Houzz Logo Print
loralee_gw

computer is dialing up to the ISP by itself

16 years ago

I had to buy a new computer this winter and now that I have a new one I have a problem that I am absolutely going nuts trying to solve. When I reboot the computer the computer will also automatically dial out to my ISP. I can cancel the dialing up to the ISP but then when I do the computer will just waite and dial up at a later time. Any thoughts on what is causing this. I have turned off various programs to see if it was causing the problem but still haven't found the cause. I have wen't into MSCONFIG, and into the general tab and turned off some of the programs to see if any of these here may be causing it. The ones I turned off here hasn't stop the problem. I haven't turned off all of the programs in start up not knowing if turning off any of the programs here may cause the computer to crash. Does anyone out in the audience know if by turning off any of these programs in the start up tab might cause the computer to crash? THANK YOU ALL FOR THE HELP YOU CAN GIVE ON THIS.

Comments (26)

  • 16 years ago
    last modified: 11 years ago

    it sounds like you need to go into your network connections to that dial up connection and change your dial settings for when to dial out and how often to try dialing out.

    If you had a firewall on it that should give you the info on what exactly is trying to connect and to where.

    what version of windows do you have on this pc?
    I would not be messing in msconfig, there are much better ways to adjust things than using msconfig. going through services is better or using a program that can tell you what exactly is starting up and that you can adjust through the program. By the makers of malwarebytes you might try
    StartUpLite

  • 16 years ago
    last modified: 11 years ago

    Windows XP home Edition is on this computer. We use Firefox Browser.
    How do you check in the firewall to tell what is trying to connect? In another post you mentioned having a 2 way firewall installed and turned on. How does this help with the computer automatically dialing.
    We are using Windows XP.
    What firewall do you suggest?

    Is there only on Malwarebytes software available or what do I look for? I see there are some free downloads.
    I did a system check using System Mechanic 6 today.

    Thanks a whole lot for your input.

  • Related Discussions

    Modem-Dial Up Problem

    Q

    Comments (5)
    With Win XP, I've always had it reconize modems and if it says the device is working properly should mean the modem is ok. I'd check that the phone line is pluged into the right jack, sometimes there are two jacks, one called phone and the other line, it will only dial out on the right one, that is if you have two of them on the back of your computer. Might recheck the access numbers for that area for your ISP. Also, with IE (Internet Explorer), click Tools/ Internet Options/ Connections Tab/ mine are set to never dial a connection, you could experiment with the other two, also with settings, maybe automatically detect settings. If it is a driver problem, right click My Computer/ Properties/ Hardware Tab/ Device Manager/ and look a yellow exclamation mark.
    ...See More

    computer dials up by itsself

    Q

    Comments (4)
    If (shellclassinfo)Localized resource name=@%systemroot%\system32\shell32.d77.-21787 comes up in note pad see link. As far as the dialing have no clue I guess that message could have something to do with it. Might take it back if it's still covered. If that's possible. Here is a link that might be useful: support.microsoft.com
    ...See More

    Using OE; must my email acct be the one thru my current ISP

    Q

    Comments (3)
    Most isp will allow the mail to come in from another isp, but not all will allow it to send email out. She can, however, get her mail from mail2web.com and also reply there too, if she wishes, and it will work out fine. When I am on vacation, I use mail2web from friends and relatives computers, and take care of all my mail from there, for both my isp's. :-)Cat
    ...See More

    Getting rid of dial-up, need a good email server

    Q

    Comments (8)
    For personal email, I am using an old copy of Netscape ver. 4.7. It's no good for browsing anymore because it does not support newer features and calls in the later versions of Windows, but it works great as an email utility. You can browse the internet with Internet Explorer and bring up Netscape when you need to access email. Both Netscape and IE will run simultaneously without interferring with each other. Just make sure that for the first time Netscape runs and the panel pops up, "do you want to make Netscape your default brouser", you answer, "No". IE will remain the default and Netscape will be secondary. You can start and stop Netscape at any time as needed while IE remains connected on-line. I use IE to log into my ISP's mail server to read and manage my mail on the mail server, but when I want to download emails to my computer, I fire up Netscape to do this. In this way, I can purge my email of spam and any messages that I do not want to keep, then download only the "keepers".
    ...See More
  • 16 years ago
    last modified: 11 years ago

    the link I provided in my post above is to the program which helps you control your start ups it is start up lite, it is not malwarebytes but is made by the same people that created malwarebytes.

