Guest Dan Posted March 21, 2003 Report Share Posted March 21, 2003 Every time I restart the system (having used Inept Pig's link to solve the qttask problem), something tries to connect to the web but cause I don't allow auto dial up it has to ask first. The site it's trying to access is called phoenix.secure-tech.net however I had a look and I can't find it at a www address or in google at all.Neither AVG or Gav report a problem and nor does Spybot search and destroy.Can anyone tell me what it is, how I can trace it to the original file on the pc, whether I should be concerned about it and how I can stop the damn thing trying to connect to the web?Cheers Dan Quote Link to comment Share on other sites More sharing options...
mark2 Posted March 21, 2003 Report Share Posted March 21, 2003 Dan if you got to Startup list download , run it, copy and paste the log, this will tell us what is starting with windows, :ph34r: we can then narrow it down and hopefully stop it <_> Quote Link to comment Share on other sites More sharing options...
Guest Nellie2 Posted March 21, 2003 Report Share Posted March 21, 2003 Well I found this. http://www.secure-tech.net/ it is a web host but there was no web page for the phoenix bit of the address!!!! Quote Link to comment Share on other sites More sharing options...
Guest Dan Posted March 21, 2003 Report Share Posted March 21, 2003 Thanks for the responses folks.I've grabbed the file mark2 suggested and will run it shortly.I had a look at the site that Nellie2 found (I'd looked for the whole expression on the web but hadn't thought to shave anything off in a search - doh!).I tried the knowledgebase on the site but got bounced to a dead page.It's just weird that I can't find a cookie and that all the security stuff can't spot anything. I mean it may even be a perfectly legitamate site for a program I'm running that I just can't remember. But it's still weird.Will run the program and come back.Cheers again. Quote Link to comment Share on other sites More sharing options...
Guest Dan Posted March 21, 2003 Report Share Posted March 21, 2003 Not convinced this is going to help. I can't see anything out of place.StartupList report, 21/03/2003, 23:08:12StartupList version: 1.52Started from : C:\MyOwnTemps\Utilities\startuplist\startuplist152\StartupList.EXEDetected: Windows XP (WinNT 5.01.2600)Detected: Internet Explorer v6.00 (6.00.2600.0000)* Using default options==================================================Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVG6\avgserv.exeC:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeC:\PROGRA~1\Iomega\System32\ActivityDisk.exeC:\WINDOWS\System32\nvsvc32.exeC:\Program Files\Sygate\SPF\Smc.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\Tablet.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\CTHELPER.EXEC:\Program Files\Iomega\DriveIcons\ImgIcon.exeC:\PROGRA~1\Grisoft\AVG6\avgcc32.exeC:\Program Files\Microsoft Hardware\Mouse\point32.exeC:\PROGRA~1\MICROS~2\GAMECO~1\Common\SWTrayV4.exeC:\Program Files\QuickTime\qttask.exeC:\WINDOWS\explorer.exe C:\WINDOWS\System32\ctfmon.exeC:\Program Files\Iomega\AutoDisk\AD2KClient.exeC:\PROGRA~1\CACHEMAN\Cacheman.exeC:\Art&Words\MyPrograms\WordPerfect\Register\Remind32.exeC:\MyOwnTemps\Utilities\startuplist\startuplist152\StartupList.exe--------------------------------------------------Listing of startup folders:Shell folders Common Startup:[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeCorel Registration.lnk = C:\Art&Words\MyPrograms\WordPerfect\Register\Remind32.exeEPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\E_SRCV02.EXE--------------------------------------------------Checking Windows NT UserInit:[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]UserInit = C:\WINDOWS\system32\userinit.exe,--------------------------------------------------Autorun entries from Registry:HKLM\Software\Microsoft\Windows\CurrentVersion\RunNvCplDaemon = RUNDLL32.EXE NvQTwk,NvCplDaemon initializenwiz = nwiz.exe /installWINDVDPatch = CTHELPER.EXEUpdReg = C:\WINDOWS\UpdReg.EXEJet Detection = C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exeIomega Startup Options = C:\Program Files\Iomega\Common\ImgStart.exeIomega Drive Icons = C:\Program Files\Iomega\DriveIcons\ImgIcon.exeAVG_CC = C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUPPOINTER = point32.exeSmcService = C:\PROGRA~1\Sygate\SPF\Smc.exe -startguiSideWinderTrayV4 = C:\PROGRA~1\MICROS~2\GAMECO~1\Common\SWTrayV4.exeQuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottimeWindows = C:\WINDOWS\explorer.exe --------------------------------------------------Autorun entries from Registry:HKCU\Software\Microsoft\Windows\CurrentVersion\RunCTFMON.EXE = C:\WINDOWS\System32\ctfmon.exeMSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /backgroundIomega Active Disk = C:\Program Files\Iomega\AutoDisk\AD2KClient.exeCacheman = C:\PROGRA~1\CACHEMAN\Cacheman.exe--------------------------------------------------Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:Shell=*INI section not found*SCRNSAVE.EXE=*INI section not found*drivers=*INI section not found*Shell & screensaver key from Registry:Shell=Explorer.exeSCRNSAVE.EXE=*Registry value not found*drivers=*Registry value not found*Policies Shell key:HKCU\..