Can't Disconnect Dialup connection

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Anyone know of a virus or spyware that is causing dialup connections to
disallow disconnecting and locking up the modem even with a shutdown?
 
onyx7 said:
Anyone know of a virus or spyware that is causing dialup connections
to disallow disconnecting and locking up the modem even with a
shutdown?

That is a common symptom of malware infestation. There are far too many
viruses and non-viral malware to tell you a specific name. Go through
these malware removal steps, doing everything with updated tools in
Safe Mode. You may need to get the tools on a known-clean computer with
a faster Internet connection and a cd-rw drive.

Delete Temporary and Temporary Internet Files, then:

1) Scan in Safe Mode with current version (not earlier than 2004)
antivirus using updated definitions.

Before you remove malware, get LSPFix (or WinSockFix for XP which you
can get from MajorGeeks) - see links below.

2) Remove spyware with Spybot Search & Destroy and Ad-aware. These
programs are free, so use them both since they complement each other.
There is a new version of CWShredder from Intermute. I would not
install the other Intermute programs, however. Alternately, there are
CoolWebSearch malware removal steps at SilentRunners.

Be sure to update these programs before running, and it is a good idea
to do virus/spyware scans in Safe Mode. Make sure you are able to see
all hidden files and extensions (View tab in Folder Options).

If the malware remains even after you used Ad-aware and Spybot, you can
scan with HijackThis. HijackThis is an excellent tool to discover and
disable hijackers, but it requires expert skill. See below for
HijackThis links, including sites where you can post your HJT logs. A
combination of HijackThis and About:Buster works well in removing the
About:Blank homepage hijacker. Again, this is an expert tool and
novices should get help with it.

3) If you are running Windows ME or XP, you should disable/enable System
Restore after the system is clean because malware will be in the
Restore Points. With ME, you must disable System Restore completely.
With XP, you can delete all but the most recent (presumably clean)
System Restore point from the More Options section of Disk Cleanup
(Run>cleanmgr).

4) Make sure you've visited Windows Update and applied all security
patches. Do not install driver updates from Windows Update.

5) Run a firewall.

Links to help with malware:

Software/Methods:
http://www.safer-networking.org - Spybot Search & Destroy
http://www.lavasoftusa.com - Ad-aware
http://www.majorgeeks.com - good download site
http://www.intermute.com/spysubtract/cwshredder_download.html
http://www.silentrunners.org/sr_cwsremoval.html. - SilentRunners
http://www.cexx.org/lspfix.htm - Repair Winsock 2 settings after
removing spyware
http://www.spychecker.com/program/winsockxpfix.html - WinsockXPFix.exe

HijackThis:
http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Jim
Eshelman
http://aumha.net - forums
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/

General:
http://aumha.net - look under "Security" for various forums
http://rgharper.mvps.org/cleanit.htm
http://mvps.org/winhelp2002/unwanted.htm
http://www.aumha.org/a/parasite.htm - The Parasite Fight
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Malke
 
In addition:

Remove KWBot.Worm (cmd32.exe/system32)
Click OK, and then close the Network Connections dialog box.
http://support.microsoft.com/default.aspx?scid=KB;en-us;q316530

Modem Automatically Attempts a Dial-Up Connection [Q316530]
http://support.microsoft.com/?kbid=316530

Disable or Enable AutoDial (Line 91)
http://www.kellys-korner-xp.com/xp_tweaks.htm

Right click My Network Places/Properties/Advanced (top toolbar)/Dial-Up
Preferences/Enable Auto-Dial by Location/Uncheck all locations and check off
always ask me before auto dialing. Also, Disable autodial while I am logged
on.

In the Enable Auto-Dial By Location dialog box, select each location for
which you want the automatic dialing feature to operate. Reboot.

Disable or Enable AutoDial (Line 91)
http://www.kellys-korner-xp.com/xp_tweaks.htm

To view the list of names and addresses recorded by AutoDial, type the
following command at a command prompt: rasautou -s

To delete a name or address entry from the list: Start/Run/Regedit

HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses

Added info:

To set Idle TimeOut:

1. The Idle TimeOut option in Dial-Up Networking must be set for the
connection to hang up after being idle. Open the Dial-Up Networking dialog
box, and select User Preferences from the More button.

2. Disable Autodial by location, and set Idle Seconds Before Hanging Up to
the desired amount of time: This value should be greater than 60.

3. Choose Logon Preferences from the More button, and set Idle Seconds
Before Hanging Up to the same value as User Preferences.

4. Open Control Panel/Services and disable the Remote Access Autodial
Manager service.

Another option: Start/Run/Regedit

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters.
In the right pane, find Autodisconnect and change the time accordingly.

Or...

Start/Run/net config server /autodisconnect:30 (30 being an example).

--
In memory of our dear friend, MVP Alex Nichol: http://www.dts-l.org/

All the Best,
Kelly (MS-MVP)

Troubleshooting Windows XP
http://www.kellys-korner-xp.com
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top