NSLSXS?? Trojan?

Discussion in 'Malware Help (A Specialist Will Reply)' started by auntiem, Sep 29, 2006.

  1. auntiem

    auntiem Private E-2

    I've been trying for about a week to get soemthing off my computer. I think it is related to this nslsxs.dll file I have gotten. I can't find any info on this and the first scan that has even recognized it was bitdefender this morning (even though I've been running scans for days now).
    Winodws malicious remover and spybot found nothing, windows defender found and removed 1 file and the log for bitdefender is attached.
    I know I have windowsantiviruspro and also something called cleandisk, I believe, popping up. I've removed malware before with the help of your forums but am getting nowhere with this one.
    I have done all the steps requested and will attach the logs.
    Thank you
     

    Attached Files:

  2. auntiem

    auntiem Private E-2

    NSLSXS - scans resutls

    Here are the last two scan results you requested.

    Thank you for any help you may be able to give me in advance.

    auntiem
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: NSLSXS - scans resutls

    You must not be using MSconfig to control Startups! As requested in step 7 of the READ ME, you must be in Normal Startup mode. So make sure you run MSconfig and select Normal Startup mode now. Then click Apply and OK. Do not reboot if it tells you to do so. We will reboot later.

    Are your copies of Spy Sweeper and Ewido free trials or paid versions? If free, uninstall them now! If paid, tell me which ones.

    Uninstall the below old version of Sun Java:
    J2SE Runtime Environment 5.0 Update 4

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of nslsxs.dll once and then click the kill button. After you have killed all of the nslsxs.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of nslsxs.dll and kill it. (If you do not find the dll, just continue on.)


    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: (no name) - {5C549074-4E07-4858-B3A7-012863F4CF5D} - C:\WINDOWS\system32\nslsxs.dll
    O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab
    O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/installers/cab/WinAntiVirusPro2006FreeInstall.cab
    O20 - Winlogon Notify: nslsxs - C:\WINDOWS\SYSTEM32\nslsxs.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\pss\Zeno.lnk
    C:\WINDOWS\pss\ktad.exe
    C:\WINDOWS\pop06ap2.exe
    C:\WINDOWS\thiselt.exe
    C:\WINDOWS\xload.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ktad.exe
    C:\Documents and Settings\Marion\Local Settings\Temp\ICD1.tmp\UWA6P_0001_N91M1807NetInstaller.exe
    C:\Documents and Settings\Marion\Local Settings\Temp\w181609.Stub.exe"
    C:\Documents and Settings\Marion\Local Settings\Temporary Internet Files\Content.IE5\6D29GHIV\WinAntiVirusPro2006FreeInstall[1].cab
    C:\WINDOWS\Downloaded Program Files\CONFLICT.1\USDR6_0001_D19M2108NetInstaller.exe
    C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UDC6_0001_D19M1908NetInstaller.exe
    C:\WINDOWS\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe
    C:\WINDOWS\Downloaded Program Files\USDR6_0001_D19M2108NetInstaller.exe
    C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N91M1807NetInstaller.inf
    C:\WINDOWS\system32\taskkill.exe
    C:\WINDOWS\system32\nslsxs.dll
    C:\WINDOWS\system32\rsysuu2d.exe
    C:\WINDOWS\system32\qvdv9r78.exe
    C:\WINDOWS\system32\stb.exe
    C:\WINDOWS\system32\putnni.exe
    C:\windows\system32\psdxregs.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folders and delete if found:
    C:\Documents and Settings\Marion\Application Data\SystemDoctor 2006 Free
    C:\Program Files\Microsoft AntiSpyware
    C:\WINDOWS\pss
    C:\Program Files\SurfSideKick 3

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Marion\Local Settings\Temp

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
    Last edited: Sep 30, 2006
  4. auntiem

    auntiem Private E-2

    Hi and thank you for your help. I have uninstalled the programs you mentionned to, and have run process explorer and rebooted in normal (forgot i was in selective start-up). I ran HJT and got rid of all the entries that you suggested.
    I saved the files to the fixme.reg file through notepad, but when I try to merge it won't let me.

