First lets get rid of peper trojan...
Go here:
http://www.pcworld.com/downloads/file_description/0,fid,22040,y,1,00.asp
Download 2xExplorer, unzip it, double click on 2xExplorer.exe and set up the following:
Menu> View> Options > Show hidden files should be checked > ok.
Menu > Tools > Find Files:
Named: *.exe
Look in: (browse or paste in) C:\WINDOWS\System32
Check the following: 'Use Text Constraints', 'Search non-text files' and in the 'Find What' paste: kern32
All other fields leave unchecked!
Hit the 'Find' tab...
The scan will run for few seconds and show the results. Delete everything found.
Reboot
Go Here and download lspfix while your internet still works...removing some of this malware you have might break internet access...lspfix will fix it.
http://www.cexx.org/lspfix.htm
This site has a tool to remove i-lookup infection:
http://www.pchell.com/support/click2findnow.shtml
Look for the link for i-lookup, download and run the uninstaller.
Go to add/remove programs and remove:
Shop at home agent
WhenUSave...or Save
Gsim...look for entries like "toolbar, Search utility, winDirect, eXpand Search" Remove all found.
Reboot
Have only hijack this running while offline and check the following to fix: (some of the entries may not be present)
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://i-lookup.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer,Default_Search_URL = http://0-OL1OIZ-XOLXII1-OXLI10OZL1L1-O-L-11-IIZXP-L-0O-OLL11IZ0OIL-OL.COM/92671ac527/ac00krtyx_65v/ogsearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\SYSTEM\sb.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://i-lookup.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://i-lookup.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://i-lookup.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://if.searchcentrix.com/sidecat.jsp?p=98567&appid=21&id=125125681722344
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = ,
R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = ,
F1 - win.ini: run=C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSINFO\
O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\BI.DLL (file missing)
O2 - BHO: (no name) - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\PROGRAM FILES\E2G\IEBHOS.DLL
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-DFF7-EC6BF4D5FA7D} - C:\WINDOWS\GSIM.DLL
O2 - BHO: ohb - {18B79968-1A76-4953-9EBB-B651407F8998} - C:\WINDOWS\SYSTEM\WINDEC32.DLL
O2 - BHO: surebar Helper - {D3F01312-8A3D-4D41-A4FA-FB61D295CB6B} - C:\WINDOWS\SYSTEM\SUREBAR.DLL (file missing)
O2 - BHO: (no name) - {000E7270-CC7A-0786-8E7A-DA09B51938A6} - C:\WINDOWS\SYSTEM\N3TPA1.DLL
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
O2 - BHO: Clear Search - {947E6D5A-4B9F-4CF4-91B3-562CA8D03313} - C:\PROGRAM FILES\CLEARSEARCH\IE_CLRSCH.DLL
O2 - BHO: (no name) - {2CF0B992-5EEB-4143-99C0-5297EF71F443} - C:\WINDOWS\SYSTEM\STLBDIST.DLL
O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-BEA1-786FA05C83AB} - C:\PROGRAM FILES\APROPOSCLIENT\APROPOSPLUGIN.DLL
O3 - Toolbar: I-Lookup.com Bar - {6EF3AE25-5A7D-40C2-9B44-9ED0068621C0} - C:\WINDOWS\SYSTEM\WINDEC32.DLL
O3 - Toolbar: Search Bar - {270B845C-712C-4773-BEE0-AE2D2001CD0F} - C:\WINDOWS\SYSTEM\SUREBAR.DLL (file missing)
O3 - Toolbar: Search - {2CF0B992-5EEB-4143-99C0-5297EF71F444} - C:\WINDOWS\SYSTEM\STLBDIST.DLL
O4 - HKLM\..\Run: [ClrSchLoader] \Program Files\ClearSearch\Loader.exe
O4 - HKLM\..\Run: [winmain] winmain.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [BELT] C:\WINDOWS\BELT.exe
O4 - HKLM\..\Run: [SAHAgent] C:\WINDOWS\SYSTEM\SahAgent.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [msbb] C:\WINDOWS\SYSTEM\MSBB.EXE
O4 - HKLM\..\Run: [Power Scan] C:\PROGRAM FILES\POWER SCAN\POWERSCAN.EXE
O4 - HKLM\..\Run: [CFIMP] C:\WINDOWS\CFIMP.exe
O4 - HKLM\..\Run: [{2CF0B992-5EEB-4143-99C0-5297EF71F444}] rundll32.exe C:\WINDOWS\SYSTEM\STLBDIST.DLL,DllRunMain
O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\SAVE\Save.exe
O4 - HKLM\..\Run: [RunWindowsUpdate] C:\WINDOWS\UPTODATE.EXE
O4 - HKLM\..\Run: [IEDriver] C:\WINDOWS\SYSTEM\IEDriver\IEDriver.exe
O4 - HKLM\..\Run: [3Q9QZFM3F4DTYZ] C:\WINDOWS\SYSTEM\Dqk5Y.exe
O4 - HKLM\..\Run: [AutoUpdater] c:\PROGRA~1\AUTOUP~1\AUTOUP~1.EXE
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O4 - HKCU\..\RunServices: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O10 - Broken Internet access because of LSP provider 'lsp.dll' missing
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download2.abetterinternet.com/download/cabs/FON19106/flash.cab
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
O16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} (iiittt Class) - http://toolbar2.i-lookup.com/toolbar2/windec32.cab
O16 - DPF: {DBAE7000-01EC-4162-8FEB-8A27AC937CA0} (HDPluginCtrl Class) - http://webpdp.gator.com/4/download/hdplugin_1015_bundle33v0d9.cab
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} (F1 Organizer Class) - http://www.netpaloffers.net/NetpalOffers/DMO1/GrlNt0i.cab
O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B2F49FB} - http://stat.trafficadvance.net/dialer/303828.exe
Reboot to safe mode (tap f8 while booting, choose safe mode from menu, hit enter) and delete the following if present (you will need to show hidden files and folders in folder options thru control panel)
C:\WINDOWS\SYSTEM\sb.htm <-this file
C:\PROGRAM FILES\E2G\IEBHOS.DLL <-E2G folder
C:\WINDOWS\GSIM.DLL <- this file
C:\WINDOWS\SYSTEM\WINDEC32.DLL <- this file
C:\WINDOWS\SYSTEM\GRLNT0I.DLL <-this file
C:\WINDOWS\SYSTEM\N3TPA1.DLL <-this file
C:\PROGRAM FILES\CLEARSEARCH\IE_CLRSCH.DLL <- whole clearsearch folder
C:\WINDOWS\SYSTEM\STLBDIST.DLL <-this file
C:\PROGRAM FILES\APROPOSCLIENT\APROPOSPLUGIN.DLL <-whole aproposclient folder
C:\Program Files\ISTsvc\istsvc.exe <-whole istsvc folder
C:\WINDOWS\BELT.exe <-this file
C:\WINDOWS\SYSTEM\SahAgent.exe <- this file
C:\Program Files\Common files\updater\wupdater.exe <- updater folder
C:\WINDOWS\SYSTEM\MSBB.EXE <-this file
C:\PROGRAM FILES\POWER SCAN\POWERSCAN.EXE <-powerscan folder
C:\WINDOWS\CFIMP.exe <-this file
C:\PROGRAM files\SAVE\Save.exe <-whole save folder
C:\WINDOWS\UPTODATE.EXE <- this file
C:\WINDOWS\SYSTEM\IEDriver\IEDriver.exe <- whole iedriver folder
C:\PROGRAM files\ezula\mmod.exe <-ezula folder
Do a search with windows explorer for winmain.exe and delete that too.
Reboot to normal windows and post fresh log.
Couple entries I dont know...mabye someone else does?
O2 - BHO: (no name) - {D319662B-D5BF-4538-ADF3-8D3E36362608} - C:\WINDOWS\ALL USERS\APPLICATION DATA\X0FF\X0FF.DLL
O2 - BHO: (no name) - {1B6A56C0-3E96-11D8-8740-00A0B000190A} - C:\WINDOWS\SYSTEM\WJINTRUST.DLL
Like I said above...some of these files to delete will not be present...just not 100% positive which ones will/willnot be..if we missed anything it should show up in the new hijack log.
Hopefully I didnt repeat someone before me...after spending an hour on this...not going to refresh page...I wasnt smart enough to do this in notepad first...:-\
If your internet breaks after doing all this...run the lspfix you downloaded above...tell it to remove lsp.dll (you will have to check "i know what i am doing"), click finish, Reboot.