This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

HJT log (wangyou)

39 min read

This thread's last reply is from December 23, 2006, 10:50 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

mattandi

Welcome back

First You need to open Outlook Express
    In the left pane, locate the deleted items folder
    Rt Click it and empty that folder
    Do the same for Outlook


Next Download CCleaner from here to clean temp files from your computer.
    Double click on the file to start the installation of the program.
    Select your language and click OK, then next.
    Read the license agreement and click I Agree.
    Click next to use the default install location. Click Install then finish to complete installation

Double click the CCleaner shortcut on the desktop to start the program.
    On the "Windows" tab, under "Internet Explorer," uncheck "Cookies" if you do not want them deleted. (If deleted, you will likely need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
    If you use either the Firefox or Mozilla browsers, the box to uncheck for "Cookies" is on the Applications tab, under Firefox/Mozilla.
    Click on the "Options" icon at the left side of the window, then click on "Advanced."
    deselect "Only delete files in Windows Temp folders older than 48 hours."
    Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program

Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
    After CCleaner has completed its process, click Exit

Next Re Run Hijackthis and place checks beside the following entries
    O2 - BHO: FltSetUp Class - {1D49D58D-5C84-4B50-8359-D9809BEB2B32} - C:\Program Files\Internet Explorer\Connection Wizard\icwuti1.dll (file missing)
    O2 - BHO: (no name) - {D424FE4E-CAF9-4fdd-BC5F-E6E6B91D53BF} - (no file)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/1706ea21e2f4347aea17/netzip/RdxIE601.cab

Close all other open windows except Hijackthis and Select "Fix checked"

Next Using Windows Explorer
    (Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)

Locate and delete the following folders
    C:\Program Files\Common Files\Softwin
    C:\Documents and Settings\Prophet's Reward
    C:\Program Files\DoDoorRSSFinder

Locate and delete the following files
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{C9C2A126-0C86-4BC5-BBBB-5F8AC13766C0}
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\nleee.exe
    C:\Program Files\Common Files\System\aekheif.dat

Close Windows Explorer->>Reboot your PC->>Rerun Hijackthis and post a fresh Hijackthis log

thanks bamajim
I have not abandoned this. Just haven't been able to get to the computer in a while.
Just reply when ready :)

thanks bamajim
This topic is now closed due to inactivity. If you wish it reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.

You can help support this site from this link :
Donations For Malware Removal

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.