AT&T Global Network Dial Up Software issue

Discussion in 'Software' started by Kodo, Mar 31, 2004.

  1. Kodo

    Kodo SNATCHSQUATCH

    Ok, I can't figure this one out. It's been an ongoing fight to try to track down what the cause of this is.

    Background:
      • WinXP PRO Sp1a : Latest Updates
      • User Level: PowerUser
      • Software: AT&T Global Network Dial Up software
      • Issue: Dial Up software pops up at random times while user is working in other applications.
      • Modem off or on; doesn't matter
    Action Taken:
    • Turned off Automatic Updates for the OS
    • Set "never dial" in IE
    • No Incoming calls detected or allowed
    • checked config for AT&T software to make sure it doesn't auto update or autodial
    Gotta reboot.. brb with more info..
     
  2. Adrynalyne

    Adrynalyne Guest

    Spyware?
    AV trying to update?
     
  3. Kodo

    Kodo SNATCHSQUATCH

    Ran Ad-aware and it only found tracking cookies..
    Ran AV.. nothing detected (Using AntiVir)
    Ran AVAST on it too, nothing
    Ran The-Cleaner on it, nothing

    No autoupdates on AV.
     
  4. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    When you stop the dial-up window have you checked task manager for any rogue processes
    Maybe Event Viewer see if any service or something is trying to start

    Double-checked MSCONFIG for a rogue backdoor or something hidden in there, often disguised as actual windows tasks

    Just my 02 :)
     
  5. Kodo

    Kodo SNATCHSQUATCH

    Nothing in the event manager.

    Will check for rogue processes WHILE it's up. Checked in the past and didn't see anything but it wasn't at the time of the event.

    MSCONFIG looks clean too.
     
  6. Adrynalyne

    Adrynalyne Guest

    Go to msconfig.

    Select selective startup.

    Uncheck:

    startup items
    process win.ini
    process system.ini

    Go to services tab.

    Hide all MS services.

    Disable the 3rd party stuff.

    Apply, close

    Reboot.

    Does it still prompt randomly?
     
  7. Kodo

    Kodo SNATCHSQUATCH

    Will test tomorrow.. let you know. User leaves at 4pm and I can't get on her PC until then.

    I did notice this one services (3rd party) .. called "iap" with no description. couldn't find any info on it. Any clues?
     
  8. Adrynalyne

    Adrynalyne Guest

    No. I would go through HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services, locate the service, then find out what exe it is using.
     
  9. Kodo

    Kodo SNATCHSQUATCH

    Roger that...
     
  10. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

  11. Kodo

    Kodo SNATCHSQUATCH

    yes it's a DELL : Service disabled.
     
  12. Kodo

    Kodo SNATCHSQUATCH

    ok, it's gotta be something in her profile because it doesn't do it while I'm logged in as admin...
     
  13. Kodo

    Kodo SNATCHSQUATCH

    RASAUTOU service is executing the dialer. So something is trying to call out because the modem is off.
     
  14. Adrynalyne

    Adrynalyne Guest


    Lodo...it has a ring to it.


    New nickname for Kodo! :D
     
  15. Kodo

    Kodo SNATCHSQUATCH

    I'll run the stinger on this machine, but I'm pretty sure that rasautou is a valid os exe.

    There is definately something trying to come in. My Rc window on the network icon in the systray is lit solid (incoming packets non-stop in the monitor). I installed ZA but all it said was that it was trying to receive DHCP from local 0.0.0.0 so, I'm cornfused...
     
  16. Adrynalyne

    Adrynalyne Guest

    Hmm, proxy client installed maybe?

    Not necessarily a legit one, mind you.

    (malware)
     
  17. Kodo

    Kodo SNATCHSQUATCH

    Thanks for that Star. I disabled everything via the registry.. we'll find out what happens tomorrow because I'm not waiting around for it ..I'm goin home! :)

    Thanks everyone!!
     
  18. Adrynalyne

    Adrynalyne Guest

    Good luck, Lodo, er Kodo. Let us know how it turns out :D
     
  19. Kodo

    Kodo SNATCHSQUATCH

    it's legit.. ran stinger and came up clean.. so I'm definately satisfied that it's not a virus.
     
  20. Kodo

    Kodo SNATCHSQUATCH

    I didn't let it run long enough couldn't leave it on her system with spending the time to really configure it. I'd definately be getting a call in the morning about it.. and I don't want that.
     
  21. Kodo

    Kodo SNATCHSQUATCH

    no 135 activity was detected.. MSN messenger is disabled and no instances of it loaded. Will check ras log tomorrow.
     
  22. radiot

    radiot Private First Class

    From the peanut gallery

    The depth of knowledge expressed in these forums is impressive, and the neighborlyness is rare.
    D
     
  23. Kodo

    Kodo SNATCHSQUATCH

    it worked!!

    No more autoras.. yeah.. she's happy, i'm happy, everyone's happy.

    Thanks guys!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds