Results 1 to 6 of 6

Thread: NDIS user mode I/O driver

  1. #1
    Join Date
    Sep 2004
    Posts
    81

    NDIS user mode I/O driver

    Since installing Sygate Personal Firewall i have found that it keeps on downloading something from internet. It carries out its downloading process even when i block the ipaddress from where it tries to download. I see incoming traffic as blocked and out going traffic as zero. I am not able to make out what exactly is the role of NDIS user mode I/O driver, its there in C:\WINDOWS\System32\DRIVERS\ndisuio.sys. It description says "It performs internal communications tasks within Windows". I will like to know what exactly is it and what the hell it keeps on downloading???

  2. #2
    Join Date
    Jan 2006
    Posts
    2,257

    Re: NDIS user mode I/O driver

    I guess Wireless Zero Configuation service might be using ndisuio.sys. There are possibilities that a spyware might be using it as well. In that case Go to Administrative Tools/Services chekc out for "Wireless Zero Configuration" and disable it fro there. If you are having a wireless setup on the machine than there is no need of keeping Wireless Zero Configuration running. Other than these you should also inspect the processes that might be running from task manager.

  3. #3
    Join Date
    Sep 2004
    Posts
    81

    Re: NDIS user mode I/O driver

    Disabling Wireless Zero Configuration was helpful, i wanted to share that some days back i came across "[181] DCE BIND to potentially vulnerable RPC DCOM security log of the firewall. It has blocked all incoming and outgoing traffic in port 181 and 135, i wanted to know if NDIS might be related to it? any idea?

  4. #4
    Join Date
    Jan 2006
    Posts
    2,257

    Re: NDIS user mode I/O driver

    If you are having a firewall protecting port 135 than you dont have to worry about anything. I wanted to share that RPC is used by Wireless Zero Configuration but as you have shut it down, there shouldn't be any problem.RPC which is RPCRT4.dll is used by svchost.exe. In case you dont see svchost.exe running than you system might have got affected by trojan. You will have to run a through scan to eliminate it as soon as possible. If that's not the case and you want to keep Wireless Zero Configuration running than you can use BlackIce. You can use it for shutting down ndisuio.sys from communicating but still allowing it to run.

  5. #5
    Join Date
    Sep 2004
    Posts
    81
    Thanks for sharing those extra information with me, I will check out BlackIce for shutting down ndisuio.sys from communicating but still allowing it to run. Hope running it wont create any mess further.

  6. #6
    Join Date
    Nov 2009
    Posts
    1

    Re: NDIS user mode I/O driver

    I was running in to exactly the same issue and while looking after a fix for this i came across this thread. Was able to fix it out by the very first solution posted by Mr. Boo Bear, your solution was really time saver for me.
    Last edited by WazzoTheMartian; 02-11-2009 at 04:55 AM.

Similar Threads

  1. Replies: 4
    Last Post: 01-04-2012, 04:56 PM
  2. Avg firewall says ndis driver not found
    By $Bird$ in forum Networking & Security
    Replies: 9
    Last Post: 15-01-2012, 04:51 PM
  3. How to reset User Password via single user mode in mac os x
    By Jay Scott in forum Operating Systems
    Replies: 3
    Last Post: 10-11-2010, 07:00 PM
  4. Symantec Tdi and Ndis Driver for Vista
    By zaid in forum Operating Systems
    Replies: 4
    Last Post: 24-04-2009, 11:34 PM
  5. User mode driver framework (umdf) install error
    By tunayx in forum Windows XP Support
    Replies: 1
    Last Post: 04-10-2008, 06:51 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,714,048,169.62155 seconds with 17 queries