    zone alarm free is a good choice and one I have used. The firewall in windows xp is not a 2 way firewall so it would not tell you what is trying to phone out and connect where as a 2 way firewall tells you that also and you can look at the details on what programs are trying to do the dial out.
    spyware and malware are notorious for that type of action so if you have not installed and run a FULL scan with malwarebytes free then I would suggest doing that also.
    How to download and install Malwarebytes' Anti-Malware application for Windows computers

    ZoneAlarm

    have you checked what your dial up settings are for your connection?

  • 16 years ago
    last modified: 11 years ago

    What Anti Virus or Security Suite like Norton or McAfee was installed on the machine when you bought it? Need the full name of it.

  • 16 years ago
    last modified: 11 years ago

    The connection is set at Never Dial a connection;

    Avast is the anti virus on the computer.

    Have not used Norton or McAfee on this computer

    One interesting this I saw. The other post where someone had written in with the same problem this week Lives 3 miles Springfield Missouri and I am 1/2 mile from Springfield Oregon. Wonder is spyware is targeting towns with the name of Springfield!
    Thanks

  • 16 years ago
    last modified: 11 years ago

    If you think that it's spyware, run a Malwarebytes scan and a SuperAntiSpyware scan.

    Try running a Malwarebytes scan. Let it remove everything it finds. So make sure you click remove selected after scan is finished. Also after you download the free version it's important to click the update tab and let Malwarebytes update before scanning with it.

    Post the Malwarebytes log if it's confusing for you to read. Probably should post it anyway.

    You can Google SuperAntispware fee and find it easy.

    These are on demand scanners and can be kept on the machine and used once a month. They will not interfere with Avast or anything.

    Here is a link that might be useful: malwarebytes

  • 16 years ago

    This may take a little time: One by one activate each application that you have installed on the system first focusing on any recent installs or upgrades. After activating check the application's Preferences, Tools, Options, etc. for any checked privilege allowing automatic checking for updates. Uncheck them all.

    DA

  • 16 years ago
    last modified: 11 years ago

    DA this is exactly what we have been doing since January trying to check everything that is running on the task bar. But really getting no where.
    We do have Malwarebites downloaded now.

  • 16 years ago
    last modified: 11 years ago

    Well sorry to say Malwarebites did not help stop the dialing.

    Do I understand that Zone Alarm is the two way firewall? If so we will download this tomorrow and see if we can check as to what is trying to connect to the internet.

  • 16 years ago
    last modified: 11 years ago

    If you have time lets see if a Hijack log shows anything, the log will reveal most start up programs and it really is easy to do, download it do a system scan and safe a log file paste in a reply. Here are full instructions below.

    Click Here to download HJTInstall.exe
    Save HJTInstall.exe to your desktop.
    · Doubleclick on the HJTInstall.exe icon on your desktop.
    · By default it will install to C:\Program Files\Trend Micro\HijackThis .
    · Click on Install.
    · It will create a HijackThis icon on the desktop.
    · Once installed, it will launch Hijackthis.
    · Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
    · Click on "Edit > Select All" then click on "Edit > Copy" and Paste the entire contents of the log (no attachments) into your next post.
    DO NOT use the AnalyzeThis button, its findings are dangerous if misinterpreted.
    DO NOT have Hijackthis fix anything yet. Most of what HJT lists will be harmless or even required by your Operating System.

  • 16 years ago
    last modified: 11 years ago

    Thank you, We will try this tomorrow.

  • 16 years ago
    last modified: 11 years ago

    Ok Thank you for responding. We may see other things too! and as I said it's easy to do..

  • 16 years ago

    Not just the ones in operation and revealed on the Taskbar, you have to do all of them including the ones not in service. It could quite easily be an on-demand application configured to check for updates.

    DA

  • 16 years ago
    last modified: 11 years ago

    Zep here is the information from HJT

    Logfile of Trend Micro HijackThis v2.0.3 (BETA)
    Scan saved at 4:26:51 PM, on 3/28/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
    C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\Web Accelerator\slipcore.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iolo\System Mechanic 6\PopupBlocker.exe
    C:\Program Files\Web Accelerator\slipgui.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5403
    R3 - URLSearchHook: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - (02478D38-C3F9-4EFB-9B51-7695ECA05670) - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Prefetch - (A66AA08A-9BF0-4e87-99E6-6972731D6B99) - C:\Program Files\Web Accelerator\Prefetch.dll
    O3 - Toolbar: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
    O4 - HKLM\..\Run: [LTCM Client] C:\Program Files\LTCM Client\ltcmClient.exe /startup
    O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [SlipStream] "C:\Program Files\Web Accelerator\slipcore.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
    O4 - HKCU\..\Run: [System Mechanic Popup Blocker] "C:\Program Files\iolo\System Mechanic 6\PopupBlocker.exe"
    O4 - Global Startup: 1Dial Web Accelerator.lnk = C:\Program Files\Web Accelerator\slipgui.exe
    O8 - Extra context menu item: Show All Original Images - res://C:\Program Files\Web Accelerator\gui_resource.dll/327
    O8 - Extra context menu item: Show Original Image - res://C:\Program Files\Web Accelerator\gui_resource.dll/328
    O9 - Extra button: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O16 - DPF: (30528230-99f7-4bb4-88d8-fa1d4f56a2ab) (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O17 - HKLM\System\CCS\Services\Tcpip\..\(2009C16B-C687-4671-8391-3898B186FEE3): NameServer = 209.244.0.3 209.244.0.4
    O22 - SharedTaskScheduler: Browseui preloader - (438755C2-A8BA-11D1-B96B-00A0C90312E1) - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - (8C7461EF-2B13-11d2-BE35-3078302C2030) - C:\WINDOWS\system32\browseui.dll
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: OPTISAFEService - Unknown owner - C:\Sentinel Web\OPTISAFE_Service.Exe

    --
    End of file - 5264 bytes

  • 16 years ago
    last modified: 11 years ago

    Hi

    I see a few regular things that don't need to be running so lets remove them using the Hijackthis program.

    Close all windows only have Hijackthis open.Do a System Scan Only When the scan opens, place a check mark in the following entries.

    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

    Once the check marks are in place.
    Click Fix Checked
    Close Hijackthis.
    Reboot the computer

    Find and delete this file (ALCMTR.EXE) if still there.

    That's it for Hijackthis program.

    Are you using an Accelerator?

    These files relate to the Accelerator program: There's nothing wrong with them but I wonder if it could be an issue somewhere.

    C:\Program Files\Web Accelerator\slipcore.exe
    C:\Program Files\Web Accelerator\slipgui.exe

    O4 - HKLM\..\Run: [SlipStream] "C:\Program Files\Web Accelerator\slipcore.exe"

    O4 - Global Startup: 1Dial Web Accelerator.lnk = C:\Program Files\Web Accelerator\slipgui.exe

    O8 - Extra context menu item: Show All Original Images - res://C:\Program Files\Web Accelerator\gui_resource.dll/327

    O8 - Extra context menu item: Show Original Image - res://C:\Program Files\Web Accelerator\gui_resource.dll/328

    So do the fixes first.

    Let me know what the web Accelerator programs is, perhaps that could be an issue unless you know it's not. We could disable it and see if it helps.

  • 16 years ago
    last modified: 11 years ago

    Yes, I absolutely use Accelerator. With dial up this software is the only thing that keeps me sane as the dial up is soooo very slow. So slow the computer is almost impossible to use without it.

    The accelerator is called slip stream and is offered with the internet dial up provider.

    I will log off and do the above fix.

  • 16 years ago
    last modified: 11 years ago

    I did the two above items you said to. I rebooted and the ALCMTR.EXE was still gone. The minute the computer restarted the computer connected online by itself.

    We have spoken to the internet provider and they claim the acclerator is not an issue???

    There is a place where we have disabled the accelerator to see in the past if that was it and it still dialed out. Maybe we should uninstall it? The company just made a new version of the accelerator two weeks ago and no change with the newer version. Not to say its not the accelerator.

    What do you suggest next?

  • 16 years ago
    last modified: 11 years ago

    Does you Internet service provider know what this is just mention the # in bold see if they know, it's probably legit

    O17 - HKLM\System\CCS\Services\Tcpip\..\(2009C16B-C687-4671-8391-3898B186FEE3): NameServer = 209.244.0.3 209.244.0.4

  • 16 years ago
    last modified: 11 years ago

    Can't find much about it,(O17 - HKLM\System\CCS\Services\Tcpip\) if we fixed it it could break the Internet connection. Some ISP's do use these entries and they are needed.

  • 16 years ago
    last modified: 11 years ago

    I did find something on that. looks legit....

    OrgName: Level 3 Communications Inc.
    OrgID: LVLT
    Address: 1025 Eldorado Blvd.
    City: Broomfield
    StateProv: CO
    PostalCode: 80021
    Country: US
    NetRange: 209.244.0.0 - 209.247.255.255
    CIDR: 209.244.0.0/14
    NetName: LEVEL3-CIDR
    NetHandle: NET-209-244-0-0-1
    Parent: NET-209-0-0-0-0
    NetType: Direct Allocation
    NameServer: NS1.LEVEL3.NET
    NameServer: NS2.LEVEL3.NET
    Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
    RegDate: 1998-05-22
    Updated: 2001-05-30
    RTechHandle: LC-ORG-ARIN
    RTechName: level Communications
    RTechPhone: 1-877-453-8353
    RTechEmail: ipaddressing@level3.com

  • 16 years ago
    last modified: 11 years ago

    Is the above code you checked out for the internet provider or the accelerator provider? So, you don't need me to call them tomorrow to ask about the above code?

  • 16 years ago
    last modified: 11 years ago

    Good question I don't know! Whoever this is Level 3 Communications Inc. Would be responsible for the entry and the entry is needed. If it were Malware I would know. Malware does install there at times, that's why I got curious with it.

    Not really sure what else to check here for now....

    Except for other advice that was given, I was hoping to see something obvious here but don't.

  • 16 years ago
    last modified: 11 years ago

    No since we found it's legit you don't need to call anyone!

  • 16 years ago
    last modified: 11 years ago

    Thank you for all the time you spent trying to help.

  • 16 years ago
    last modified: 11 years ago

    I reran the Malwarebytes and while it was running the Avast Blocked two trojan horse and asked if it was a false/positive. How do I determine if they are false.

    One is Win32:Refroso-AA (Trj> from program files cryptomathic which Is a software I use.

    The other is Win32: Trojan-gen from system volume information\_restore"6FF26D1B-3FB...A0005781.EXE

    Avast put these in a chest.

    Are these ok to take out of the chest?

  • 16 years ago
    last modified: 11 years ago

    Win32:Refroso, I don't like the looks of this and my abilities end here. It could be a false positive. But with the symptoms you have and some of the information I have found would feel much better if you go to a malware removal forum for more thorough scans and mostly an expert opinion.

    At this time I am going to supply a link where we send folks for Malware issues. Please follow the instructions at the link provided and post the required logs, it's important you post the logs. You will need to register and create an account there here is link, Please link back to here too so they know I sent you.

    Let us know what the outcome is.

Sponsored