Misc Links
Forum Archive
News Archive
File DB
 

Ads
 

Advertisement
Age of Valor - Ultima Online Free Shard
AoS/SE/ML/Custom - advanced code, dedicated staff, peerless bosses, non overpowered customs + much much more
 

Latest Forum Topics
(Turing + school)|(help + google)==iceteks
Posted by Red Squirrel
on Oct 03 2008, 3:20:24 pm

home page news
Posted by Red Squirrel
on Sep 29 2008, 4:53:08 pm

help a trojan messed up my system.
Posted by rovingcowboy
on Oct 01 2008, 5:01:37 pm

dance crew
Posted by rovingcowboy
on Sep 05 2008, 8:28:45 am

Huge boobs
Posted by Red Squirrel
on Sep 04 2008, 5:15:53 pm

 



Big Brother and Ndisuio.sys
A new Internet phenomenon?
By Red Squirrel


Ndisuio.sys, a very mysterious system file is present in Windows XP and is a driver for wireless things such as wi-fi and bluetooth. However, there have been many issues with this file downloading immense amounts of data and perhaps causing activity that is "big brother"ish.

The fact that hardly any information on this file downloading data is available by Microsoft makes things quite suspicious about it. It has even been noted that it looked as if it was transferring data to major companies like Comcast, Road Runner, Time Warner, BTC and Verizon.

The good news is, it turns out this file duplicates data that is sent/received, so wherever you go, it will also transfer the data to that file but it does not leave the computer/network so it's not spyware. So it's not as much of a big brother situation then it looks like. It simply performs internal communication tasks and stands for NDIS user I/O, hence, NDISUIO. NDISUIO is also used as a driver by many developers as it makes certain wireless network tasks easier such as implementing it for 802.11x connections. Some firewalls also use it as it can get the data in order to filter it.

But duplicating this data can hog resources for no reason, so disabling it is the best thing to do. The data rate of this file's received data is huge, so that indicates that the data transfer is not over the Internet, but locally. So it's just a duplicate of network activity but because it's local everything transfers faster but uses more resources then casual internet usage as there's more data involved at a given time span of 1 second, for example.

To disable this file, go to the control panel, administration tools, services, Wireless Zero Configuration, double click and disable it. This file is probably required to run if you use any linksys wireless devices.

Because I use win2k and not XP I have never experienced anything with this file myself, so this is only a summary of what this file does and what it is for and not based on my own experience but researched information.

-Red Squirrel
IceTeks Owner


Here are a few links having to do with this file:

This was a thread here at Iceteks discussing about this file's strange network behavior.
http://www.iceteks.com/forums/show.php/showtopic/1290

NDIS User Mode I/O (NDISUIO) Version Dependencies
http://www.ndis.com/pcakb/KB01010301.htm

DHCP Does Not Obtain a New Address When EAP Reauthenticates Across Access Points with IP Subnets That Differ
http://support.microsoft.com/default.aspx?kbid=822596

NDIS User-mode I/O Driver
http://msdn.microsof...fndisuser-modeiodriver.asp


Next Page
spacer
126194 Hits Pages: [1] 35 Comments
spacer


Latest comments (newest first)
Posted by Guest on April 04th 2006 (05:05)
pausing but for a moment to see if the widow pops up again ... yes that paticular app is quite annoying.. i might think it was more reputable if it didnt try to run on mutiple ports ... it was like it was scanning for a hole... sagrin.gif now be gone i say.. cheers... tks for the advice

spacer
Posted by Brooklynegg on January 01th 2006 (21:37)
I use Panda as well and just started getting prompted about ndisuio.sys. Like Rob, I have blocked all its attempts to access the Intranet.
spacer
Posted by Matt on January 01th 2006 (21:59)
em194.gif I just tried it and it works! go to start menu > settings > control panel > Administrative tools > double click on services > double click on wireless zero configuration > At "service status:" click on close > on "startup type:" drop down menu to "disable" > then click "apply" vola! no more pesky sygate alarms!
spacer
Posted by DukeP on December 12th 2005 (15:20)
to FENDER

How did you do that, could you write more details, pls.

spacer
Posted by fender on October 10th 2005 (14:51)
i disabled the ndisuio.sys from services and changed that it wont start at system startup. so my sygate doesnt seem to get any more activity to block from outside... i guess im safe again
spacer
View all comments
Post comment


Top Articles Latest Articles
- What are .bin files for? (397374 reads)
- Big Brother and Ndisuio.sys (126194 reads)
- PSP User's Guide (104071 reads)
- SPFDisk (Special Fdisk) Partition Manager (72739 reads)
- Tutorial on how to burn an ISO image (63638 reads)
- Successfully Hacking your iPhone or iTouch (3381 reads)
- Ultima Online Newbie Guide (10949 reads)
- BBcode editor: PHP - The sensible approach (11600 reads)
- The Hitch Hikers guide to "the mouse" (10669 reads)
- Setting up a Backup Server (24273 reads)
corner image

This site best viewed in a W3C standard browser at 800*600 or higher
Site design by Red Squirrel | Contact
© Copyright 2008 Ryan Auclair/IceTeks, All rights reserved