Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
hi
i found this backdoor then i run norton 2003 to del this.this worm was in the file esplore.exe.
but some trace stays i think bcoz i have identd problem
here is a copy of my hijack this logthanx for your help
i have doubt about filename nstask32.exe
cu
Logfile of HijackThis v1.96.0
Scan saved at 11:36:43, on 12/08/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\sstray.exe
C:\WINDOWS\System32\GSICON.exe
C:\WINDOWS\System32\dslagent.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Secway\SimpLite-MSN 2.0\SimpLite-MSN.exe
C:\Program Files\No-IP\DUC20.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.exe
C:\ssl\wrap.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe
C:\Documents and Settings\Manu\Local Settings\Temp\Répertoire temporaire 4 pour hijackthis.zip\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F0 - system.ini: Shell=explorer.exe nstask32.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [GSICONEXE] GSICON.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NDplDeamon] nstask32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.exe C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Simp] C:\Program Files\Secway\SimpLite-MSN 2.0\SimpLite-MSN.exe
O4 - Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.141/code/PWActiveXImgCtl.CAB
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by1fd.bay1.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{A6807261-C0FE-4038-93D1-393E2C3B5D31}: NameServer = 193.252.19.3 193.252.19.4

Yes, This does look suspicious:
O4 - HKLM\..\Run: [NDplDeamon] nstask32.exe
Could you email me a zipped copy of nstask32.exe to analyze? I'll let you know what it is. Click my name for the email addy.

I have the same problem with the file nstask32.exe, in C:\WINDOWS\SYSTEM32 (I have WINDOWS XP/PRO). It was created by the virus "TrojanDropper.win32small.bc. It was what the AVP antivirus informed. I deleted the file.
Also had the file win32sockdrv.dll, it was the virus "Backdoor.sdbot.at. I deleted it too.
The virus made the connection, when using a chat or a P2P program, to get cut.
After deleting the two "virus file", and before, always have the same message when starting :windows can not find the nstask32.exe file.
The problem continues, but the computer takes more time to get disconnected.
I don't know what configuration must change in order to avoid it.
I would really appreciate some help

I got this same worm. i dont know how i got it either. everytime i boot up i get cant find nstask32.exe and i deleted the win32sockdrv.dll file said it was a virus, some randy or something virus. how can i fix my pcand how did i get this i dontknow. i was using irc and talking but i ddint write anything or anything. someone must of hacked me but i dont know how. cause i know i didnt do anuything or download or run any stuff unless it came from some internet site that has a file with a virii in int. i know i didnt run any weird stuff. but i get that error too.

Hi Everyone.
The Trojan tried to leave nstask32.exe but it failed so it just left a stupid entry in your registry which makes logon extradordinarily slow. Here's the entry I found:HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
String Value
Name: Shell
Type: REG_SZ
Binary Value:
explorer.exe nstask32.exeJust remove the part after the explorer.exe and your logon will be back to normal. Cheers

how to get to registry
start->run type "regedit"I got the nstask32.exe and the win32sockdrv.dll and couldn't get rid of them. Each time i deleted one it would come back with the next boot. I also deleted all of the reg entry's it made that i could find but to no avail. I think it got there by rpc buffer overflow. Any way.... i finally gave up and formated. I used antivirus software too but it didn't work either.
I started looking at the code in nstask32.exe and it said in the code "you are owned by nataya kee" or some crap. Ha ha. the anti virus software said it was "dcom-rpc exploit trojan".

my Norton 2003 always pops up with a message that i have a file called brittanyspearsgame.exe on my comp...it deletes it and after a while it pops out again. I have been on symantec.com and read about removing 0 byte files from my startup and removing some data from my regedit but i cant find them and i still continue to get virus alert popups...can anyone help?

![]() |
NAV starts to scan, then ...
|
norton anti virus corpora...
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |