Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Networking Support
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

Networking Support General Networking Support Forum

Reply
 
Thread Tools
Old 12-22-2004, 09:01 AM   #1 (permalink)
Member
 
Join Date: Dec 2004
Posts: 29
OS: 2000 SP4 NT5.00.2195, XP Home 2002 SP2


Network gets cut off every 24 hours. See my hijack log (moved from HJT Help)

Hi. This is my work station. Every day, I have to relogin/reboot to reconnect my network. I think I surfed a spam site and it must of loaded some sort of spyware that cuts me off at a certain hour each night. My IT guys cannot solve the problem. I've used PestPatrol, Ad-Aware, Spybot S&D, and some other program my IT guys used that failed. I'm at my last attempt before he rebuilds my computer.

Any help? Thanks and happy holidays!

Logfile of HijackThis v1.98.2
Scan saved at 7:42:48 AM, on 12/22/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Reuters\DACS\DACS_S~1.EXE
c:\PROGRA~1\NavNT\DefWatch.exe
c:\winnt\system32\domtimec.exe
C:\WINNT\System32\svchost.exe
C:\program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
C:\WINNT\System32\mgabg.exe
C:\PROGRA~1\NavNT\NavRoam.exe
C:\PROGRA~1\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Reuters\Openmsg\cmauthsetup.exe
C:\Program Files\Reuters\Openmsg\cmsetup.exe
C:\Program Files\Reuters\Sun_Jre\1.1\bin\JREW.exe
C:\Program Files\Reuters\Sun_Jre\1.1\bin\JREW.exe
C:\Program Files\Reuters\Openmsg\MessagingService.exe
C:\WINNT\System32\rtmservice.exe
C:\Program Files\Reuters\Sun_Jre\1.1\bin\JREW.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\TIBCO\TIBRV\BIN\rvd.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\PROGRA~1\NavNT\vptray.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\temp\HijackThis.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f412.mail.yahoo.com/ym/log...=2p7ripcpobo8r
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://insite.bankofamerica.com/insite/index.shtml
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customi...earch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://insite.bankofamerica.com/insite/index.shtml
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customi....yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://mail.yahoo.com/?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Bank of America
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconfig.bankofamerica.com
R3 - Default URLSearchHook is missing
O1 - Hosts: 00.35.32.251 ila.sserver.session.rservices.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: IE5_Helper Class - {9C8C1650-2A4C-11D4-8575-000629268C15} - C:\Program Files\Reuters\Shared\RMB\RMN\IE5BandHelper.dll
O3 - Toolbar: Reuters Navigator - {C001E001-146C-11D4-855C-000629268C15} - C:\Program Files\Reuters\Shared\RMB\RMN\ReutersNavigatorBand.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SwdisUsrPCN.B0008C76BB234] "C:\Program Files\Tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "C:\Program Files\Tivoli\swdis\1\wdusrpcn.env"
O4 - HKLM\..\Run: [SwdisUsrPCN.#MOBILE] "C:\Program Files\Tivoli\lcf\dat\1\cache\lib\w32-ix86\lib\w32-ix86\wdusrpcn.exe" "C:\Program Files\Tivoli\swdis\1\wdusrpcn.env"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\PLUGINS\NPDocBox.dll
O15 - Trusted Zone: *.knowledgenet.com
O16 - DPF: Yahoo! MLB StatTracker - http://aud4.sports.dcn.yahoo.com/java/y/mlbst8402_x.cab
O16 - DPF: {2DEF4530-8CE6-41C9-84B6-A54536C90213} (Crystal Report Viewer Control 9) - http://www.final64.com/viewer9/activeXV...viewer.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = corp.bankofamerica.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = corp.bankofamerica.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = corp.bankofamerica.com
ike301 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-22-2004, 01:26 PM   #2 (permalink)
Knower of all that is MS
 
CTSNKY's Avatar
 
Join Date: Aug 2004
Posts: 10,755
OS: (multiple machines) 95, 98, 2K & XP Home & Pro


Your log is clean. I am moving your thread over to Networking for more assistance.
__________________


GO BIG BLUE!!
CTSNKY is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-22-2004, 01:47 PM   #3 (permalink)
Member
 
Join Date: Dec 2004
Posts: 29
OS: 2000 SP4 NT5.00.2195, XP Home 2002 SP2


Quote:
Originally Posted by CTSNKY
Your log is clean. I am moving your thread over to Networking for more assistance.
THank you kind sir. My IT guy says that it's some spyware that is trying to reconnect with it's host. And that the firm's security firewall may just be shutting down to not let the command continue. Not sure....

