Question

System reboot every few hours. Probably malware but nothing found.

Asked by: PaulCaswell

Hi All,

I have a problem with my Laptop where it reboots every few hours with the message that the system is rebooting because the RPC service has stopped.

Please read the thread where I originally asked for expert help:

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Windows/Q_23767371.html#a22627180

As you can see I have collected a FileMon of the activity around the time it happened and it looks malicious to me. It is creating a program called dts12.exe which seems to collect some information, create a dll called mspush.dll and call it.

It does all this under the watchfull eye of MacAfee (Corporate).

I have scanned my laptop with SuperAntiSpyware, MalwareBytes, Spyware S&D and I am now trying an online scan with Kaspersky. None of them have found anything malicious.

Someone else seems to have the same problem:

http://www.bwhacks.com/forums/hardware-software/35630-computer-forces-restard-every-hour.html

Please only focus on the 'System Shutdown' dialog in the screenshot and the narrative below. Refrain, for your own sanity, from studying the rest of the screenshot and from following the discussion.

I've attached the FileMon log as an xls. I believe you can see signs of Winlogon recognising that the RPC has stopped in record 5245 just after what looks like an invocation of mspush.dll by dts12.exe.

Notice that dts12.exe is created on the fly by a svchost.exe a little further up the log and dts12 creates mspush.dll on the fly too. This looks distinctly fishy to me.

Has anyone got any ideas what this is and how I can get rid of it?

Paul

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2008-10-02 at 13:35:58ID23783156
Topics

Anti-Spyware

,

McAfee Anti-Virus Software

,

Anti-Virus Applications

Participating Experts
5
Points
500
Comments
16

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Malware?  Spyware?  Help!!
    System: Windows XP Pro Office XP Pro Help! I believe this is malware, but I can't seem to get rid of it. It mysteriously re-appears on every boot. Wma eggs.exe found in a file named license else poke. It shows up on hijack this list and startup menu. I have gone to the r...
  2. Spyware?
    My computer has several pieces of spyware, including but not limited to "Aurora - part of the ABI Network" I tried to remove Aurora by booting into savemode runing nailfix.exe and scanning with ewido but it still came back. here are the results from my HiJackThis Lo...
  3. Spyware/Malware C:\secure32.html
    Hi Guys, We've a laptop which believed to be infected by spyware/malware. Everytime launching the IE 6, it opens up a web page with addres c:\secure32.html. Realising that, the user did performed virus/spyware scan using McAfee and deleted off the virus detected (including s...
  4. Winlogon trying to access Internet
    I have a problem with Winlogon trying to access the Internet - my firewall stops it but how do I remove the problem? Thanks Colin Northway
  5. PC infected with  spyware / malware
    Hi Experts! My computer is again infected with spyware. I use Win XP Pro SP2. A month ago, I reformatted the HDD because I was not able to remove all of these spyware. Now they are back and I don't want to reformat the HDD again. My anti-virus software is Panda and it stopp...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: nlcafePosted on 2008-10-02 at 14:26:05ID: 22628857

 

by: PaulCaswellPosted on 2008-10-02 at 15:19:59ID: 22629315

Hi nlcafe,

I am pretty confident this is not msblast. I have run the small scan script and the McAfee full scan. No sign. I am running XP fully patched and updated with corporate MacAfee ant-virus and regular (weekly) spyware scans.

Paul

 

by: orangutangPosted on 2008-10-02 at 18:30:58ID: 22630327

Well, I know rpggamergirl and IndiGenus are very good at this stuff. Maybe they'll get here soon and recommend ComboFix or SDFix. Also, check:
http://www.computerhope.com/forum/index.php?topic=67362.0;all

 

by: IndiGenusPosted on 2008-10-02 at 18:50:56ID: 22630411

Hi,

Both the dts12.exe and mspush.dll files are pretty much surely malware.

I think it would be a good idea to run combofix at this.

Please download ComboFix from either of these links to your Desktop.
http://subs.geekstogo.com/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

1. Please, never rename Combofix unless instructed.
2. Close any open browsers.
3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

* Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. *
They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".

* The link below is a list of programs that should be disabled. If yours is not listed and you don't know how to disable it, please ask.
http://www.bleepingcomputer.com/forums/topic114351.html

* Close any open browsers.
* WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
* Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
* If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

4. Double click on combofix.exe & follow the prompts.
5. When finished, it will produce a report for you.
6. Please attach the "C:\ComboFix.txt" along with a new HijackThis log for further review.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

PLEASE ALSO NOTE: Combofix will typically fix most and sometimes all Malware entries but many times a script is also needed to finish cleaning up. So please keep CF until advised whether you need the script or not.


