Download the PeperFix.exe tool from here:
http://downloads.subratam.org/PeperFix.exe
Click on the PeperFix.exe to launch it.
Click the Find and Fix button.
It will scan the %Systemroot% folder and locate all the peper files. You will be prompted to reboot. Reboot and it will delete the peper files.
Ensure that you are online before starting the fix. Make sure to run the fix twice.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Have you run the recommended (and free) "spyware" removal utilities decribed in this thread?:
http://www.daniweb.com/techtalkforums/thread5690.html
If not, do so.
Before running the utilities, clear your Temporary Internet files (including "offline content"), delete your Cookies, and empty your Recycle BIn.
Let the utilities fix whatever they find and then post a new HJTlog.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
hey thanx for the help. I ran the program twice and then it says that no peper files where detected.
Were you online when you ran the fix? You have to be online. Peper is definitely showing in your log. Please do as DMR suggests then reboot your system, thenGo here for an on-line scan & set it to autoclean for you.
Try this scan as well.
Post your log after doing that.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or directly on the desktop (in a folder on the desktop is fine) & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/cus...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/cus...://my.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {905429DE-19AE-14A9-E359-B2D986ECF629} - C:\WINDOWS\system32\ipgb.dll
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automove.exe
O4 - HKLM\..\Run: [AutoLoader20sp1PIjZYPI] "C:\WINDOWS\System32\shefos.exe" /PC="AM.SKHN" /HideUninstall /HideDir
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [ipgb.exe] C:\WINDOWS\system32\ipgb.exe
O4 - HKLM\..\RunOnce: [ipds.exe] C:\WINDOWS\ipds.exe
O4 - HKLM\..\RunOnce: [sysdw32.exe] C:\WINDOWS\system32\sysdw32.exe
O4 - HKLM\..\RunOnce: [msuu.exe] C:\WINDOWS\system32\msuu.exe
O4 - HKLM\..\RunOnce: [ipyj.exe] C:\WINDOWS\system32\ipyj.exe
O4 - HKLM\..\RunOnce: [appjb32.exe] C:\WINDOWS\appjb32.exe
O4 - HKLM\..\RunOnce: [mfcia32.exe] C:\WINDOWS\system32\mfcia32.exe
O4 - HKLM\..\RunOnce: [addbu32.exe] C:\WINDOWS\system32\addbu32.exe
O4 - HKLM\..\RunOnce: [appwx32.exe] C:\WINDOWS\appwx32.exe
O4 - HKLM\..\RunOnce: [nettz.exe] C:\WINDOWS\nettz.exe
O4 - HKLM\..\RunOnce: [apidg.exe] C:\WINDOWS\apidg.exe
O4 - HKLM\..\RunOnce: [apion.exe] C:\WINDOWS\system32\apion.exe
O4 - HKLM\..\RunOnce: [ntjy32.exe] C:\WINDOWS\ntjy32.exe
O4 - HKLM\..\RunOnce: [crme32.exe] C:\WINDOWS\system32\crme32.exe
O4 - HKLM\..\RunOnce: [atlyj.exe] C:\WINDOWS\system32\atlyj.exe
O4 - HKLM\..\RunOnce: [ieim32.exe] C:\WINDOWS\ieim32.exe
O4 - HKLM\..\RunOnce: [cryn.exe] C:\WINDOWS\system32\cryn.exe
O4 - HKLM\..\RunOnce: [crfs32.exe] C:\WINDOWS\system32\crfs32.exe
O4 - HKLM\..\RunOnce: [d3yo32.exe] C:\WINDOWS\system32\d3yo32.exe
O4 - HKLM\..\RunOnce: [javajl32.exe] C:\WINDOWS\system32\javajl32.exe
O4 - HKLM\..\RunOnce: [ipnr32.exe] C:\WINDOWS\ipnr32.exe
O4 - HKLM\..\RunOnce: [addba.exe] C:\WINDOWS\addba.exe
O4 - HKLM\..\RunOnce: [crif.exe] C:\WINDOWS\crif.exe
O4 - HKLM\..\RunOnce: [appod32.exe] C:\WINDOWS\system32\appod32.exe
O4 - HKLM\..\RunOnce: [ntov.exe] C:\WINDOWS\ntov.exe
O4 - HKLM\..\RunOnce: [sdkxo.exe] C:\WINDOWS\system32\sdkxo.exe
O4 - HKLM\..\RunOnce: [apihg32.exe] C:\WINDOWS\system32\apihg32.exe
O4 - HKLM\..\RunOnce: [d3wl.exe] C:\WINDOWS\system32\d3wl.exe
O4 - HKLM\..\RunOnce: [winxj.exe] C:\WINDOWS\winxj.exe
O4 - HKLM\..\RunOnce: [addew.exe] C:\WINDOWS\system32\addew.exe
O4 - HKLM\..\RunOnce: [atlpu.exe] C:\WINDOWS\atlpu.exe
O4 - HKLM\..\RunOnce: [ieqa32.exe] C:\WINDOWS\system32\ieqa32.exe
O4 - HKLM\..\RunOnce: [ieko.exe] C:\WINDOWS\system32\ieko.exe
O4 - HKLM\..\RunOnce: [atlcv32.exe] C:\WINDOWS\atlcv32.exe
O4 - HKLM\..\RunOnce: [javarq32.exe] C:\WINDOWS\javarq32.exe
O4 - HKLM\..\RunOnce: [apppj.exe] C:\WINDOWS\apppj.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [ir32_32] C:\WINDOWS\System32\ir32_32.exe
