Author Topic: WebSiteViewer  (Read 3286 times)

Felix

  • Guest
WebSiteViewer
« on: January 28, 2005, 06:51:20 PM »
Ok, I've been infested with a nasty Spyware program that reinstalls intself all the time. Soooooo annoying. Can anyone help me how to get rid of this, as I know nothing about these kinds of things.

Anyways here's my hijackthis log:

Logfile of HijackThis v1.98.2
Scan saved at 22:48:50, on 28.01.2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Programme\Java\j2re1.4.2_06\bin\jusched.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\Programme\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\prvdi.exe
C:\Programme\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Programme\WebSiteViewer\127021.dlr
C:\Programme\RegCleaner\RegCleanr.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://69.50.160.100/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://69.50.160.100/
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Programme\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programme\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1098355668218
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

Anyone know what's going on?
Cheers for the help....

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
WebSiteViewer
« Reply #1 on: January 28, 2005, 10:04:39 PM »
I see you have Microsoft's Anti-Spyware installed
If there real time protection get's in our way of any fixes you will have to disable it.....

But first
I need you to download the latest version of Hijackthis
Open Hijackthis>>Config>>Misc Tools>>Check for updates online
If, for some reason it won't update you can download the latest version from my signature below and save it to your
C:\HJT folder, allowing to overwrite your version if prompted

Could you also download and install
Download and Install the free version of Ad-Aware SE Personal 1.05
Ensure you have this version or the paid version
Open Ad-Aware, ensure to click the  check for updates now link and Connect to download the latest updates
Ad-Aware may check for updates and run a scan when installing
Allow to update but don't run a scan at this time

Please print the rest of this out or save to a Notepad file on the desktop
Also, Know how to Start in safe mode in advance, I supplied a link below if you need it

Set Windows To Show Hidden Files and Folders
    * Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Under the Hidden files and folders heading select Show hidden files and folders.
    * Uncheck the Hide protected operating system files (recommended) option.
    * Uncheck the Hide Extensions for known file types
    * Click Yes to confirm.
    * Click OK.

Restart your computer into SAFE MODE

In safe mode look for and delete these files or folders if they exist
C:\127021.dlr Or 127021.exe <--file
C:\WINDOWS\System32\prvdi.exe <--this file

C:\Programme\WebSiteViewer <--this folder


Stay in safe mode
Do another scan with Hijackthis 1.99 and put a check next to these entries:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://69.50.160.100/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://69.50.160.100/


After you have ticked the above entries, close All other open windows, including this one
Leave Hijackthis open and click FIX CHECKED
YES and exit Hijackthis

Open Ad-aware and
Perform a Full system scan--
When it's finished scanning
At this point you should either right click on the screen and and choose the "Select All" Objects option or individually put a checkmark in each objects checkbox
click on the Next button. Ad-Aware SE will now present you with a confirmation box as to whether or not you would like to remove the objects you have just selected. Press the "OK" button

RESTART your computer back to Normal mode to finish the cleaning process

I don't see you running any Anti-Virus software
If you have your own please enable it now and update it and run a full system scan
If you don't have your own and need a free solution I highly recommend that you
Download and install the free version
of AVAST free edition
You will have to register online and supply them with a legitimate Email address
after you install the product and Restart the computer
Don't supply them with a webbased one such as Hotmail
After registering online they will email you a License key for your free product, simply copy the License number and then
Right click the Avast Icon by the Clock>>Left click About Avast!
License key>>Paste it in and your done
I believe you have 3 months to register
After you Install it please run a Full System scan
Let it fix whatever it finds

I also recommend the free version of
AVG7 free edition

You only need one or the other
Don't install both, choose which one you prefer and run a full system scan
Again, don't install both, but install at least one if you don't have your own

Post back with a fresh hijackthis log from Hijackthis 1.99  after you have done the above
Hold onto Ad-Aware, it's yours for free too.....
« Last Edit: January 28, 2005, 10:08:42 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here