\Policies: Shell=*Registry key not found*HKLM\..\Policies: Shell=*Registry value not found*--------------------------------------------------Enumerating Browser Helper Objects:(no name) - C:\Program Files\DAP\DAPBHO.dll - {0000CC75-ACF3-4cac-A0A9-DD3868E06852}--------------------------------------------------Enumerating Download Program Files:[{41F17733-B041-4099-A042-B518BB6A408C}]CODEBASE = http://a1540.g.akamai.net/7/1540/52/200212...meInstaller.exe[intraLaunch.MainControl]InProcServer32 = C:\WINDOWS\Downloaded Program Files\INTRALAUNCH.OCXCODEBASE = file://E:\system\IntraLaunch.CAB[shockwave Flash Object]InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocxCODEBASE = http://download.macromedia.com/pub/shockwa...ash/swflash.cab--------------------------------------------------Enumerating ShellServiceObjectDelayLoad items:PostBootReminder: C:\WINDOWS\system32\SHELL32.dllCDBurn: C:\WINDOWS\system32\SHELL32.dllWebCheck: C:\WINDOWS\System32\webcheck.dllSysTray: C:\WINDOWS\System32\stobject.dll--------------------------------------------------End of report, 5,488 bytesReport generated in 0.110 secondsCommand line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history onlyAny ideas folks? Quote Link to comment Share on other sites More sharing options...
Guest ellas Posted March 21, 2003 Report Share Posted March 21, 2003 well it looks ok to me but maybe mark2 willl see something,you could disable some of the startup programs like sidewinder tray icon and epson status monitor. Quote Link to comment Share on other sites More sharing options...
Guest Dan Posted March 21, 2003 Report Share Posted March 21, 2003 that's true, but I don't think they're the problem. after all both have been there a looong time and this is a new problem. Quote Link to comment Share on other sites More sharing options...
madboy33 Posted March 21, 2003 Report Share Posted March 21, 2003 Hi Dan1 Use adaware to see if there is any spyware, if there isnt go to number 22 Get rid of all of them in start upNow load them one by one and see which one is the offending onemadboy33 Quote Link to comment Share on other sites More sharing options...
Boris Posted March 22, 2003 Report Share Posted March 22, 2003 I'm not sure about this one ? - in :-Enumerating Download Program Files:[{41F17733-B041-4099-A042-B518BB6A408C}]CODEBASE = http://a1540.g.akamai.net/7/1540/52/200212...meInstaller.exe Quote Link to comment Share on other sites More sharing options...
Boris Posted March 22, 2003 Report Share Posted March 22, 2003 I don't think you need it ?In Nellie2's thread "Strange goings on" Mark2 advised this :-You should then go to C:\windows\downloaded program files and remove the following Active X Control: IntraLaunch.MainControl]InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\INTRALAUNCH.OCXCODEBASE = file://L:\supercd\IntraLaunch.CAB[{41F17733-B041-4099-A042-B518BB6A408C}]CODEBASE = http://a1540.g.akamai.net/7/1540/52/200112...meInstaller.exe Quote Link to comment Share on other sites More sharing options...
mark2 Posted March 22, 2003 Report Share Posted March 22, 2003 A look at This thread suggests thatUpdReg = C:\WINDOWS\UpdReg.EXE can be responsible for some odd connections.Block C:\WINDOWS\system32\lsass.exe using Sygate if not already blocked As Boris says the 2 Active X files you can dispense with, CODEBASE = http://a1540.g.akamai.net/7/1540/52/200112...meInstaller.exe may be to do with Trend Housecall online A/V check, if so it will reinstall next time you use trend housecall.and Intralaunch is a spyware component.Does sygate list an Ip address for the offenders destination? Does it only try once? Does it show up in processes as using cpu/memory at the same time it is trying to conect ?Other than that it is going to be a case of following Madboys suggestion in Msconfig start up until we get a hit.But no immediate nasties spring into view. Quote Link to comment Share on other sites More sharing options...
Guest Dan Posted March 22, 2003 Report Share Posted March 22, 2003 Ok, thanks for all the responses.I shall work through them and see what solutions and / or developments come to light. Quote Link to comment Share on other sites More sharing options...
mark2 Posted March 22, 2003 Report Share Posted March 22, 2003 Let is know if/when anything turns up or it sorts itself out :blink: Quote Link to comment Share on other sites More sharing options...
Guest Dan Posted March 23, 2003 Report Share Posted March 23, 2003 Haven't had much time to work on this but I had already got the Block C:\WINDOWS\system32\lsass.exe using Sygate suggestion done anyway.As a curiosity and to try and trace what program was launching the dial up I let it dial part way and then had Sygate refuse it's link.This showed the program in question to be c:\Windows\explorer.exeNow why on earth would a part of windows be trying to dial this site?If I block this off am I going to be shooting myself in the foot as far as internet connection goes?(I know i know, suck it and see.)Will try it in a few days time as shifts allow <_< Quote Link to comment Share on other sites More sharing options...
mark2 Posted March 23, 2003 Report Share Posted March 23, 2003 I too have w/explorer trying to connect and have always had it blocked with no problems, seems that XP tries to connect with the net, may be part of the 'search' function with XP Quote Link to comment Share on other sites More sharing options...
Guest Dan Posted March 24, 2003 Report Share Posted March 24, 2003 But Why this site? If it were an MS link I could understand it, but this third party link. It seems really weird. Quote Link to comment Share on other sites More sharing options...
mark2 Posted March 24, 2003 Report Share Posted March 24, 2003 Do you have anything such as Bigfix on your comp or some other update monitoring program. Quote Link to comment Share on other sites More sharing options...
mark2 Posted March 24, 2003 Report Share Posted March 24, 2003 Do you have a Phoenix mobo ?Got this reply elsewhere.I assume this is one of the new Phoenix Motherboard which have this integrated in the BIOS! Aaaaaaaaaaaagh!! Not good I know You need to disable PhoenixNet in the BIOS to stop it happening I'm afraid. Quote Link to comment Share on other sites More sharing options...
Guest Dan Posted March 24, 2003 Report Share Posted March 24, 2003 The motherboard is an MSI (K2 ultra I think) not a Phoenix.Re the Bigfix query have to say I don't know what it is though I assume it's some kind of pc health check utility. The only pc health things on my machine (to my knowledge) are GAV and AVG virus killers, Adaware 6 and Spybot Search and destroy.As it's now weekdays I may go to the site and see if I can query them as to why an unknown item on my pc is trying to contact their site. Quote Link to comment Share on other sites More sharing options...
mark2 Posted March 24, 2003 Report Share Posted March 24, 2003 Have you tried a look in the bios see if there is something like it ? Quote Link to comment Share on other sites More sharing options...
Guest Dan Posted March 24, 2003 Report Share Posted March 24, 2003 Cheers for all your help on this mark2, will have a look at the bios tomorrow am. Bed beckons now. Quote Link to comment Share on other sites More sharing options...
mark2 Posted March 25, 2003 Report Share Posted March 25, 2003 One other thing, a check in the registry for a reference to the site may yield a result too ? Quote Link to comment Share on other sites More sharing options...
Guest Dan Posted March 26, 2003 Report Share Posted March 26, 2003 Tried replying to this yesterday but the site was sticky.My bios are American megatrends not phoenix.I contacted the secure-tech.net part of the link and they said that the phoenix part was a customer of theirs and they'd pass the query on. This was fine though a minor bit of paranoia made me check the details on the mail sent to me from secure-tech.net and the responder's mail is @us.army.mil which pardon my paranoia is a little worrying. What the hell have I tapped into and who's gonna off me?!! :ph34r: Regaining my sanity a little and with regard to your Registry suggestion, is there a really safe way to take a peek? It's something I've always avoided - I'm kind of club handed and as likely to do damage just stepping in and out.CheersDan Quote Link to comment Share on other sites More sharing options...
mark2 Posted March 26, 2003 Report Share Posted March 26, 2003 It is safe if you want to take a peek in the registry, run regedit, then file>export, export to the desktop is simplest. Then should any thing go wrong you can just d/click and merge it back in.Also set a restore point beforehand, belt and braces :D to find the references to phoenixsecuretech. run regedit then F3 key brings up the find function enter the name of the offender and click on find and away you go. If you post where all the references are found I can have a quick look 1st if you like. ;) BTW I thought pressganging went out in the last century :D Quote Link to comment Share on other sites More sharing options...
Guest Dan Posted March 26, 2003 Report Share Posted March 26, 2003 Mark2 - you're so right and I'm real sorry to be such a pain. You're too helpful. Will go away and try some self help for a while and then come back if I'm still stumped.Many thanks for all your input.Dan Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.