This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Security Alert: Netwom-i.Virus@fp

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I get pop-ups saying my computer is infected with one of the 3 viruses
1. Networm-i.virus@fp
2. Spyware.cyberlog-x
3. Spyworm.win32

I have installed ESET NOD 32 Antivirus 4 with no luck (I have the latest updates as well).

Attached is my log file:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:26:27 PM, on 24/11/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\WebMediaViewer\qttask.exe
C:\Program Files\WebMediaViewer\hpmon.exe
C:\WINNT\system32\atiptaxx.exe
C:\WINNT\system32\GSICON.EXE
C:\WINNT\system32\dslagent.exe
C:\WINNT\system32\CTHELPER.EXE
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\WebMediaViewer\qttaskm.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\WebMediaViewer\hpmom.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINNT\system32\LVComS.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: VirTriggerWarningBHO Class - {0088C75C-6361-4dfb-B2CF-576CACFA3C55} - C:\Program Files\VirTrigger\VirTriggerWarning.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: 512686 helper - {51B15F5A-E98B-4658-B9CB-9307B74773A7} - (no file)
O2 - BHO: (no name) - {64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C} - C:\Program Files\WebMediaViewer\hpmun.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Browser Toolbar - {2EEF94DF-75F6-42E9-B7FB-AF5A170A6E2E} - C:\Program Files\WebMediaViewer\browseul.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINNT\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpppta] C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hpppta.exe /ICON
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKLM\..\Policies\Explorer\Run: [QuickTime Task] C:\Program Files\WebMediaViewer\qttask.exe
O4 - HKLM\..\Policies\Explorer\Run: [VMware hptray] C:\Program Files\WebMediaViewer\hpmon.exe
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.ietoolexpress.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IExplorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.ietoolexpress.com/redirect.php (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1204011799801
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1204014685530
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8FB079F2-58C2-41FF-AD1D-B45D7A1E6D9B}: NameServer = 209.250.128.6 209.250.128.8
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

–
End of file - 8149 bytes
Hello daredevilxtc and welcome to the forums.

Please do not run any other programs with out my permission !!
Run all programs in the order posted !!!!!


My name is flashh4 and I will be helping you to remove any infection(s) that you may have.

Please observe these rules while we work:

1. If you don't know, stop and ask! Don't keep going on.
2. Please reply to this thread. Do not start a new topic.
3. Please continue to respond until I give you the "All Clear"
(Just because you can't see a problem doesn't mean it isn't there)
4. Please note you'll need to have Administrator privileges to perform the fixes. (XP accounts are Administrator by default)
5. Please let me know if you are using a computer with multiple accounts, as this can affect the instructions given.

If you can do those things, everything should go smoothly.

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.

Note: I am still in training at Malware Removal, however I will be working under the direct supervision of one of our Malware Experts. Any recommendations will first be approved before being given to you. Because of this, there may be a short delay in getting our responses to you, however be assured that we will be working diligently on your problem.

I will be back as soon as possible with a fix !!
In the mean time can you give me an Uninstall list please !!


  • Open HijackThis.
  • Click on the Open the Misc Tools section button.
  • Look under System tools.
  • Click on the Open Uninstall Manager… button.
  • Click on the Save list… button.
  • It will prompt you to save. Save this log in a convenient location. By default it's named uninstall_list.txt.
  • Notepad will open. Please post this log in your next reply.


Thanks
Chuck
Hi Chuck, Thanks for your help…please don't be upset… Before I originally posted my request I did remove a couple of applications that seemed 'fishy'… Also, I really needed my computer back up and running so I took a bit of gamble it seems. I have used an earlier version of hijack…so I searched other forums to see people with similar issues. I have run Malware. It seems to be OK but I will post as you have suggested in case I did not clean out my system entirely…. Adobe AIR Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Media Player Adobe Media Player Adobe Reader 8.1.2 ATI Display Driver ATI Multimedia Center Canon Camera Support Core Library Canon Camera TWAIN Driver 6.4 Canon G.726 WMP-Decoder Canon MovieEdit Task for ZoomBrowser EX Canon PhotoRecord Canon RAW Image Task for ZoomBrowser EX Canon Utilities CameraWindow Canon Utilities CameraWindow DC Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX Canon Utilities MyCamera Canon Utilities MyCamera DC Canon Utilities PhotoStitch 3.1 Canon Utilities RemoteCapture DC Canon Utilities RemoteCapture Task for ZoomBrowser EX Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility DivX Codec DivX Converter DivX Player DivX Web Player GlobeSpan DSL Modem Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer HijackThis 2.0.2 Hotfix for MDAC 2.53 (KB927779) Hotfix for Microsoft .NET Framework 2.0 Service Pack 1 (KB947748) HP PrecisionScan Pro HP Scan-to-Web Wizard Japanese Fonts Support For Adobe Reader 8 Java™ 6 Update 4 Lexmark 510 Series LimeWire 4.18.3 Logitech Print Service Logitech QuickCam Malwarebytes' Anti-Malware Microsoft .NET Framework 2.0 Service Pack 1 Microsoft ActiveSync Microsoft Office 2000 Disc 2 Microsoft Office 2000 Premium Mozilla Firefox (3.0.4) MSN Messenger 7.0 MSN Toolbar MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) Nero 7 Essentials neroxml Opera 8.65 for Windows Mobile 5 Pocket PC Security Update for DirectX 8 (KB941568) Security Update for DirectX 8 (KB951698) Security Update for DirectX 9 (KB951698) Security Update for Windows 2000 (KB941569) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 7.1 (KB936782) Security Update for Windows Media Player 9 (KB936782) Sound Blaster Live! Web 2K/XP Spb Full Screen Keyboard Update Rollup 1 for Windows 2000 SP4 Vuze WebCam for MSN Messenger Winamp Winamp Remote Windows 2000 Hotfix - KB842773 Windows 2000 Hotfix - KB893756 Windows 2000 Hotfix - KB896358 Windows 2000 Hotfix - KB896422 Windows 2000 Hotfix - KB896423 Windows 2000 Hotfix - KB899587 Windows 2000 Hotfix - KB899589 Windows 2000 Hotfix - KB900725 Windows 2000 Hotfix - KB901017 Windows 2000 Hotfix - KB901214 Windows 2000 Hotfix - KB905414 Windows 2000 Hotfix - KB905495 Windows 2000 Hotfix - KB905749 Windows 2000 Hotfix - KB908519 Windows 2000 Hotfix - KB908531 Windows 2000 Hotfix - KB911280 Windows 2000 Hotfix - KB913580 Windows 2000 Hotfix - KB914388 Windows 2000 Hotfix - KB914389 Windows 2000 Hotfix - KB917008 Windows 2000 Hotfix - KB918118 Windows 2000 Hotfix - KB920213 Windows 2000 Hotfix - KB920670 Windows 2000 Hotfix - KB920683 Windows 2000 Hotfix - KB920685 Windows 2000 Hotfix - KB921398 Windows 2000 Hotfix - KB922582 Windows 2000 Hotfix - KB923191 Windows 2000 Hotfix - KB923414 Windows 2000 Hotfix - KB923810 Windows 2000 Hotfix - KB923980 Windows 2000 Hotfix - KB924270 Windows 2000 Hotfix - KB924667 Windows 2000 Hotfix - KB925902 Windows 2000 Hotfix - KB926122 Windows 2000 Hotfix - KB926436 Windows 2000 Hotfix - KB927891 Windows 2000 Hotfix - KB928843 Windows 2000 Hotfix - KB930178 Windows 2000 Hotfix - KB931784 Windows 2000 Hotfix - KB933729 Windows 2000 Hotfix - KB935839 Windows 2000 Hotfix - KB935840 Windows 2000 Hotfix - KB936021 Windows 2000 Hotfix - KB937894 Windows 2000 Hotfix - KB938127 Windows 2000 Hotfix - KB938464 Windows 2000 Hotfix - KB938827 Windows 2000 Hotfix - KB938829 Windows 2000 Hotfix - KB941202 Windows 2000 Hotfix - KB941644 Windows 2000 Hotfix - KB941693 Windows 2000 Hotfix - KB943055 Windows 2000 Hotfix - KB943485 Windows 2000 Hotfix - KB944338 Windows 2000 Hotfix - KB944533 Windows 2000 Hotfix - KB945553 Windows 2000 Hotfix - KB947864 Windows 2000 Hotfix - KB948590 Windows 2000 Hotfix - KB948881 Windows 2000 Hotfix - KB950749 Windows 2000 Hotfix - KB950759 Windows 2000 Hotfix - KB950760 Windows 2000 Hotfix - KB950974 Windows 2000 Hotfix - KB951066 Windows 2000 Hotfix - KB951748 Windows 2000 Hotfix - KB952954 Windows 2000 Hotfix - KB953838 Windows 2000 Hotfix - KB953839 Windows 2000 Hotfix - KB954211 Windows 2000 Hotfix - KB955069 Windows 2000 Hotfix - KB956390 Windows 2000 Hotfix - KB956391 Windows 2000 Hotfix - KB957095 Windows 2000 Hotfix - KB957097 Windows 2000 Hotfix - KB958644 Windows 2000 Service Pack 4 Windows Installer 3.1 (KB893803) Windows Media Player Hotfix [See Q828026 for more information] Windows Media Player system update (9 Series) WinZip 12.0 ZoneAlarm ZoneAlarm Spy Blocker I really appreciate the support.
Hi daredevilxtc, please do not remove anything else unless i advise you to ! It just makes it harder for me to find and remove stuff !


REMOVE P2P PROGRAMS

IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

LimeWire 4.18.3'
Vuze'


P2P programs

We have noticed that most people seeking help from us are coming with infections contracted from the use of P2P programs.

Because of this, we felt we needed to change our policy on the use of P2P file sharing programs.

* If your helper detects the presence of such programs on your computer he/she will ask you to remove them. We will withdraw our help should you not agree to their removal.
* If we clean your computer of infection, and you return to us a short time later with an infection contracted by the use of P2P programmes, we will refuse our help.



We do not ask you to do this without reason.

P2P programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P programme is not configured correctly you may be sharing more files than you realise. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured programme.

This article from InfoWorld illustrates perfectly the dangers of a poorly configured P2P program.
http://www.infoworld.com/article/07/09/06/…ID-theft_1.html

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.


This is how you uninstall it/them:

* Click Start
* Go to Control Panel
* Go to Add/Remove Programs
* Find and click Remove for the following (if present):

LimeWire 4.18.3'
Vuze'
Google Toolbar for Internet Explore
( uninstall this also )

Note: Take care when answering any questions posed by an uninstaller. Some questions may be worded to deceive you into keeping the program.




If you removed the P2P programs Please post these:
1. New HJT log
2. New Uninstall List

Thanks
Chuck

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI