Jump to content

Yet another trojan query (sorry bout this)


Guest Dan
 Share

Recommended Posts

Every time I restart the system (having used Inept Pig's link to solve the qttask problem), something tries to connect to the web but cause I don't allow auto dial up it has to ask first.

The site it's trying to access is called phoenix.secure-tech.net however I had a look and I can't find it at a www address or in google at all.

Neither AVG or Gav report a problem and nor does Spybot search and destroy.

Can anyone tell me what it is, how I can trace it to the original file on the pc, whether I should be concerned about it and how I can stop the damn thing trying to connect to the web?

Cheers

Dan

Link to comment
Share on other sites

Thanks for the responses folks.

I've grabbed the file mark2 suggested and will run it shortly.

I had a look at the site that Nellie2 found (I'd looked for the whole expression on the web but hadn't thought to shave anything off in a search - doh!).

I tried the knowledgebase on the site but got bounced to a dead page.

It's just weird that I can't find a cookie and that all the security stuff can't spot anything. I mean it may even be a perfectly legitamate site for a program I'm running that I just can't remember. But it's still weird.

Will run the program and come back.

Cheers again.

Link to comment
Share on other sites

Not convinced this is going to help. I can't see anything out of place.

StartupList report, 21/03/2003, 23:08:12

StartupList version: 1.52

Started from : C:\MyOwnTemps\Utilities\startuplist\startuplist152\StartupList.EXE

Detected: Windows XP (WinNT 5.01.2600)

Detected: Internet Explorer v6.00 (6.00.2600.0000)

* Using default options

==================================================

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\PROGRA~1\Grisoft\AVG6\avgserv.exe

C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe

C:\PROGRA~1\Iomega\System32\ActivityDisk.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\Sygate\SPF\Smc.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\Tablet.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\CTHELPER.EXE

C:\Program Files\Iomega\DriveIcons\ImgIcon.exe

C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe

C:\Program Files\Microsoft Hardware\Mouse\point32.exe

C:\PROGRA~1\MICROS~2\GAMECO~1\Common\SWTrayV4.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\explorer.exe 

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\Iomega\AutoDisk\AD2KClient.exe

C:\PROGRA~1\CACHEMAN\Cacheman.exe

C:\Art&Words\MyPrograms\WordPerfect\Register\Remind32.exe

C:\MyOwnTemps\Utilities\startuplist\startuplist152\StartupList.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Common Startup:

[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]

Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

Corel Registration.lnk = C:\Art&Words\MyPrograms\WordPerfect\Register\Remind32.exe

EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\E_SRCV02.EXE

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]

UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

NvCplDaemon = RUNDLL32.EXE NvQTwk,NvCplDaemon initialize

nwiz = nwiz.exe /install

WINDVDPatch = CTHELPER.EXE

UpdReg = C:\WINDOWS\UpdReg.EXE

Jet Detection = C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe

Iomega Startup Options = C:\Program Files\Iomega\Common\ImgStart.exe

Iomega Drive Icons = C:\Program Files\Iomega\DriveIcons\ImgIcon.exe

AVG_CC = C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP

POINTER = point32.exe

SmcService = C:\PROGRA~1\Sygate\SPF\Smc.exe -startgui

SideWinderTrayV4 = C:\PROGRA~1\MICROS~2\GAMECO~1\Common\SWTrayV4.exe

QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime

Windows = C:\WINDOWS\explorer.exe 

--------------------------------------------------

Autorun entries from Registry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

CTFMON.EXE = C:\WINDOWS\System32\ctfmon.exe

MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background

Iomega Active Disk = C:\Program Files\Iomega\AutoDisk\AD2KClient.exe

Cacheman = C:\PROGRA~1\CACHEMAN\Cacheman.exe

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*

SCRNSAVE.EXE=*INI section not found*

drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe

SCRNSAVE.EXE=*Registry value not found*

drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*

HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Enumerating Browser Helper Objects:

(no name) - C:\Program Files\DAP\DAPBHO.dll - {0000CC75-ACF3-4cac-A0A9-DD3868E06852}

--------------------------------------------------

Enumerating Download Program Files:

[{41F17733-B041-4099-A042-B518BB6A408C}]

CODEBASE = http://a1540.g.akamai.net/7/1540/52/200212...meInstaller.exe

[intraLaunch.MainControl]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\INTRALAUNCH.OCX

CODEBASE = file://E:\system\IntraLaunch.CAB

[shockwave Flash Object]

InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx

CODEBASE = http://download.macromedia.com/pub/shockwa...ash/swflash.cab

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll

CDBurn: C:\WINDOWS\system32\SHELL32.dll

WebCheck: C:\WINDOWS\System32\webcheck.dll

SysTray: C:\WINDOWS\System32\stobject.dll

--------------------------------------------------

End of report, 5,488 bytes

Report generated in 0.110 seconds

Command line options:

/verbose - to add additional info on each section

/complete - to include empty sections and unsuspicious data

/full - to include several rarely-important sections

/force9x - to include Win9x-only startups even if running on WinNT

/forcent - to include WinNT-only startups even if running on Win9x

/forceall - to include all Win9x and WinNT startups, regardless of platform

/history - to list version history only

Any ideas folks?

Link to comment
Share on other sites

I don't think you need it ?

In Nellie2's thread "Strange goings on" Mark2 advised this :-

You should then go to C:\windows\downloaded program files and remove the following Active X Control:

IntraLaunch.MainControl]

InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\INTRALAUNCH.OCX

CODEBASE = file://L:\supercd\IntraLaunch.CAB[{41F17733-B041-4099-A042-B518BB6A408C}]

CODEBASE = http://a1540.g.akamai.net/7/1540/52/200112...meInstaller.exe

Link to comment
Share on other sites

A look at This thread suggests that

UpdReg = C:\WINDOWS\UpdReg.EXE

can be responsible for some odd connections.

Block C:\WINDOWS\system32\lsass.exe using Sygate if not already blocked

As Boris says the 2 Active X files you can dispense with,

CODEBASE = http://a1540.g.akamai.net/7/1540/52/200112...meInstaller.exe may be to do with Trend Housecall online A/V check, if so it will reinstall next time you use trend housecall.

and Intralaunch is a spyware component.

Does sygate list an Ip address for the offenders destination?

Does it only try once?

Does it show up in processes as using cpu/memory at the same time it is trying to conect ?

Other than that it is going to be a case of following Madboys suggestion in Msconfig start up until we get a hit.

But no immediate nasties spring into view.

Link to comment
Share on other sites

Haven't had much time to work on this but I had already got the

Block C:\WINDOWS\system32\lsass.exe using Sygate suggestion done anyway.

As a curiosity and to try and trace what program was launching the dial up I let it dial part way and then had Sygate refuse it's link.

This showed the program in question to be c:\Windows\explorer.exe

Now why on earth would a part of windows be trying to dial this site?

If I block this off am I going to be shooting myself in the foot as far as internet connection goes?

(I know i know, suck it and see.)

Will try it in a few days time as shifts allow <_<

Link to comment
Share on other sites

Do you have a Phoenix mobo ?

Got this reply elsewhere.

I assume this is one of the new Phoenix Motherboard which have this integrated in the BIOS! Aaaaaaaaaaaagh!! Not good I know  You need to disable PhoenixNet in the BIOS to stop it happening I'm afraid.
Link to comment
Share on other sites

The motherboard is an MSI (K2 ultra I think) not a Phoenix.

Re the Bigfix query have to say I don't know what it is though I assume it's some kind of pc health check utility. The only pc health things on my machine (to my knowledge) are GAV and AVG virus killers, Adaware 6 and Spybot Search and destroy.

As it's now weekdays I may go to the site and see if I can query them as to why an unknown item on my pc is trying to contact their site.

Link to comment
Share on other sites

Tried replying to this yesterday but the site was sticky.

My bios are American megatrends not phoenix.

I contacted the secure-tech.net part of the link and they said that the phoenix part was a customer of theirs and they'd pass the query on. This was fine though a minor bit of paranoia made me check the details on the mail sent to me from secure-tech.net and the responder's mail is @us.army.mil which pardon my paranoia is a little worrying. What the hell have I tapped into and who's gonna off me?!! :ph34r:

Regaining my sanity a little and with regard to your Registry suggestion, is there a really safe way to take a peek? It's something I've always avoided - I'm kind of club handed and as likely to do damage just stepping in and out.

Cheers

Dan

Link to comment
Share on other sites

It is safe if you want to take a peek in the registry, run regedit, then file>export, export to the desktop is simplest. Then should any thing go wrong you can just d/click and merge it back in.

Also set a restore point beforehand, belt and braces :D

to find the references to phoenixsecuretech. run regedit then F3 key brings up the find function enter the name of the offender and click on find and away you go.

If you post where all the references are found I can have a quick look 1st if you like. ;)

BTW I thought pressganging went out in the last century :D

Link to comment
Share on other sites

Mark2 - you're so right and I'm real sorry to be such a pain. You're too helpful. Will go away and try some self help for a while and then come back if I'm still stumped.

Many thanks for all your input.

Dan

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy