Nsis Media Pop-ups

Discussion in 'Malware Help (A Specialist Will Reply)' started by mikejulie4, Aug 9, 2006.

  1. mikejulie4

    mikejulie4 Private E-2

    I followed all directions posted in the stickythread http://forums.majorgeeks.com/showthread.php?t=35407

    I keep getting a popup the dialog box on the header displays "Advertisment - NSIS Media" with a ad in the body and while in internet explorer and during Moxilla Firefox that displays "A..." on the header but no ad. I googled it and found out the problem was located at C:\Program Files\Common Files\NSIS
    Files in the folder- uninst.exe, ns24.dll . But it was also said in one Forum that if you deleted or renamed the files it would just embed deeper into your system.

    I followed directions as best I could but the Scans would shut down half way through the scans in Safe Mode so I did everthing in Normal Mode.

    The only thing interesting that happened was during the Bitdefender scan Norton AntiVirus poped up and said I had a virus ( located C:/Documents and Settings/Mike/Local Settings/temp/tmp000049a3/tmp00000000) I could not remove it using Norton.

    I am attaching the files requested (3 in this post and 1 in a seperate thread)
    Thanks for your help. I really tried to follow directions exactly as was given. If I messed up just yell at me and then i will fix it.
     

    Attached Files:

  2. mikejulie4

    mikejulie4 Private E-2

    The other logfile requested is attached.
     

    Attached Files:

  3. mikejulie4

    mikejulie4 Private E-2

    Re: Nsis Media Pop-ups /HJT log

    Here is the Hijackthis log I forgot it in the 2nd post,sorry.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Nsis Media Pop-ups /HJT log

    Welcome to Majorgeeks,

    In your Add/Remove Programs list the below appears:
    NSIS Media Extension

    Have you actually tried just uninstalling this?
     
  5. mikejulie4

    mikejulie4 Private E-2

    Yes I have. But it keeps coming back.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will need to save the below information locally to a text file or print it because I will be telling you to disconnect from the internet soon!

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files".

    NOW DISCONNECT YOUR PC from the internet by unplugging the cable.


    Once you are disconnected from the internet and you have saved the file double click it and allow it to merge with the registry.
    Look for the below files and them if they exist, delete them(if you cannot delete it right now, boot into safe mode and see if you can delete them):
    C:\Program Files\Mozilla Firefox\chrome\nsis.jar
    C:\Windows\A~NSISu_.exe
    c:\windows\system32\krnsvr32.dll
    c:\windows\system32\wmdmb32.dll

    Just stay in safe mode if at any point you need to boot to safe mode to delete any files.


    Now delete the below folder and everything in it. (if you cannot delete it right now, boot into safe mode and see if you can delete it)
    C:\Program Files\Common Files\NSIS

    Now create the same folder as we just deleted (the NSIS folder) then right click on the folder from Windows Explorer and select Properties. Change the Attributes to have Read-only selected and also put a check in the Hidden box. (Note the Read-only option should already be set after creating the folder.)


    Now delete all files & subfolders in the below folder (downloading things like this is a sure way to have malware problems):
    C:\Documents and Settings\Mike\Local Settings\TEMP

    Note Windows may block deletion of a few files from the current date in the above folder.

    Now reboot into normal mode but do not reconnect to the internet yet. Just check to see if the problem files have come back or not. Hopefully the NSIS folder we recreated is empty.

    Now connect to the internet and again check the status of the NSIS folder.

    Now come back and tell me what happened.

    Questions: Did you ever have Foxie Browser Suit with Security Firewall installed?
     
    Last edited: Aug 9, 2006
  7. mikejulie4

    mikejulie4 Private E-2

    Well, so far so good nothing has shown up in the NSIS folder as of yet and no popups. No I did not download Foxie Browser.... but I did just recently started using Firefox and what I have read in other forums there are other ways to pick NSIS media up usually linked to Moxilla Firefox.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds good! FireFox is not the cause of the problem. It is just one of the vehicle's that the infection uses to reinfect you. Any program on your PC can be used as a vehicle for reinfection. Most often malware creators have used Microsoft processes like explorer.exe, iexplore.exe (Internet Explorer), and winlogon.exe. Something else that has been installed or a site you visited (etc) just made use Firefox.

    Make sure you download today's latest update to Sun Java: Sun Java Runtime Environment 5.0 Update 8

    Then uninstall any old versions. Also make sure you say NO to the Google Toolbar add-on unless you want that.
     
  9. mikejulie4

    mikejulie4 Private E-2

    Thank you so much. Do I need to doanything else?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds