Pop-ups and random links in text with Internet Explorer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Boardboy, Feb 10, 2005.

  1. Boardboy

    Boardboy Private E-2

    I have a dell Inspiron 5150 laptop. It has WinXP Pro with SP2. Mobile Intel Pentium 4, 3.06GHz, 512MB of RAM.

    Here is the issue:
    I am getting periodic pop-ups when I have Internet Explorer open. Also, in IE, within the text there are links. The links have specified words (i.e. "computer" "single" "call" "help" software" "phone" "emergency"). When I scroll over the link (not clicking on them) there is not website that shows in the bottom left side of the window. It just shows the same word as the "link" in the text. Some "link" show the web site www<dot>103092804<dot>com. I don't know what is going on.

    I have gone through the steps of the Basic Spyware, Trojan And Virus Removal page and downloaded all appropriate programs and applications from that page. The first time through the steps, I was not able to run Spybot in Safe Mode. The second attempt at trying to go through the steps, McAfee AVERT Stinger doesn't run completely through. In both cases with Spybot in Safe Mode and recently with Stinger, as the programs were scanning the computer shut off. I had to re-start my laptop.

    Again, I don't know what is going on and any help would be greatly appreciated. Let me know if you need any more information from me.

    Thanks.
    Boardboy
     
    Last edited: Feb 10, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. Boardboy

    Boardboy Private E-2

    Attached is the requested log file (saved as a .txt file). Thanks for you help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to pick which Antivirus application you want to have and uninstall the other. You have both Symantec and Trend Micro installed. Only one antivirus application should be used.

    You must remember to exit browsers before using HijackThis. IE was running: C:\Program Files\Internet Explorer\iexplore.exe


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\atmlib48.exe
    C:\WINDOWS\system32\alrsvc33.exe
    After killing all the above processes, click "Back". Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [3Tu2L] C:\documents and settings\tmoyer\local settings\temp\3Tu2L.exe
    O4 - HKLM\..\Run: [6zc9qJr75] C:\documents and settings\tmoyer\local settings\temp\6zc9qJr75.exe
    O4 - HKLM\..\Run: [278T34U] dgn10.exe
    O4 - HKLM\..\Run: [2ff62f08a6bd] C:\WINDOWS\system32\atmlib48.exe
    O4 - HKLM\..\Run: [7cbdf500d894] C:\WINDOWS\system32\alrsvc33.exe
    O16 - DPF: {332bd5a0-8000-11d7-b657-00c04faedb18} -

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\atmlib48.exe
    C:\WINDOWS\system32\alrsvc33.exe
    C:\WINDOWS\system32\dgn10.exe
    C:\documents and settings\tmoyer\local settings\temp\3Tu2L.exe
    C:\documents and settings\tmoyer\local settings\temp\6zc9qJr75.exe

    Actually it would be best to delete all files you can in C:\documents and settings\tmoyer\local settings\temp

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Do you have any idea what this Rpcnet.exe program is related to? Is is it something for your Cisco Rehat stuff?
    O23 - Service: Remote Procedure Call (RPC) Net - Unknown - C:\WINDOWS\SYSTEM32\Rpcnet.exe
     
  5. Boardboy

    Boardboy Private E-2

    RANDOM LINKS ARE GONE!!!!! Thank you so much!!!

    I imagine the pop-ups will be gone as well. But, if a pop-up occurs, is there something that I should be looking for? or is there something I can do?

    Question about the anti-virus, if you don't mind me asking. I had the two anti-virus softwares (Trend Micro and Symantec), Trend Micro was recognized by WinXP Security Center as an anti-virus software whereas Symantec was not recognized. I tried both with realtime scans and it seemed that Trend Micro picked up what Symantec did not. I noticed that Windows recommends Trend Micro but is one better than the other?

    Could you tell me where a good place would be to look to find out the best ways to protect against future issues?

    Thank you again. I really appreciate your help. Boardboy.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Symantec and keep TrendMicro.

    You never complete my instructions. You really should post the follow up HJT log to be sure everything is gone and nothing new popped up.

    You should follow the steps in the below link to help avoid future problems:
    How to Protect yourself from malware!
     
  7. Boardboy

    Boardboy Private E-2

    Sorry about not posting another HJT log. However, I just created an HJT log (without any browsers open and no other "visual" programs running) and the latest log file is attached. The log seems to be clear of the items that you requested me to delete/remove.

    I went through the steps early this morning and since that time I have not seen a pop-up or a link on IE. I haven't seen any other issues come up since that time.

    Thanks for the link to prevent malware. I'll definitely read through that and apply necessary apps/programs. Thanks again.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes your log is clean now. However you never answer my previous question about this:

    O23 - Service: Remote Procedure Call (RPC) Net - Unknown - C:\WINDOWS\SYSTEM32\Rpcnet.exe

    Do you know who uses it? Who installed it?
     
  9. Boardboy

    Boardboy Private E-2

    I'm not sure where this rpcnet.exe process is from. I have been trying to get as much free information from the internet as possible.

    As far as free information goes, people are making guesses as to what it is and what it does. Most of the guesses have something to do with RPCs (remote procedure calls) but nothing definite.

    There is one website that claims to know what it is but it costs at least $10 to find out. If it is possible, I'd like to find that info out for free.

    I have gone into C:\Windows\system32 and renamed the executable. I'm hoping that if there is a valid program that uses it, the program will generate a prompt that will give some kind of information. What do think?

    I did another HijackThis log after I renamed the rpcnet.exe and the rpcnet.exe is still showing in the list of processes but at the end of that line shows "(file missing)", which makes sense. But would the process show up in the list if it was not running?

    Interesting thing happened. I did an advanced search with Windows Explorer and my search criteria was:

    All or part of the file name:
    *.*

    A word or phrase in the file:
    rpcnet.exe

    Look in:
    C:\

    The search ran for about an hour and then out of nowhere my computer shut off. It did not shut down. It just turned off. It was similar to how my laptop shut off when I was doing the initial antivirus scans with the "Basic Spyware, Trojan And Virus Removal". It's really odd that my laptop would shut off with a basic search. Any ideas?

    Thanks.
    Boardboy

    (Obviously I tried some things here and I'm not sure if they're going to make any difference. I know that there's a process of how to do things so if I'm getting off-track with my attempts please let me know.)
     
  10. Boardboy

    Boardboy Private E-2

    The info on RPCnet.exe is useful, thanks.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well Star has answered your question about what that program is but I'm rather surprised that you would have something like that on your computer and not know about it. I doubt it is a very useful item anyway. It is probably fairly easy to defeat.

    I'm confused by your message. You now seem to be talking about a second computer. If you have the same problems on it you should be using the same procedures as we did on your laptop.

    Is you laptop running okay now? Your the one that should be able to tell if the things you have done have made a difference. But you had a bunch of problems and should already see a difference since executing my instructions.
     
    Last edited: Feb 13, 2005
  12. Boardboy

    Boardboy Private E-2

    The laptop is running smoothly now. No more pop-ups and the random links have gone away.

    The advanced search was done on the laptop. I haven't switched machines. The odd thing was that the laptop shut off during the search. Everything is running great but it was just that search that was odd. It's rare that I do searches like that so I don't know if it is a big issue or not.

    Currently the rpcnet.exe file is re-named and there are no issues with doing that. I do not have any pop-ups or random links, which is great, but if you think that there is more that I should do then please let me know. Otherwise, I happy with the way my laptop is running right now.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should follow all the steps in: How to Protect yourself from malware!

    I'm not sure why search causes a problem. Have you tried using seach in safe mode?
    Does it work in safe mode?

    When is the last time you did an error check on your disk and also a defrag?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds