Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #51  
Old October 16th, 2006, 12:36 AM
tobacco's Avatar
tobacco tobacco is offline
Frequent Poster
 
Join Date: Nov 2005
Location: British Columbia
Posts: 1,075
Default Re: NSIS Media Popups

Thanks to everyone especially 'Pieter' for contributing to a solution in removing this nasty. Question if i may.

Pieter

Is there anything else that needs to be done- i.e.- Deletion of files, folders, etc. before or after running your script.

Thanks.
__________________
Your Antivirus Wears Army Boots
  #52  
Old October 16th, 2006, 02:45 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,399
Default Re: NSIS Media Popups

Hi tobacco,

Hard to tell untill we have tried it on a live infection.
I do not know in which processes the dll gets injected.
If it is only explorer and iexplore then the script should work without any special preparations.
(Ofcourse it's always advisable to close as many programs as possible)

Regards,

Pieter
__________________
Regards,

Pieter
It´s nice to be important, but it´s more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
  #53  
Old October 16th, 2006, 11:08 AM
LonnyRJones LonnyRJones is offline
Spyware Expert
 
Join Date: Apr 2003
Posts: 61
Default Re: NSIS Media Popups

It loads under explorer, and any exe it wants to.

We need samples and more info on what it is that installs this thing.
the programs mentioned here and eslwhere dont anymore or it could be it wont on virtual machines
  #54  
Old October 19th, 2006, 05:28 PM
LP-Listener LP-Listener is offline
Infrequent Poster
 
Join Date: Oct 2006
Location: Netherlands
Posts: 1
Default Re: NSIS Media Popups

This is my result:

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "{B9CE503D-03F8-4161-A8A6-C912ADFCF2D4}" 19-10-2006 21:52:56



[HKEY_USERS\S-1-5-21-1004336348-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached]
"{B9CE503D-03F8-4161-A8A6-C912ADFCF2D4} {000214E8-0000-0000-C000-000000000046} 0x401"=hex:01,\

jan
  #55  
Old October 19th, 2006, 11:19 PM
Irma Irma is offline
Infrequent Poster
 
Join Date: Oct 2006
Posts: 3
Default Re: NSIS Media Pop-ups

I finally found the apparent source of NSIS.
It comes from Nullsoft, in my case with the Winamp player. It is a plug-in of sorts. After I uninstalled Winamp, rebooted, all my scans and searches came out negative. It still did not come back.

If anyone is interested , here is the URL for the NSIS download and description of it;
http://nsis.sourceforge.net/EclipseN...in_for_Eclipse

http://nsis.sourceforge.net/Support

plus
http://nsis.sourceforge.net/Main_Page"
Spyware Terminator Homepage

Search

Search in our database
Search in the web

Homepage
Software Database
N
Nullsoft, Inc.
Nullsoft, Inc.
Software Developer Detail
Info: Nullsoft, Inc. develops one of the most popular media players - Winamp and plug-ins for it. Its other products include SHOUTcast - media streaming and directory system, NTV - global streaming television, NSIS - installer system for Windows, JNetLib - asynchronous C++ network abstraction library, NetMon - network latency monitor for Windows nad other open source software.
URL: http://www.nullsoft.com
Phone: 703-265-0094

Maybe this can shed some light on this.
  #56  
Old October 20th, 2006, 12:49 AM
LonnyRJones LonnyRJones is offline
Spyware Expert
 
Join Date: Apr 2003
Posts: 61
Default Re: NSIS Media Popups

Dont confuse Nullsoft Scriptable Install System
http://nsis.sourceforge.net/Support

With NSIS media Extension which couses adware popups
  #57  
Old October 21st, 2006, 04:19 PM
Irma Irma is offline
Infrequent Poster
 
Join Date: Oct 2006
Posts: 3
Default Re: NSIS Media Popups

Hi,
all I know is, that after uninstalling Winamp player, cleaning the registry of the left over keys, all my scans came out negative, no more traces and keys and files found, and most important of all, NO MORE POP UPS!

Since then, I restarted my pc at least 10 times, and just in case did the scans,and I am still negative, and my computer is running just fine.
  #58  
Old October 31st, 2006, 12:35 PM
pwp007 pwp007 is offline
Infrequent Poster
 
Join Date: Oct 2006
Location: BC, Canada eh?
Posts: 1
Default Re: NSIS Media Popups

For what it's worth - I tried something completely different to trick this one sinec no 2 people seem to be having the same luck in getting this thing.....

