PDA

View Full Version : What is trying to connect ?


Yinda
November 30th, 2002, 08:39 AM
Hi,

I am using W98. During normal startup, ZoneAlarm is the last application to be launched. Then I manually connect to Internet.

From time to time, however, the connection screen appears just before ZA is started, asking 3 or 4 times (because I answer no) whether I want to connect to Internet.

Is it possible to know what is trying to connect? According to msconfig, there is apparently no update program. Could it be ZA itself ?

Thanks,

Yinda

Pieter_Arntz
November 30th, 2002, 08:47 AM
Hi Yinda,

Not everything that starts up automatically is shown in msconfig. Please grab a copy of Startuplist from our download section (http://www.wilders.org/free_tools.htm) (under monitoring) Unzip and run the program and copy and paste the results in your next post. If there is anything in there you don´t want the world to know about, you´re welcome to mail or IM it to me.

Regards,

Pieter

Scotcov
November 30th, 2002, 08:54 AM
Yinda, check out this thread:
http://www.wilderssecurity.com/showthread.php?t=3864
after doing what Pieter suggested.
ZA v.3.1.395 evidently does try to dial home on boot.
Scotcov

Yinda
November 30th, 2002, 10:31 AM
Hi,

I have just sent my startuplist to Pieter. As for ZA, I am still using 3.0 but maybe the issue was there too?

Thanks a lot.

Yinda

Pieter_Arntz
November 30th, 2002, 10:56 AM
Hi Yinda,

I think I found it.
Take a look here (http://www.pacs-portal.co.uk/startup_pages/startup_full.htm#M) and scroll down to MSDTC and read the description in the last column. Unfortunately the link given there is no longer valid. This starts up from HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Other programs that might want to access the internet: Messenger, Reminder.lnk = C:\Utils\Reminder\Reminder.exe or WOOWATCH = C:\PROGRA~1\WANADOO\watch.exe
Other then that you might want to get hijackthis (http://www.geocities.com/merijn_bellekom/new/files.html) and remove the DAP remnants from your browser.

Hope this helps,

Pieter

Yinda
November 30th, 2002, 11:48 AM
Hi Pieter,

I have read the description of MSDTC (auto dials on startup). So it may be the responsible.

Reminder is a small program which just displays a todo list. Wanadoo is my Internet provider ???

Thanks very much Pieter and to all of you. I always learn a lot on this forum.

Yinda

Pieter_Arntz
November 30th, 2002, 12:16 PM
{QUOTE-> quoting: Yinda link=board=23;threadid=5205;start=0#33912 date=1038674898]
I have read the description of MSDTC (auto dials on startup). So it may be the responsible. <-QUOTE}
I think so. I guess there´s only one way to make sure.

{QUOTE->
Reminder is a small program which just displays a todo list. <-QUOTE}
Then it´s probably not the one. I was thinking along the lines of little apps that remind you to register certain software.

{QUOTE->
Wanadoo is my Internet provider ??? <-QUOTE}
I have a thing against software provided by ISP´s. Call it bad experience ;)

{QUOTE->
Thanks very much Pieter and to all of you. I always learn a lot on this forum. <-QUOTE}
You´re very welcome and don´t we all.

Regards,

Pieter

Yinda
November 30th, 2002, 01:56 PM
According to
http://www.answersthatwork.com/Tasklist_pages/tasklist_m.htm :

{QUOTE-> Microsoft Distributed Transaction Coordinator. The Microsoft Distributed Transaction Coordinator is a transaction manager which permits client applications to include several different sources of data in one transaction and which then coordinates committing the distributed transaction across all the servers that are enlisted in the transaction. MSDTC runs on all Windows platforms and is installed by applications which need to use it, such as the Microsoft’s Personal Web Server, or Microsoft SQL Server.

Recommendation :
If you have it running, it is most probably needed by a Microsoft Application, so leave it untouched unless it is definitely causing you problems. <-QUOTE}

2 or 3 years ago, I tried without success to install Microsoft's PWS. The line MSDTC was probably inserted at that moment.

I'll uncheck it and see whether something will go wrong.

Regards,

Yinda

Yinda
December 9th, 2002, 05:13 AM
Hi,

Just FYI.

The connection attempts are due to ZAP 3.0 itself. I have read the DNS lookup explanation. But there is normally no upgrade request. The check ZA upgrade itself is manual.

Allow the connection may not be the solution, because the ZA icon is not yet there, so maybe the firewall is not yet effective. If I block the connection, then there will be 10 or 11 attempts. The problem is relatively recent, but I don't know what has been changed.

On the other hand, ZAP takes more than one minute to appear. So, yesterday, I decided to use Kerio. According to your firewall download page, it should not be too bad.

BTW, there has no problem removing the MSDTC line in the startup.

Regards,

Yinda

Pieter_Arntz
December 9th, 2002, 05:18 AM
So scotcov was right :)
He'll be pleased.
So am I by the way, to see that you resolved it.

Best regards,

Pieter