Welcome, Guest. Please login or register.
December 31, 2009, 12:19:45 PM

Login with username, password and session length

346456 Posts
38292 Topics
86956 Members

Latest Member: Paranoimia

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  General Security Questions and Comments (not product related)
| | |-+  USB camera trojan
« previous next »
Pages: [1] Go Down Print
Author Topic: USB camera trojan  (Read 1269 times)
dph987
Newbie
*
Offline Offline

Posts: 8


« on: October 11, 2009, 03:31:58 AM »

A virus report.

Today I found these files added to windows directory that were created on  2nd June 2009 that I think is a trojan set. The modified date on these files is earlier than the creation date.

They are:
FixCamera.exe
tsnpstd3.exe
snpstd3.src
snpstd3.ini
vsnpstd3.exe
csnpstd3.dll

My Windows log revealed that, on the 1st June 09, I uninstalled 2 old security products: XoftSpy and Noadware5.0

Yesterday I uninstalled Adaware but the icon was still in the task tray!

I eventually tracked the task down to tsnpstd3.exe which was using the Adaware icon. The mouseover message read "Disconnected".

tsnpstd3.exe is supposed to be a non-essential camera task that is unrelated to security.

My PC was running slow and long delays were experienced using email and browsers.

At startup something would try to access the usb BIGDOG camera entry in the registry which I  would block. Whats more, my USB security camera software regularly lost the camera and I would have to unplug and plug it in again to get it to work.

I suspect this is a camera spy taking secret snapshots.

None of my regular spy and virus detection software (including comodo) found them.

Any ideas?
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 4375



« Reply #1 on: October 12, 2009, 07:52:40 PM »

Upload the .exe files to Virus Total and see what all scanner report. Leave the urls to the analysis pages here in the topic.

Also submit it to Comodo's Camas and let it generate a report for all three files. Please leave the urls to the reports here.

I assume that program has no uninstall entry in the list of installed software. Is that correct?
Logged

Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
cautim
Newbie
*
Offline Offline

Posts: 6


« Reply #2 on: November 20, 2009, 12:28:24 PM »

Any resolutions yet?

I recognize the executables, they came with my webcam. But I too experience problems with it. Sometimes unless I dissable and then enable the device from the device manager (i guess unplug replug would do the same trick) all I get is a black screen - probably meaning that the camera is already in use by another program... or perhaps it's just that the drivers are buggy.
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7694


... and I say to myself, "What a wonderful world"


« Reply #3 on: November 20, 2009, 03:33:04 PM »

fixcamera.exe is a tropjan/backdoor.

Boot into Safe More and delete fixcamera.exe. Similarly, get rid of tsnpstd3.exe.

Hope this helps,
Ewen :-)


Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
cautim
Newbie
*
Offline Offline

Posts: 6


« Reply #4 on: November 21, 2009, 01:13:16 PM »

Is that mandatory ? I mean, did I buy a webcam with a trojan bonus ? seriously...? I scaned with virustotal, it seems clean. I don't quite get it why it uses the CPU while I'm not using the cam, neither about what I've already talked about, so while it's suspicious, it's just too bad to be true also.
Logged
JJasper
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1418



« Reply #5 on: November 21, 2009, 05:38:55 PM »

Hi dph987 and cautim

If you have a lenovo webcam check this out.

http://forums.lenovo.com/t5/Options-Accessories/Why-the-drivers-CD-shipping-with-the-WebCam-has-Trojan-virus/m-p/34352 and this one

http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-69592

John
Logged
sweepergunsweeep
Newbie
*
Offline Offline

Posts: 3


« Reply #6 on: December 05, 2009, 03:07:01 PM »

i've got the same issue then i downloaded the original driver from the manufacturer web site
Logged
cautim
Newbie
*
Offline Offline

Posts: 6


« Reply #7 on: December 13, 2009, 07:47:08 AM »

Claiming a file is a trojan isn't of much help for me, if virustotal claims otherwise; neither does Comodo antivirus alert me. Getting rid of it is like getting rid of the cam. It's a no-name thing and unless I find something generic...

So, I installed the drivers again, on a presumably clean system (installed win a few days ago) and now winpatrol tells me that telnet wants to register/startup or something, and I have a TV\Video connection showing in my Network Connections. I don't know anything about telnet other than that I don't want it to connect anywhere. Weird thing is, I see only vsnpstd3.exe running in the process list this time. fixcamera.exe and tsnpstd3.exe used to come with it...

I couldn't be more confused... Huh

What's going on ? Is this normal ?

Here's the report from CIMA:
http://camas.comodo.com/cgi-bin/submit?file=383065fcda51cd5f39c78c983e60260a18e19a4513f680630502de3ddee0b61e
« Last Edit: December 13, 2009, 07:57:45 AM by cautim » Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.04 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com