1. First I went to Program Files\Common Files\NSIS Media then I deleted the 2 files in the directory.

2. Then I went to START -> RUN -> Regedit <ENTER> then I searched for NSIS and deleted the registry key.

3. Then I went back to Program Files\Common Files, made the NSIS Media directory (now empty) Hidden and Read Only.

4. Then I went into the directory and creates a ns00.dll empty (0 kb) file and an unist.exe empty (0 kb) file.

5. Then I replicated the ns00.dll file 100 times and renamed them in sequence until I had ns00.dll through ns100.dll completed.

6. Then I made all files in the directory Hidden and Read Only.

7. Rebooted the computer and went back to check Regedit and the Program Files\Common Files directories to make sure nothing changed.

8. Thats it (took about 30 mins to complete since creating blank DLL and EXE files prooved tricky (Those not sure can create a blank text file by the correct name, go to Command Prompt mode (CMD), use CD PROGRA~1 then CD COMMON~1 then CD NSIS, then RENAME *.txt *.dll, then DIR to make sure they look right.

It seems to work for me anyhow....
  #59  
Old November 17th, 2006, 05:36 PM
Mcgruff Mcgruff is offline
Infrequent Poster
 
Join Date: Nov 2006
Posts: 1
Default Re: NSIS Media Popups

Quote:
Originally Posted by Sam-the-Sly
Ok, so here's how it is:

My problem: getting pop-ups in IE labelled Advertisement- NSIS Media Extensions (or something like that )

The cause:
They appeared after installing Foxie Security Suite

Files Presumably Responsible:
C:\Program Files\Common Files\NSIS\ns**.dll
C:\Program Files\Common Files\NSIS\uninst.exe

What happens:
When the user clicks on uninst.exe, the program removes all of it, but then when the user clicks on the prompt to restart, it sets for those deleted files to be restored on shutdown (or startup in some varieties).

My solution:
I found that if I crashed my computer (e.g pulling out the power cable crash lol) at the restart prompt when uninstalling it, when I boot up, it's gone. I then did a search (start\search) for any file on my computer containing "nsis". I deleted any found. I then did a registry search (start\run\"regedit"\ then click on edit, find) for the same, and cleared anything found.

(it helped me)


This worked for me!!! I got it from a CNET download "Classic Arcade Pack" from Openwares.org... I removed that first, then I removed the NSIS and crashed the system at the click OK prompt... Seems to have done the trick. thx Sammy
  #60  
Old November 27th, 2006, 11:07 AM
ninja9 ninja9 is offline
Infrequent Poster
 
Join Date: Nov 2006
Posts: 1
Default Re: NSIS Media Popups

had anyone try stopzilla.........http://www.stopzilla.com/

i haven't try the registered version so it full functioning to the removal but it seems this program can detect nsis media as an malware............

i was infected and did these for removal...

1. uninstall nsis media from add and remove

2. delete the nsis registry key using registry editor

3. scan using trojan hunter.. did found trojan.. (my mcafee antivirus running in the background keep telling that there are viruses in folder /localsetting/temp... but it is not there.. i don't know about this)

4. delete the chrome folder..........and install the firefox again...

... now my firefox run normally....

Last edited by ninja9 : November 27th, 2006 at 11:20 AM.
  #61  
Old November 28th, 2006, 12:10 AM
LonnyRJones LonnyRJones is offline
Spyware Expert
 
Join Date: Apr 2003
Posts: 61
Default Re: NSIS Media Popups

SpyBot Search & Destory fix's it as of two weeks ago
Updates 2006-11-10 - Safer Networking Forums: http://forums.spybot.info/showthread.php?t=8850
  #62  
Old November 29th, 2006, 08:11 PM
novi novi is offline
Infrequent Poster
 
Join Date: Nov 2006
Posts: 2
Default Re: NSIS Media Popups

Nice info LonnyRJ.Spybot cleared it,or i hope that it's removed now coz the results of scanning are "negative" on this junk .Thats why i posted reply here,I just want to be sure is it totally removed from pc.Is there someone who used spybot few days or weeks ago,i would like to hear does it come back (that junk) after some timeI read here that this softver was made for spying credit card codes in online shoping.Is it safe now to use cards for online shoppingThanks Lonny once again,and thanks in advance if someone answer.
  #63  
Old November 29th, 2006, 08:40 PM
Longboard's Avatar
Longboard Longboard is offline
Very Frequent Poster
 
Join Date: Oct 2004
Location: Sydney, Australia
Posts: 2,873
Default Re: NSIS Media Popups

A bit OT:

Been watching here;
Always interesting to me that SB seems to perform poorly on "magazine tests", yet all the peeps who have some expertise regard it as a great tool.