    " The specified file is not a registry script. You can only import binary registry files from within the registry editor".

    I didn't see til after I posted that you wanted system info. I'm running windows xp, sp2, 2.6Ghxz, 504 ram,celeron cpu.

    thank you
    auntiem
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try again and make sure to follow the directions exactly as written. There is nothing wrong with the script. This error normally occurs when the file is not saved properly.
     
  6. auntiem

    auntiem Private E-2

    Hi,

    I finished the processes you gave me to run and they all worked fine, but there's stuff in my hjt log that wasn't there before. Is this right??
    At the moment, all is working fine. No pop- ups and nothing eating up my cpu resources.

    A couple of questions - is nslsxs new?? Is this why I couldn't find anything about it? and does windows bit defender really work? Not sure what it is about the program, I'm just wondering about it.

    I've attached a new hjt log and the other 2 logs requested.

    Thank you,
    auntiem
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is somewhat ew but malware changes names at random inorder to hide from you and scanners.

    Yes Windows Defender works but it is not the best. However it is free. There are better tools but you will have to buy them. Let me know if you want alternatives.

    You have a whole bunch of new problems that showed up. This is due to the fact that you have no antivirus and no firewall installed.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [ZStart] C:\windows\system32\psdxregs.exe DO0605
    O4 - HKLM\..\Run: [xload] "C:\WINDOWS\xload.exe"
    O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\putnni.exe reg_run
    O4 - HKLM\..\Run: [wincin] C:\DOCUME~1\Marion\LOCALS~1\Temp\w181609.Stub.exe
    O4 - HKLM\..\Run: [SysStart] C:\WINDOWS\system32\rsysuu2d.exe DO0605
    O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O4 - HKLM\..\Run: [stb] C:\WINDOWS\system32\stb.exe
    O4 - HKLM\..\Run: [qvdv9r78] C:\WINDOWS\system32\qvdv9r78.exe
    O4 - HKLM\..\Run: [pop06apelt] C:\WINDOWS\thiselt.exe
    O4 - HKLM\..\Run: [pop06ap] C:\WINDOWS\pop06ap2.exe
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (many/all of these may already be gone)
    :
    C:\windows\system32\psdxregs.exe
    C:\WINDOWS\xload.exe
    C:\WINDOWS\system32\putnni.exe
    C:\Documents and Settings\Marion\Local Settings\Temp\w181609.Stub.exe
    C:\WINDOWS\system32\rsysuu2d.exe
    C:\WINDOWS\system32\stb.exe
    C:\WINDOWS\system32\qvdv9r78.exe
    C:\WINDOWS\thiselt.exe
    C:\WINDOWS\pop06ap2.exe
    C:\Program Files\Microsoft AntiSpyware <--- the whole folder
    C:\Program Files\SurfSideKick 3 <--- the whole folder

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. auntiem

    auntiem Private E-2

    Thank you,

    I have done all the things you suggested in the previous post.

    As far as a firewall, we have a router (non-wireless) which is supposed to provide us with a firewall. At least that was my understanding.

    I don't have anti-virus as I've had trouble finding one that doesn't tie everything up. However, I did notice there are some you recommend that don't tie everything up. I'll try those and see how I make out.

    The files which I just deleted were all things that were in my start-up. I was booting in selective start-up so they wouldn't run. I see they are gone now from there.

    Thank you
    auntiem
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is a good start but you still need a Software firewall which will add a greater level of security and that is more upto date.

    Yes you have to use one. Unless you would prefer to be "tied up" by malware and trying to repair the malware problems created.

    And that is why step 7 of the READ ME requests that you NOT use Msconfig to control startups and instructs you to select Normal Startup before using HJT.

    How are things working now?
     
  10. auntiem

    auntiem Private E-2

    Hi,
    Things seem to be working great!!
    Thanks so much for all your help - it's greatly appreciated.

    auntiem
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds