PhoenixNet problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SpiderOne, Oct 21, 2004.

  1. SpiderOne

    SpiderOne Private E-2

    Ok well I had to format my computer recently... and then I started getting this. My mobo is a Soyo which apparently has PhoenixNet in it. (I only know this because in the top right of my startup sequence it says "this computer is PhoenixNet enabled"). I never had this problem before and I really don't know what to do. I tried the way another website said to remove it but it didn't work.
    My Norton Antivirus detects a Malicious Script at startup so nothing major has come of it yet but it is a rather big annoyance.
    If anyone can help me I would greatly appreciate it.


    Logfile of HijackThis v1.98.2
    Scan saved at 12:54:06 PM, on 10/21/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


    Edit by chaslang: HJT log deleted
     
    Last edited by a moderator: Oct 21, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis is the last step and we have rules about how and when to post a log.

    Begin by using Add/Remove programs to uninstall Messenger Plus! 3. It comes with a bunch of spyware programs and LOP too.

    Also, see: http://cexx.org/phoenix.htm

    Then please follow all the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    NOTE: You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser (i.e, Mozilla, IE, Netscape) , e-mail. Close before running Hijack This!


    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of \Documents and Settings, or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT
     
  3. SpiderOne

    SpiderOne Private E-2

    Sorry for not following your guidlines the first time.

    I have run Ad-Aware and Spybot S&D. They are updated but since it's in my bios they didn't help at all.
    I have had no problems with MSN Plus 3 but uninstalled it as you requested anyways.

    My problem is that after formatting my C:\ and returning it to a backed up state there was a new icon on the desktop. While it was finishing starting up my Norton Anti-Virus detected a Malicious Script.

    The icon is called "PhoenixNet" and is directed to "http://www.seqdl.com/servlets/Redir?BID=65457&CID=9875"

    After looking things up myself I found that it is a discontinued BIOS program from Phoenix Technologies.
    It's not very serious because it doesn't actually install cause Norton detects and stops it before anything can happen, but it is very annoying to have to deal with it every time I start-up or restart my computer.

    The page on Counter Exploitation that you sent me to only confirms what I found out.

    I didn't have this problem once one previous backups or complete formats so a setting in my BIOS must have triggered it. I did recently get a new hard drive and I think that it might have something to do with it, since I had to change some BIOS settings (IDE Auto Detection and what not) so that the new drive worked.

    If you need any other info please let me know so that I can post it as soon as possible.

    Thanks.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think I saw a line in you HJT log the referred to PhoenixNet. Take a look at a fresh log. Perhaps removing that line will help.
     
  5. SpiderOne

    SpiderOne Private E-2

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. SpiderOne

    SpiderOne Private E-2

    Correct. It did not work.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you tried searching your registry for PhoenixNet ?
     
  9. SpiderOne

    SpiderOne Private E-2

    Not yet. But I will start right now.
     
  10. SpiderOne

    SpiderOne Private E-2

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. SpiderOne

    SpiderOne Private E-2

    Yeah I figured it out before I read that message though. But thank you for the help you did provide.

    For future reference to people trying to fix this problem.

    You have to delete the files and registry entries associated with it.

    HijackThis does a good job since it can recognise the registry entry faster than the search option in regedit. Although if you choose to use 'regedit' to do it just search "PhoenixNet" and delete the whole folder.

    After the registry stuff delete any associated favourites and desktop icons.

    Then restart and during the restart change your BIOS settings so that your pre-OS virus scan (which does nothing most of the time anyways) is off then in the same option screen there should be something that says PhoenixNet. Make sure it says "No" or "Disabled" in the field. You have to disable the Pre-OS virus scan or else it may not work. (That's what happened in my situation anyways.

    So again.

    1. Remove all associated files and reg entries.
    2. Restart and adjust BIOS settings (no pre-os virus scan, and no "phoenixnet".

    Worst product idea for phoenix tech. EVER.
     
    Last edited: Oct 24, 2004
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Happy to see you got it worked out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds