India Broadband Forum


Hostile driver

This is a discussion on Hostile driver within the Computer Security forums, part of the Computer technology category; Some driver is continuously trying to access internet and sygate firewall i am using is blocking it. It is in ...

Go Back   India Broadband Forum > Computers > Computer technology > Computer Security

India Broadband Forum


                      

Reply

 

LinkBack Thread Tools Display Modes
Old 04-20-09, 02:00 PM   #1
meetdilip
Guest
 
Posts: n/a
Default Hostile driver

Some driver is continuously trying to access internet and sygate firewall i am using is blocking it. It is in windows folder and is not a windows driver. Please tell me what to do. How to find out which program it represents? Please help me.

The name is NDIS user mode I/O driver

Location : C:\WINDOWS\system32\DRIVERS\ndisuio.sys

Last edited by meetdilip; 04-20-09 at 02:19 PM.
  Reply With Quote
Old 04-20-09, 05:28 PM   #2
Bronze Member
 
Raghav_K's Avatar
 
Join Date: Apr 2009
Age: 23
Posts: 101
Rep Power: 1
Raghav_K is on a distinguished road
Default

Hey it's not spyware.. it's a microsoft file only and many people have problems with it....

Check these linx to find more and to remove it (googled em )..

Big Brother and Ndisuio.sys [Page 1 of 1]

ndisuio.sys Windows process - What is it?

and finally check this too..

http://www.cultkanaal.nl/Tech/google-bart.jpg jk
Raghav_K is offline   Reply With Quote
Old 04-20-09, 07:29 PM   #3
meetdilip
Guest
 
Posts: n/a
Default

Important: Some malware camouflage themselves as ndisuio.sys, particularly if they are located in c:\windows or c:\windows\system32 folder. Thus check the ndisuio.sys process on your pc whether it is pest. We recommend Security Task Manager for verifying your computer's security. It is one of the Top Download Picks of 2005 of The Washington Post and PC World.
  Reply With Quote
Old 04-21-09, 12:32 AM   #4
Bronze Member
 
Raghav_K's Avatar
 
Join Date: Apr 2009
Age: 23
Posts: 101
Rep Power: 1
Raghav_K is on a distinguished road
Default

^ woah din know that...
Raghav_K is offline   Reply With Quote
Old 04-21-09, 01:21 AM   #5
Platinum Member
 
just4kix's Avatar
 
Join Date: Dec 2007
Location: Pune
Posts: 8,899
Blog Entries: 6
Rep Power: 19
just4kix is a splendid one to beholdjust4kix is a splendid one to beholdjust4kix is a splendid one to beholdjust4kix is a splendid one to beholdjust4kix is a splendid one to beholdjust4kix is a splendid one to beholdjust4kix is a splendid one to beholdjust4kix is a splendid one to behold
Default

This particular driver is often apt to "drinking and driving".
just4kix is offline   Reply With Quote
Old 04-21-09, 05:58 PM   #6
ShAdOwCoN
Guest
 
Posts: n/a
Default

Quote:
Originally Posted by meetdilip View Post
Important: Some malware camouflage themselves as ndisuio.sys, particularly if they are located in c:\windows or c:\windows\system32 folder. Thus check the ndisuio.sys process on your pc whether it is pest. We recommend Security Task Manager for verifying your computer's security. It is one of the Top Download Picks of 2005 of The Washington Post and PC World.
you can figure out if its a malware or a system process , simply by looking at its Destination

Many malware disguise themselves as different process not just this particluar process ......

Quote:
Originally Posted by meetdilip View Post
Some driver is continuously trying to access internet and sygate firewall i am using is blocking it. It is in windows folder and is not a windows driver. Please tell me what to do. How to find out which program it represents? Please help me.

The name is NDIS user mode I/O driver

Location : C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Just by looking at its location i can tell you that its perfectly safe process
because

1) like all system processes its located in the system32 folder
2) a virus can replicate itself , but it can never replace/delete another file without the user's explicit knowledge .....
3) so as u know from the internet that ndisuio is a system process ( so its should have been present in the system32 folder) and it can never be replaced by a virus u can be sure that its a safe process ....

but if the same exists in some other folder , u can be sure its a virus

Last edited by ShAdOwCoN; 04-21-09 at 05:59 PM. Reason: Automerged Doublepost
  Reply With Quote
Reply

Tags
driver, hostile

Thread Tools
Display Modes

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
USB driver for TKD modem coolmustang MTNL broadband 2 07-13-09 02:12 PM
Need Driver for TKD 318 EUI !! groovyanubhav MTNL broadband 2 07-29-08 11:27 AM
Windows Driver Updates may corrupt your modem driver (UT-300R2U) just4kix BSNL broadband 0 01-20-08 07:07 PM
Driver for SMC7003USB V.2 - Win XP Subrat Tata Indicom broadband 1 05-04-07 12:09 AM


All times are GMT +5.5. The time now is 10:50 AM.


India Broadband Forum