Taken from:
http://boards.cexx.org/index.php?topic=3566
It has worked for me in the past...
First get rid o f the peper trojan, by following these instructions :
Download and run this file to fix Peper Trojan:
http://experts.spywareinfo.com/pieter/uninst.exe
double click on 'uninst.exe', let it run and terminate.
To delete all the associated files download the following tool:
http://www.mjc1.com/files/mo/drpeper.html
It will self extract to C:\
Find :
C:\drpeper\Find backup and Delete Peper files.vbs file and double click.
On the first prompt copy and paste:
Pib0EG.exe and hit ok.
You will get a confirmation and proceed:
On the second, paste:
QjlrXhe2.exe and hit ok
It will find all the files, delete them and will make backups in the same folder.
It'll open a text file (Peper.txt) with the list of all files deleted.
Next, fix the following with HijackThis :
O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-BEA1-786FA05C83AB} - C:\Program Files\AproposClient\AproposPlugin.dll
O2 - BHO: (no name) - {CD2A865B-6C0F-44F9-BAA1-7CDB31E04BC8} - C:\WINDOWS\System32\BarBHO.dll
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\system32\spoolsvv.exe -invisible
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://207.188.7.150/19bcb0269accacaee702/netzip/RdxIE601.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\Documents and Settings\Bill\Local Settings\Temp\EI40_\msxml4.cab
O16 - DPF: {BB0578ED-E672-4697-9663-EC5A0460B949} (SomaticCAB.Setup) -
http://downloads.searchcentrix.com/install/weblz.CAB
Make sure all hidden files / folders are set to show :
Here's how
Reboot after doing so and remove :
C:\Program Files\AproposClient\ <- this folder
C:\WINDOWS\system32\spoolsvv.exe <- this file