 

by: yhalaiPosted on 2008-10-03 at 03:32:07ID: 22632500

Hi Paul,
McAfee Anitvirus alone does not defend spaywares! you will need  Mcafee Antispyware addon.
Keep that in mind for future.


Have you tried running Windows Malicious Software Removal Tool (KB890830)?

 

by: nlcafePosted on 2008-10-03 at 06:03:24ID: 22633389

Run hijack this- Post log

Turn off system restore.

Delete the bad entries.

Turn back on system restore.  You will be done.  Dont make this harder than it is.  If you wanted help listen to these guys.

 

by: PaulCaswellPosted on 2008-10-03 at 10:58:40ID: 22636342

Thanks for the suggestions people.

I'll be running Combofix as per your instructions.

I think I've either removed it or disabled it because it hasn't happened today. I expect ComboFix will tell me.

Last night I did a clean boot and went straight in with Process Explorer and terminated any services and background apps I knew weren't necessary. Essentially leaving me with just Microsoft and McAfee services.

I then watched for a while to see if any services started themselves up again. The most persistent were from 'Nokia PC' so I uninstalled that and started again.

I noticed that spoolsv also had a svchost child process. Is this normal?

I then created a folder called DTS12.exe in my System32 folder to stop the creation of DTS12.exe that I noticed in the FileMon log.

So, the combination of the removal of Nokia PC and the creation of the folder has stopped the crashes.

Last night there was definitely a copy of mspush.dll in my System32 folder but there wasnt today which points at Nokia but I have had it installed for over a year and had no troubles with it.

I'll let you know what ComboFix finds.

I posted a HijackThis log on the other thread. Are you asking for a new one?

Paul

 

by: IndiGenusPosted on 2008-10-03 at 11:17:21ID: 22636504

Yes, post a new HJT log after running combofix.

 

by: PaulCaswellPosted on 2008-10-03 at 11:55:48ID: 22636892

Hi people. ComboFix finished, log attached.

HJT on it way.

Paul

 

by: PaulCaswellPosted on 2008-10-03 at 12:03:09ID: 22636952

HJT log enclosed.

Nothing amiss in there that I can see.

Paul

 

by: PaulCaswellPosted on 2008-10-03 at 12:24:31ID: 22637155

I've also added an entry in my McAfee onAccess rules to alert me and block creation of System32\dts21.exe. Hopefully that will disable it even if it is still there.

I notice some md5s of spoolsvc in the ComboFix log. Am I right in guessing that something may be lurking there?

Paul

 

by: orangutangPosted on 2008-10-03 at 12:30:20ID: 22637220

Hmm, maybe if it ever appears again, you can submit the file to Malwarebytes or SUPERAntiSpyware or whoever. Anyway, your logs look clean to me. Wait for rpggamergirl or IndiGenus to check.

 

by: PaulCaswellPosted on 2008-10-03 at 12:38:57ID: 22637294

I've removed the dt12.exe folder and I'm now going to leave it to McAfee to catch it if it's still there.

I'll leave this question open for a few days in case it comes back like last time.

Thanks again all for your help.

Paul

 

by: surgexxPosted on 2008-10-06 at 10:35:07ID: 22652393

Thanks, I ran combofix and also deleted the original dts12.exe, and created a folder called DTS12.exe in system32.  Now I just have to do this on EVERY computer at my work, and at home...sigh!  Upon further inspection, it seems that every box @ work has InClick.txt in C:\...the strange thing is, only a handful of them have the RPC restarting thing.

 

by: PaulCaswellPosted on 2008-10-06 at 11:37:38ID: 22652996

Hi surgexx,

I had the same feeling you had about the Blaster derivative.

The odd thing I noticed in the FileMon log was the creation of DTS12.exe by a service called svchost, which seems unlikely doesn't it? Combine that with the fact that I also noticed a svchost child process of spoolsv and it may be in a printer driver or spooler somewhere.

It seems to have got/gone away or is hiding on my setup. Perhaps these guys will catch it on yours.

I think it is collecting information and posting somewhere through the web.

I got quite a lot out of the FileMon log. You might like to install the new Sysinternals ProcessMonitor if you havent yet. You could then have a trace of everything it does. Just leave it running and logging until the RPC restart kicks in.

I hope someone comes in to look. You may get more help if you post your own question and include a link to this one.

Paul

 

by: PaulCaswellPosted on 2008-10-06 at 11:40:48ID: 22653015

P.S. I have no proof that the creation of a folder called DTS32.exe made any difference. I never saw the effect after that but that was the last in a long line of scans from many different spyware removal tools and the complete deinstallation of a quite complex package.

Paul

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...