In fact, I'm going to post a log tommorrow when the connection is severed. Perhaps that can provide more insight what was running/occurred when the connection ended.

THanks again, Mod.

Last edited by ike301 : 12-22-2004 at 02:08 PM.
ike301 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-22-2004, 02:37 PM   #4 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 31,276
OS: XP-Pro, Vista, Linux


Blog Entries: 1
Before and after the connection is severed, do this:

Open a DOS window and type:

IPCONFIG /ALL >C:RESULT.TXT

Open C:\RESULT.TXT with Notepad and copy/paste the entire results here.
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-22-2004, 03:27 PM   #5 (permalink)
Member
 
Join Date: Dec 2004
Posts: 29
OS: 2000 SP4 NT5.00.2195, XP Home 2002 SP2


Quote:
Originally Posted by johnwill
Before and after the connection is severed, do this:

Open a DOS window and type:

IPCONFIG /ALL >C:RESULT.TXT

Open C:\RESULT.TXT with Notepad and copy/paste the entire results here.


Windows 2000 IP Configuration



Host Name . . . . . . . . . . . . : B0008C76BB234
Primary DNS Suffix . . . . . . . : corp.bankofamerica.com
Node Type . . . . . . . . . . . . : Hybrid

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No

DNS Suffix Search List. . . . . . : corp.bankofamerica.com
montgomery.com
bankofamerica.com

Ethernet adapter Local Area Connection 2:



Connection-specific DNS Suffix . : montgomery.com
Description . . . . . . . . . . . : Intel(R) PRO/100 VM Network Connection
Physical Address. . . . . . . . . : 00-08-02-50-6B-1C

DHCP Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 10.223.22.28

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 10.223.22.1

DHCP Server . . . . . . . . . . . : 165.48.113.138

DNS Servers . . . . . . . . . . . : 10.223.171.72
10.223.172.112
Primary WINS Server . . . . . . . : 165.48.113.235

Secondary WINS Server . . . . . . : 171.137.239.248

Lease Obtained. . . . . . . . . . : Wednesday, December 22, 2004 7:39:49 AM

Lease Expires . . . . . . . . . . : Wednesday, January 19, 2005 7:39:49 AM
ike301 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-23-2004, 07:11 AM   #6 (permalink)
Member
 
Join Date: Dec 2004
Posts: 29
OS: 2000 SP4 NT5.00.2195, XP Home 2002 SP2


Just for a compare and contrast, I came in today, and lo and behold, the network again was shut off. So I closed all open programs and did a hijack this log. Maybe a process ran during the night. Anything? The very first log posted is when the network was functional. This log is after the network was killed.

-----------

Logfile of HijackThis v1.98.2
Scan saved at 7:05:55 AM, on 12/23/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Reuters\DACS\DACS_S~1.EXE
c:\PROGRA~1\NavNT\DefWatch.exe
c:\winnt\system32\domtimec.exe
C:\WINNT\System32\svchost.exe
C:\program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
C:\WINNT\System32\mgabg.exe
C:\PROGRA~1\NavNT\NavRoam.exe
C:\PROGRA~1\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Reuters\Openmsg\cmauthsetup.exe
C:\Program Files\Reuters\Openmsg\cmsetup.exe
C:\Program Files\Reuters\Openmsg\MessagingService.exe
C:\WINNT\System32\rtmservice.exe
C:\Program Files\Reuters\Sun_Jre\1.1\bin\JREW.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\TIBCO\TIBRV\BIN\rvd.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\NavNT\vptray.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Reuters\Shared\RMB\RMN\CONTAI~1.EXE
C:\Program Files\Reuters\Shared\RMB\RMNCGS~1.EXE
C:\Program Files\Reuters\NSILight\N2DB_Lite.exe
C:\Program Files\Reuters\NSILight\SSLCON~1.EXE
C:\Program Files\Reuters\NSILight\HNDIPR~1.EXE
C:\PROGRA~1\Adobe\ACROBA~1.0\Acrobat\Acrobat.exe
C:\Program Files\Common Files\Adobe\Web\AOM.exe
C:\Program Files\Reuters\Sun_Jre\1.1\bin\JREW.exe
C:\Program Files\Reuters\Sun_Jre\1.1\bin\JREW.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f412.mail.yahoo.com/ym/log...=2p7ripcpobo8r
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://insite.bankofamerica.com/insite/index.shtml
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://insite.bankofamerica.com/insite/index.shtml
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://mail.yahoo.com/?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Bank of America
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconfig.bankofamerica.com
R3 - Default URLSearchHook is missing
O1 - Hosts: 00.35.32.251 ila.sserver.session.rservices.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: IE5_Helper Class - {9C8C1650-2A4C-11D4-8575-000629268C15} - C:\Program Files\Reuters\Shared\RMB\RMN\IE5BandHelper.dll
O3 - Toolbar: Reuters Navigator - {C001E001-146C-11D4-855C-000629268C15} - C:\Program Files\Reuters\Shared\RMB\RMN\ReutersNavigatorBand.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SwdisUsrPCN.B0008C76BB234] "C:\Program Files\Tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "C:\Program Files\Tivoli\swdis\1\wdusrpcn.env"
O4 - HKLM\..\Run: [SwdisUsrPCN.#MOBILE] "C:\Program Files\Tivoli\lcf\dat\1\cache\lib\w32-ix86\lib\w32-ix86\wdusrpcn.exe" "C:\Program Files\Tivoli\swdis\1\wdusrpcn.env"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\PLUGINS\NPDocBox.dll
O15 - Trusted Zone: *.knowledgenet.com
O16 - DPF: Yahoo! MLB StatTracker - http://aud4.sports.dcn.yahoo.com/java/y/mlbst8402_x.cab
O16 - DPF: {2DEF4530-8CE6-41C9-84B6-A54536C90213} (Crystal Report Viewer Control 9) - http://www.final64.com/viewer9/activ...ivexviewer.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = corp.bankofamerica.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = corp.bankofamerica.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = corp.bankofamerica.com

Last edited by ike301 : 12-23-2004 at 07:14 AM.
ike301 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 01-01-2005, 11:42 AM   #7 (permalink)
Member
 
Join Date: Dec 2004
Posts: 29
OS: 2000 SP4 NT5.00.2195, XP Home 2002 SP2


humble bump
ike301 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 01-01-2005, 02:24 PM   #8 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 31,276
OS: XP-Pro, Vista, Linux


Blog Entries: 1
I was actually looking for the IPCONFIG results when you were disconnected, not the HijackThis log, since that's already been determined to be clean.

What does your IT dept. say about the issue? I'm assuming since this appears to be connected to a large network, they should be looking at the problem.
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 01-02-2005, 07:54 AM   #9 (permalink)
Semi-Retired Manager, Microsoft Support
 
Chevy's Avatar
 
Join Date: Jul 2003
Location: Notlob
Posts: 5,171
OS: Vista Ultimate

My System

To make sure I am reading this right: You can work all day just fine, with no network issues. Except - when you come in in the AM, the network is not accessible.

Do I have it right?

If so, go to the Device Manager (right click on My Computer, select Properties, click on the Hardware tab, then click on the Device Manager button).

Find the entry Network Adapters and click the + next to it. Double Click on the entry for your network card, then click on the Power Management tab. Here you should see a box (checked) that is labeled "Allow the computer to turn off this device to save power.". Uncheck that box.

It could be that your PC, being idle overnight, shuts down the NIC, but doesn't properly bring it back up - thus the reboot.
__________________


“My philosophy, like color television, is all there in black and white”
-M. Python
Chevy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 01-04-2005, 07:19 AM   #10 (permalink)
Member
 
Join Date: Dec 2004
Posts: 29
OS: 2000 SP4 NT5.00.2195, XP Home 2002 SP2


Quote:
Originally Posted by johnwill
I was actually looking for the IPCONFIG results when you were disconnected, not the HijackThis log, since that's already been determined to be clean.

What does your IT dept. say about the issue? I'm assuming since this appears to be connected to a large network, they should be looking at the problem.

DOH! Couldnt access the Net to look at the instructions. The only thing I remembered was IPCONFIG. I forgot the results. I'll repost when this happens. I am not ignoring your post. It just hasn't occured since your post until today....

Thanks again. It's always when you want it to happen, it doesn't.

Quote:
Originally Posted by Chevy
To make sure I am reading this right: You can work all day just fine, with no network issues. Except - when you come in in the AM, the network is not accessible.

Do I have it right?

If so, go to the Device Manager (right click on My Computer, select Properties, click on the Hardware tab, then click on the Device Manager button).

Find the entry Network Adapters and click the + next to it. Double Click on the entry for your network card, then click on the Power Management tab. Here you should see a box (checked) that is labeled "Allow the computer to turn off this device to save power.". Uncheck that box.

It could be that your PC, being idle overnight, shuts down the NIC, but doesn't properly bring it back up - thus the reboot.
Wow very interesting. That sounds like the solution, actually. I did as instructed. Let's see if this solves the problem. Thanks Chevy, I think you might be the hero in this one. I'll update in a few.

ike301
ike301 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 01-04-2005, 03:43 PM   #11 (permalink)
Member
 
Join Date: Dec 2004
Posts: 29
OS: 2000 SP4 NT5.00.2195, XP Home 2002 SP2


Quote:
Originally Posted by johnwill
I was actually looking for the IPCONFIG results when you were disconnected, not the HijackThis log, since that's already been determined to be clean.

What does your IT dept. say about the issue? I'm assuming since this appears to be connected to a large network, they should be looking at the problem.
It went out again. God giveth. God taketh away....

---------------------
Windows 2000 IP Configuration
Host Name . . . . . . . . . . . . : B0008C76BB234
Primary DNS Suffix . . . . . . . : corp.bankofamerica.com
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : corp.bankofamerica.com
montgomery.com
bankofamerica.com

Ethernet adapter Local Area Connection 2:
Connection-specific DNS Suffix . : montgomery.com
Description . . . . . . . . . . . : Intel(R) PRO/100 VM Network Connection
Physical Address. . . . . . . . . : 00-08-02-50-6B-1C
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 10.223.22.28
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 10.223.22.1
DHCP Server . . . . . . . . . . . : 165.48.113.138
DNS Servers . . . . . . . . . . . : 10.223.171.72
10.223.172.112
Primary WINS Server . . . . . . . : 165.48.113.235
Secondary WINS Server . . . . . . : 171.137.239.248
Lease Obtained. . . . . . . . . . : Friday, December 31, 2004 12:37:48 PM
Lease Expires . . . . . . . . . . : Friday, January 28, 2005 12:37:48 PM

--------------
Thoughts??
ike301 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 01-04-2005, 05:11 PM   #12 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 31,276
OS: XP-Pro, Vista, Linux


Blog Entries: 1
I'm thinking that the server is disconnecting you. Does this happen to any other workstation, or just yours? Did you look at the suggest Chevy made?
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 01-04-2005, 09:05 PM   #13 (permalink)
Member
 
Join Date: Dec 2004
Posts: 29
OS: 2000 SP4 NT5.00.2195, XP Home 2002 SP2


Quote:
Originally Posted by johnwill
I'm thinking that the server is disconnecting you. Does this happen to any other workstation, or just yours? Did you look at the suggest Chevy made?
I did. Only mine. I would say the server supports at least 100 people, and that's just my floor.

The disconnect occurred AFTER using Chevy's suggestion.

Hmmmm.... My IT guys says that it could be that I have some sort of spyware embedded and that it trys to contact it's host at a certain hour of the night. He added that the internal firewall/security of our company is seeing this and blocking the connection and possibly severing my connection all together. Is this possible?
ike301 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 01-05-2005, 05:51 PM   #14 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 31,276
OS: XP-Pro, Vista, Linux


Blog Entries: 1
Quite possible, I'd do a complete spyware/malware/virus scan to rule out that possibility.
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 01-07-2005, 07:53 AM   #15 (permalink)
Member
 
Join Date: Dec 2004
Posts: 29
OS: 2000 SP4 NT5.00.2195, XP Home 2002 SP2


Quote:
Originally Posted by johnwill
Quite possible, I'd do a complete spyware/malware/virus scan to rule out that possibility.

how to remove these?

c:winnt\system32\r48slel71hq.dll
c: program\admilliservice\admilliserv.exe
c: winnt\system32\fzgrbz.exe

keeps saying it's in use. they were found using lavasoft adaware se.
ike301 is offline