O4 - HKCU\..\Run: [Jws9RRZpe] avimsnsv.exe
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} (F1 Organizer Class) - http://www.addictivetechnologies.ne...b/TrfV3nd02.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50151/QDow_AS2.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {D97287B6-4018-4060-948D-54D2122FC5C3} - http://www.fastfind.org/ss/client/5...03C00/setup.exe
O16 - DPF: {FE4BBEA8-1EFD-4B8A-BD1B-341CCDBEEAA6} - http://ads.dealhelper.com/updates/DealHelperNew.cab
Reboot into safe mode following the instructions here & navigate to & delete the following if found:
C:\WINDOWS\System32\automove.exe<<<<
C:\WINDOWS\System32\shefos.exe<<<<
C:\Program Files\AutoUpdate<<<<
C:\WINDOWS\system32\ipgb.exe<<<
C:\WINDOWS\ipds.exe<<<<
C:\WINDOWS\system32\sysdw32.exe<<<<
C:\WINDOWS\system32\msuu.exe<<<<
C:\WINDOWS\system32\ipyj.exe<<<<
C:\WINDOWS\appjb32.exe<<<<
C:\WINDOWS\system32\mfcia32.exe<<<<
C:\WINDOWS\system32\addbu32.exe<<<<
C:\WINDOWS\appwx32.exe<<<<
C:\WINDOWS\nettz.exe<<<<
C:\WINDOWS\apidg.exe<<<<
C:\WINDOWS\system32\apion.exe<<<<
C:\WINDOWS\ntjy32.exe<<<<
C:\WINDOWS\system32\crme32.exe<<<<
C:\WINDOWS\system32\atlyj.exe<<<<
C:\WINDOWS\ieim32.exe<<<<
C:\WINDOWS\system32\cryn.exe<<<<
C:\WINDOWS\system32\crfs32.exe<<<<
C:\WINDOWS\system32\d3yo32.exe<<<<
C:\WINDOWS\system32\javajl32.exe<<<<
C:\WINDOWS\ipnr32.exe<<<<
C:\WINDOWS\addba.exe<<<<
C:\WINDOWS\crif.exe<<<<
C:\WINDOWS\system32\appod32.exe<<<<
C:\WINDOWS\ntov.exe<<<<
C:\WINDOWS\system32\sdkxo.exe<<<<
C:\WINDOWS\system32\apihg32.exe<<<<
C:\WINDOWS\system32\d3wl.exe<<<<
C:\WINDOWS\winxj.exe<<<<
C:\WINDOWS\system32\addew.exe<<<<
C:\WINDOWS\atlpu.exe<<<<
C:\WINDOWS\system32\ieqa32.exe<<<<
C:\WINDOWS\system32\ieko.exe<<<<
C:\WINDOWS\atlcv32.exe<<<<
C:\WINDOWS\javarq32.exe<<<<
C:\WINDOWS\apppj.exe<<<<
C:\Program Files\SpyKiller<<<<
C:\WINDOWS\System32\ir32_32.exe<<<<
Reboot normally after doing the above then post a fresh log please.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Go to Start>Run and type msconfig Press enter.
When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.
Check the box labeled Turn off System restore.
Reboot.
Reboot into safe mode following the instructions here & navigate to & delete the following:
C:\Program Files\AutoUpdate< folder
C:\WINDOWS\System32\he3bbcff.dll< file
C:\WINDOWS\System32\wmcbaaca.dll< file
C:\WINDOWS\System32\icddefff.dll< file
C:\WINDOWS\System32\ielcaabe.dll< file
O4 - HKLM\..\Run: [273V35V] shefos.exe< file
C:\WINDOWS\System32\icddefff.dll< file
C:\WINDOWS\System32\he3bbcff.dll< file
C:\WINDOWS\System32\ielcaabe.dll< file
C:\WINDOWS\System32\wmcbaaca.dll< file
C:\WINDOWS\system32\ipgb.exe< file
C:\WINDOWS\systk.exe< file
C:\WINDOWS\crqb.exe< file
C:\WINDOWS\System32\ir32_32.exe< file
In order to view these files you may have to select 'show hidden files/folders.' Instructions on how to here.
Still in safe mode Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked':
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [he3bbcff] rundll32.exe C:\WINDOWS\System32\he3bbcff.dll,EnableRunDLL32
O4 - HKLM\..\Run: [wmcbaaca] rundll32.exe C:\WINDOWS\System32\wmcbaaca.dll,EnableRunDLL32
O4 - HKLM\..\Run: [icddefff] rundll32.exe C:\WINDOWS\System32\icddefff.dll,EnableRunDLL32
O4 - HKLM\..\Run: [ielcaabe] rundll32.exe C:\WINDOWS\System32\ielcaabe.dll,EnableRunDLL32
O4 - HKLM\..\Run: [273V35V] shefos.exe
O4 - HKLM\..\Run: [icdd7ee6] rundll32.exe C:\WINDOWS\System32\icddefff.dll,EnableRunDLL32
O4 - HKLM\..\Run: [he3e3fc4] rundll32.exe C:\WINDOWS\System32\he3bbcff.dll,EnableRunDLL32
O4 - HKLM\..\Run: [iel2cde8] rundll32.exe C:\WINDOWS\System32\ielcaabe.dll,EnableRunDLL32
O4 - HKLM\..\Run: [wm41a398] rundll32.exe C:\WINDOWS\System32\wmcbaaca.dll,EnableRunDLL32
O4 - HKLM\..\Run: [ipgb.exe] C:\WINDOWS\system32\ipgb.exe
O4 - HKLM\..\RunOnce: [systk.exe] C:\WINDOWS\systk.exe
O4 - HKCU\..\Run: [wping.exe] C:\WINDOWS\System32\wping.exe
O4 - HKCU\..\Run: [ir32_32] C:\WINDOWS\System32\ir32_32.exe
Reboot normally after doing the above then post a fresh log please.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985