There is a message there

(As an aside I recently registered at one magazine 'Webuser' forum who had given very positive reviews about PrevX and Spysweeper.
I actually recently dumped SS but am licensed PX member.
I wrote posts scathingly critical of both utilities and lo and behold both posts were pulled without notice or explanation )
__________________
Don't confuse me with someone who actually knows what they are talking about.
Linux Registered user 469135
Please, support Medecins Sans Frontieres
  #64  
Old November 30th, 2006, 04:22 AM
LonnyRJones LonnyRJones is offline
Spyware Expert
 
Join Date: Apr 2003
Posts: 61
Default Re: NSIS Media Popups

Novi

Nsis is relatively harmless, only does popups as far as i know,
It seams to be on a timer, so if its no completely gone, (should be) it will come back in a week or two.
From what Ive see it only gets installed with supposedly free software
That IS mentioned (this software is brought to you by NSIS media, or similar notice), you'd have to agree to have it installed.
As littlebits mentions earleyer in this thread

Longbourd
SpyBot S&D
Ad-Aware
avg antispyware
prevx
Spysweeper
windows defender
all good programs, unfortunatley we need more than one.
  #65  
Old November 30th, 2006, 08:21 AM
novi novi is offline
Infrequent Poster
 
Join Date: Nov 2006
Posts: 2
Default Re: NSIS Media Popups

Thank you Lonny for your answer .I tought that its much more dangerous by the reviews I read here,but if you say that its harmless I'll take your opinion then.Mmm,week or two you said (b4 popups again start to show up) if its not completely removed from system.So,since yesterday no popups again,one day without that scum is success for me .Just in case,I removed firefox 1.508,codecs and filters for video-audio streaming and some games i downloaded like freeware in past days (all that seems to be potentially entries of Nsis on system).I hope that its gone for ever,but if it shows up again I'll post reply here,so that we could continue fight against it .
  #66  
Old December 10th, 2006, 11:33 AM
stevenf12801 stevenf12801 is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 1
Big Grin Re: NSIS Media Popups

This NSIS seemed to be such a problem, with both Firefox & IE, IE I couldn't even open up. The big hammer on for Firefox to generate this, I think is wrong. Symantic had known about this since 3/21/05, where in another forum others think it's a newbe. Spybot located and removed it but obvious as to others it came back. I removed Ad-aware, and nullsoft (is associated with NSIS) also winamp.... removed it manually in regedit, through program files, ad remove programs...with the ns** file #'s changing on it's return. Cleaned the registry with numerous cleaners, it still came back...even "crashed" the system by unpulgging after a 'cleaning'. Still returned! Going to my computer\program files\common files\ I opened the folder NSIS to a ns**file and a uninst.exe...I clicked on uninst.exe, it opened to uninstall, I went for it...that's all it took to clean it out!!! Simple! I went through in regedit, there was a folder there, removed it, checked program file\common file...it's gone, also ad-remove, gone!!! Cleaned the registry, and Halleluyah!!! Cleaned!!! IE opened right up!!! I've seen where others had it easy removal also....I didn't read all the postings in this forum. So may the nightmare not continue! Steve
  #67  
Old December 15th, 2006, 04:00 AM
siliconman01 siliconman01 is offline
Frequent Poster
 
Join Date: Mar 2003
Location: West Virginia (USA)
Posts: 761
Default Re: NSIS Media Popups

The site below provides some useful info on this NSIS infection:

http://kichik.net/
  #68  
Old December 15th, 2006, 09:22 AM
PaulBB PaulBB is offline
Frequent Poster
 
Join Date: Jan 2006
Posts: 223
Default Re: NSIS Media Popups

the NSIS Media Uninstaller by NSIS Media himself:
hxxp://nsismedia.net/uninstall/
__________________
http://removebloatware.org/
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:53 AM.


Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2010, Wilders Security Forums