Rino,
Hello! and welcome to the Daniweb forums :).
-
You'll need to download uninst.exe to remove the 'peper' infection, then:
1. run uninst.exe ... (first pass).
2. reboot your computer.
3. run uninst.exe ... (final pass).
Note: You must have an active internet connection, each time this program is run, for it to properly work.
===============
Go to www.trendmicro.com , and then:
1. Click "Free Online Scan".
2. Click "Scan now, it's free".
It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:
1. Select all available drives.
2. Check(tick) "Auto Clean".
3. Click "Scan".
When it completes, post back the full filename of any files that cannot be cleaned or deleted.
===============
Run HiJackThis, click "Scan", then check(tick) the following, if present:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/cus...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/cus...://my.yahoo.com
R3 - URLSearchHook: (no name) - _{8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
O2 - BHO: (no name) - {51082128-B9B7-B51B-BB19-C9EE8980B9BF} - C:\WINDOWS\system32\lqu.dll (file missing)
O4 - HKLM\..\Run: [3] C:\documents and settings\alessia\local settings\temp\3.exe
O4 - HKLM\..\Run: [Open Site] "C:\Program Files\Open Site\opensite.exe"
O4 - HKLM\..\Run: [oF7] C:\documents and settings\rino\local settings\temp\oF7.exe
O4 - HKLM\..\Run: [gcqdf] C:\documents and settings\alessia\local settings\temp\gcqdf.exe
O4 - HKLM\..\Run: [q6bYXh] C:\documents and settings\alessia\local settings\temp\q6bYXh.exe
O4 - HKLM\..\Run: [Hyw7aeXO] C:\documents and settings\alessia\local settings\temp\Hyw7aeXO.exe
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [o6USPRl] C:\windows\system32\o6USPRl.exe
O4 - HKLM\..\Run: [mXMLIK.exe] c:\windows\system32\mXMLIK.exe
O4 - HKLM\..\Run: [4JATK3@4#AJHRM] C:\WINDOWS\system32\Kqxpex.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/021e0f2...ip/RdxIE601.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.roings.com/cabs/budicon.cab
O16 - DPF: {E62A47D8-74B1-4A93-963A-E5E43B7CC5C2} (UCSearch.ucUCSearch) - http://www.zuvio.com/opnste/UCSearch.CAB
O16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} - http://toolbar2.globalwebsearch.com/winenc32.cab
Now, with all windows closed except HiJackThis, click "Fix checked".
===============
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
folders...
C:\Program Files\Open Site
files...
C:\documents and settings\alessia\local settings\temp\3.exe
C:\documents and settings\rino\local settings\temp\oF7.exe
C:\documents and settings\alessia\local settings\temp\gcqdf.exe
C:\documents and settings\alessia\local settings\temp\q6bYXh.exe
C:\documents and settings\alessia\local settings\temp\Hyw7aeXO.exe
C:\windows\system32\o6USPRl.exe
c:\windows\system32\mXMLIK.exe
C:\WINDOWS\system32\Kqxpex.exe
search for...
D0CE0C16B1 and D0CE0C16B1
-
Note that some of these file(s)/folder(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them in " Safe Mode ".
-
Reboot.
===============
To help protect your system from hostile ActiveX content, or special 'downloadable' files:
Download, install and keep updated, SpywareBlaster . If you've installed it for the first time:
1) Check for any available updates; if present, they'll be automatically downloaded and installed.
2) Next, "Enable all protection".
3) Exit the program.
-
Note: Remember to regularly check for updates.
===============
After rebooting, rescan with hijackthis and post back a new log. Let me know how everything goes.