Forum Moderators: phranque

Message Too Old, No Replies

Lots of connections to nbname

         

Natashka

2:43 am on Jan 30, 2003 (gmt 0)

10+ Year Member



Since I've changed the ISP, I started getting these endless connections to my computer's NetBios name. They are coming all over the world, all possible IPs, like about every minute. My firewall blocks those connections. Usually they try to connect via some application called MSDTCW.EXE, but it may be any application on my PC. I am on Windows 98, and I am absolutely sure I don't have any viruses or trojans on my machine.

It all started with my new Dial-up number, kind of "dirty" number. :) My ISP is a reseller, but actually I'm connected via o1.com (for example, NetZero uses them, too). Another dial-up number they have sends some kind of routed traffic through my machine.. I noticed it really slows down my connection towards the end of the day, sometimes I even have to restart my machine, it gets fast again after restarting.

Why is it doing it? I heard there may be a router somewhere, but what is exactly "a router"? And is it bad to have that router? And what should I do, maybe I shouldn't block those connections?

Brett_Tabke

1:49 pm on Jan 30, 2003 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Are you running SQL on that machine?

msdtcw.exe [myweb.tiscali.co.uk]:

The Microsoft Distributed Transaction Coordinator is a transaction manager which permits client applications to include several different sources of data in one transaction and which then coordinates committing the distributed transaction across all the servers that are enlisted in the transaction. MSDTC runs on all Windows platforms and is installed by applications which need to use it, such as the Microsoft’s Personal Web Server, or Microsoft SQL Server.

Sounds to me like you have a worm/virus. I would run a scan for everything, but virus and spyware.

Natashka

1:18 am on Jan 31, 2003 (gmt 0)

10+ Year Member



Yes, I have a Microsoft Personal Web Server running (as I use MS FrontPage).
Oh gosh, I've scanned and re-scanned my PC both with Norton and Kaspersky, and both haven't found nothing! I have all current Microsoft patches installed... Besides, it all started the same day and same minute when I've changed my provider and dialed that new number...

I thought maybe there is somebody else using o1.com as a provider, or at least if it IS a worm, what file to look for, as the antivirus programs don't detect it.