Logfile of HijackThis v1.97.2 Scan saved at 6:24:20 PM, on 9/19/03 Platform: Windows 98 Gold (Win9x 4.10.1998) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE

Logfile of HijackThis v1.98.2 Scan saved at 5:34:40 PM, on 8/28/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe First download and run THIS to remove the peper trojan from your computer ( Remain connected to the internet when you run this uninstall

You can run regedit and navigate to: HKEY_CLASSES_ROOT\scrfile\shell\open\command >> double click on "default" and copy the above bolded data to the data field for the scr command.

Save that notepad file reboot normally Use the Reply button and attach the notepad file here .

Keep it in the forums, so everyone benefits

C:\Explorer.exe: not present C:\WINDOWS\Explorer\Explorer.exe: not present C:\WINDOWS\System\Explorer.exe: not present C:\WINDOWS\System32\Explorer.exe: not present C:\WINDOWS\Command\Explorer.exe: not present C:\WINDOWS\Fonts\Explorer.exe: not present -------------------------------------------------- C:\WINDOWS\WININIT.BAK listing: (Created 1/9/2003, 12:50:24) [Rename] NUL=C:\WINDOWS\SYSTEM\JPICPL32.CPL -------------------------------------------------- Checking for superhidden extensions: Figure 1: FRST Save File dialog box Your browser will now download FRST and save it on your Desktop.

I downloaded WinPFind but haven't run it in safe mode yet. It may take a while to get a response because the HJT Team members are EXTREMELY busy working logs posted before yours.

Click Startup Programs and uncheck all items. Over to the left, Click shields and Uncheck all there. Accept the license agreement by clicking the "I Accept" button.

Please read through this agreement, and if you agree to it, please click on the Yes button to continue. Post that; it should tell us if the repair.reg file did what it was supposed to in repairing the .bat, .pif, .com and .scr extensions as well.