Is nvsvcsb.exe a virus/spyware?

Hello,

Does anyone know what the nvsvcsb.exe does? Doing a google shows it is not listed anywhere.

A friend’s computer (WinXP SP2) recently got that nasty Skype worm as described in http://news.yahoo.com/s/pcworld/20070910/tc_pcworld/137007&printer=1;_ylt=ArdSws0q7Sv8trFdeqjqXkARSLMF

Most of the viruses/spyware from the Skype worm was removed in safe mode using AVG and Spybot. Now, there are messages from their firewall saying nvsvcsb.exe wants to access the Internet (IP address traces to Akamai.com). We’ve been denying it access so far.

I believe this executable is related to the Skype worm because it showed up after the computer got infected. But I can’t be sure since it’s not mentioned anywhere on-line. AVG and Spybot does not recognize it as a virus/spyware. The rootkit software(s) do not show anything. So why is it trying to access the Internet?

I don’t see it being in the startup services and I erased all entries containing nvsvcsb in the windows registry. Yet, /system32/nvsvcsb.exe keeps coming back as a process on bootup.

Thanks.

Hi Highlander,

Download MULTI_AV.EXE from the URL –
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following…
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on ‘Start Menu’ in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT – { or Double-click on ‘Start Menu’ in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor’s web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting ‘H’ or ‘h’ will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm

polonus

polonus,

Thanks for the reply but the www.ik-cs.com website appears to be down. Doing a google for multi_av.exe shows another link at:

http://help.lockergnome.com/security/Help-Virus-ftopict8710.html

I did a little more digging and found the nvdvcsb.exe filename on a Japanese website. From there, I was able to determine it’s part of the spy-agent.cj worm/virus which is transmitted via Skype. So it’s what I suspected in my original message.

Thanks.

A Translate link for a Japanese page, possibly the one you found, http://translate.google.com/translate?hl=en&sl=zh-TW&u=…=translate…

Send the sample to virus@avast.com zipped and password protected with password in email body and false positive/undetected malware in the subject.

Or you can also add the file to the User Files (File, Add) section of the avast chest where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.

Polonus,

You should have told me it would take SEVERAL HOURS to run through the scans from multi_av.exe. The Sophos scan alone took over 9 HOURS!

After doing all four scans (which took 2 days!), NONE of the scans found the spy-agent.cj worm.

It turns out, AVG put out an update yesterday which found and healed this worm. Even this update didn’t correct the windows registry which was looking for the worm executable on bootup. I fixed it manually with regedit.

Hi highlander,

Sorry that I have sent your complete box to virustotal, so to say. Anyways you know for sure now besides this problem your computer is clean.
There is however always the possibility that some unknown new malware has sought you out. Look at it this way, that you did it for the good of all the people of the forum that fight malware.

polonus