coz i switch off the modem..(it connects if the modem is on..and then i can work smooth but i dont want to be connected all time while using my pc)...
I cancel the connection but then it starts trying to connect to the internet after every 10-15 second gap and i have to cancel it every time..
this is so irritating..
i have uninstalled the modem driver and installed it again...made a new connection again...but the problem persists..
please help me someone
Raman
raman82@gmail.com :roll:
enter_the_matrix is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 23-08-2005, 01:24 PM   #2 (permalink)
Microsoft MVP
 
Vishal Gupta's Avatar
 
Join Date: Jul 2005
Location: AskVG.com
Posts: 5,173
Default

May be some spyware s/w is trying to connect to net!
Type msconfig in Run dialog box and goto Startup tab, and check whether is there ne suspicious s/w listed?
If yes, then uncheck the checkbox and apply it.
U can also post a screenshot of the startup tab, so that all of us can find that which s/w is causing that problem?
__________________
:arrow: http://www.AskVG.com/
Vishal Gupta is offline  
Old 23-08-2005, 01:25 PM   #3 (permalink)
Alpha Geek
 
club_pranay's Avatar
 
Join Date: Apr 2004
Location: United States
Posts: 624
Default

i am not sure but please try this way...
go to the internet explorer, tools....then internet options
go to the connections tab
here u'll see your modem dialup settings..
in this window, click on "never dial a connection"
"apply" and "ok"
pls reply if the problem remains.
__________________
Be not Thou far from me o Lord....o my strength....haste Thee to help me.
club_pranay is offline  
Old 23-08-2005, 01:59 PM   #4 (permalink)
Right Off the Assembly Line
 
Join Date: Mar 2005
Posts: 5
Default

thanx for the possible solutions guys...no they didn't worked out..
Well, Pranay...i tried what u have suggested...but the connection already is set on "never dial a connection"
and Vishal, i find no suspicious s/w listed there..
enter_the_matrix is offline  
Old 23-08-2005, 03:33 PM   #5 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

club-pranays soln shud have wrkd...
...u know what, download 'active ports' from www.ntutility.com or a similar utility to show u who is trying to connect. realplayer, etc often try to connect 'suo moto'. once u'v found out who the asshxxx is, u can remove him from the startup, and disable 'auto connect' from its program settings also. try it. lets see if this helps.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 23-08-2005, 04:16 PM   #6 (permalink)
Guest
 
Posts: n/a
Default

get hijackthis utility and give here log file .. here many persons are powerful to analise it..
and check whether any dialer is in ur system . scan with antispyware with latest updates .

or onething let it connect first by keeping modem on. and then using TCPVIEW utility check all active connection .. is any suspicious?

try it
 
Old 23-08-2005, 04:44 PM   #7 (permalink)
Right Off the Assembly Line
 
Join Date: Mar 2005
Posts: 5
Default

Here is the log file extracted by HIJACKTHIS utility
have a look




Logfile of HijackThis v1.99.1
Scan saved at 4:42:35 PM, on 8/23/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\WINDOWS\System32\mwupdate32.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\netddeclnt.exe
C:\WINDOWS\netinfo.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\dfgj\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.d ll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.d ll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [microsft windows updates] mwupdate32.exe
O4 - HKLM\..\RunServices: [microsft windows updates] mwupdate32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\YAHOO!\COMMON\yhexbmesin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\YAHOO!\COMMON\yhexbmesin.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: Win32 Classes -
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/game...s/y/pote_x.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: Network DDE Client (NetDDEclnt) - Unknown owner - C:\WINDOWS\System32\netddeclnt.exe
O23 - Service: netinfo - Unknown owner - C:\WINDOWS\netinfo.exe
enter_the_matrix is offline  
Old 23-08-2005, 04:52 PM   #8 (permalink)
Right Off the Assembly Line
 
Join Date: Mar 2005
Posts: 5
Default

hey, i tried TCPVIEW utility too...
it shows some..."NETONE" AND "MWUPDATE" ALL THE TIME
mwupdate is MICROSOFT WINDOWS UPDATE..hey may be microsoft windows XP is trying for some updates or something and its automatically connecting the internet for some updates...but while i am connected, i see no updates...tried CTRL+ALT+DEL...but shows no updates...so why this MWUPDATE utlility is running in background ?>
its getting so confusing...
enter_the_matrix is offline  
Old 23-08-2005, 05:16 PM   #9 (permalink)
Wise Old Owl
 
siriusb's Avatar
 
Join Date: May 2005
Location: Chennai, India, Asia, the Earth, the Solar system, the Milky Way, the Local group, this Universe.
Posts: 1,171
Default

Maybe this is ur malware:
http://www.file.net/process/ycomp5_6_2_0.dll.html
__________________
http://myxp.blogspot.com
-----------------------
Winchester 3200+ @2,500MHz
LeadTek 7900GT VOLT MODDED @ 680 core, 1800 mem
2x1GB Transcend DDR400 @ DDR454 2.5,3,3,5,1T
siriusb is offline  
Old 23-08-2005, 06:48 PM   #10 (permalink)
Right Off the Assembly Line
 
Join Date: Mar 2005
Posts: 5
Default

hey..the link u gave showed that this is a malware caused due to yahoo toolbar installation....which i did a few days back (as i was installing yahoo messenger)...
but can that link refers to a page which describes the malware but doesn't give a hint abt removing it except for the SPYDOCTOR utility which is shown in the end !!
how do i remove this malware ?
enter_the_matrix is offline  
Old 23-08-2005, 07:43 PM   #11 (permalink)
In The Zone
 
Join Date: Oct 2004
Location: Chennai
Posts: 400
Default

Try the following software to remove spyware:

1. SpyBot Search and Destroy click Here

2. Lavasoft Adware Removal Tool see here

These are the some of the best malware removal tool and they are free. The only lack is realtime scanning........

Happy malware busting pal
__________________
Intel Pentium 4 2.40C @ 800 Mhz FSB,On Asrock P4i65GV, 1 GB Transcend DDR 400 Mhz,160 GB Seagate SATA,120 GB Samsung PATA
GeForce FX5500 256MB,LG GCE-8525B,52x32x52x,Lite-On SOHW-1633S DVD Burner
Creative 2.1 Inspire Series,Syncmaster 17\" 793MB
shivaranjan.b is offline  
Old 23-08-2005, 08:39 PM   #12 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

spyware infected > R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
also perhaps mwupdate32.exe (!)
http://www.castlecops.com/s10931-mic...s_updates.html

download, install, update and run microsoft anti-spy AND (adaware OR spybot). click www.download.com
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 23-08-2005, 08:54 PM   #13 (permalink)
Human Spambot
 
swatkat's Avatar
 
Join Date: Mar 2004
Location: India
Posts: 2,033
Default

Hi,

Boot in SAFE Mode. Go to Start > Run and type services.msc and press ENTER. Here, navigate to the service Network DDE Client (NetDDEclnt) and click "Properties". Here, under "Status" dialog box, click "Stop". And, under "Startup type" dialog box, select "Disabled". Click "Apply" and "OK". Next, navigate this serivce and do the same netinfo.


Run HijackThis and click "Do only a System Scan". Next, select these entries:-

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O4 - HKLM\..\Run: [microsft windows updates] mwupdate32.exe
O4 - HKLM\..\RunServices: [microsft windows updates] mwupdate32.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: Win32 Classes -
O23 - Service: Network DDE Client (NetDDEclnt) - Unknown owner - C:\WINDOWS\System32\netddeclnt.exe
O23 - Service: netinfo - Unknown owner - C:\WINDOWS\netinfo.exe


Close all other progams, and click "Fix Checked" in HijackThis.


Delete these files:-
C:\WINDOWS\System32\mwupdate32.exe
C:\WINDOWS\System32\netddeclnt.exe
C:\WINDOWS\netinfo.exe


Reboot to Normal Mode and post a fresh log. Also, check whether your System auto dials or not, and post back.
__________________
http://swatrant.blogspot.com/
swatkat is offline  
Old 23-08-2005, 09:00 PM   #14 (permalink)
In The Zone
 
Join Date: Oct 2004
Location: Chennai
Posts: 400
Default

How to analyse the hijak this log file?
__________________
Intel Pentium 4 2.40C @ 800 Mhz FSB,On Asrock P4i65GV, 1 GB Transcend DDR 400 Mhz,160 GB Seagate SATA,120 GB Samsung PATA
GeForce FX5500 256MB,LG GCE-8525B,52x32x52x,Lite-On SOHW-1633S DVD Burner
Creative 2.1 Inspire Series,Syncmaster 17\" 793MB
shivaranjan.b is offline  
Old 23-08-2005, 09:30 PM   #15 (permalink)
Human Spambot
 
expertno.1's Avatar
 
Join Date: May 2005
Location: Expert Planet
Posts: 2,480
Default

see this
http://forums.spywareinfo.com/lofive...hp/t16960.html
__________________
Off From Digit Forum for some months.....busy
expertno.1 is offline  
Old 23-08-2005, 11:18 PM   #16 (permalink)
Guest
 
Posts: n/a
Default

mwupdate32.exe is suspicious ..
 
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Charan
- by abhidev
- by Sujeet
- by Sarath
- by Krow

Advertisement




All times are GMT +5.5. The time now is 08:48 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2