View Single Post
Old 08-22-2005, 07:29 PM   #4
DS
look at that hat
 
DS's Avatar
 
Posts: 4,520
DS has a great deal of rep (15,000+)DS has a great deal of rep (15,000+)DS has a great deal of rep (15,000+)DS has a great deal of rep (15,000+)DS has a great deal of rep (15,000+)DS has a great deal of rep (15,000+)DS has a great deal of rep (15,000+)
First thing first, download a program called GarbageClean. You will need to sign up to download it because it's in beta stage but it gets rid of pretty much all this crap that others can't. Here is the program and here is where you can sign up. Next, run Hijack This again and check all the "R" options and click fix. That should fix the browser settings. Next thing is that these processes are all part of your virus:

O4 - HKLM\..\Run: [atlzg.exe] C:\WINDOWS\atlzg.exe
O4 - HKLM\..\Run: [netue32.exe] C:\WINDOWS\netue32.exe
O4 - HKLM\..\Run: [iepx32.exe] C:\WINDOWS\system32\iepx32.exe
O4 - HKLM\..\Run: [addqh.exe] C:\WINDOWS\addqh.exe
O4 - HKLM\..\Run: [winqw.exe] C:\WINDOWS\system32\winqw.exe
O4 - HKLM\..\RunOnce: [addfu.exe] C:\WINDOWS\addfu.exe
O4 - HKLM\..\RunOnce: [d3eo.exe] C:\WINDOWS\d3eo.exe
O4 - HKLM\..\RunOnce: [winik32.exe] C:\WINDOWS\winik32.exe
O4 - HKLM\..\RunOnce: [apimc32.exe] C:\WINDOWS\apimc32.exe
O4 - HKLM\..\RunOnce: [d3bz32.exe] C:\WINDOWS\system32\d3bz32.exe
O4 - HKLM\..\RunOnce: [ntzo32.exe] C:\WINDOWS\ntzo32.exe
O4 - HKLM\..\RunOnce: [netwe32.exe] C:\WINDOWS\netwe32.exe
O4 - HKLM\..\RunOnce: [atlty32.exe] C:\WINDOWS\system32\atlty32.exe
O4 - HKLM\..\RunOnce: [ipns32.exe] C:\WINDOWS\system32\ipns32.exe
O4 - HKLM\..\RunOnce: [iegk.exe] C:\WINDOWS\system32\iegk.exe

The best thing to do is restart windows and go into safe mode (this is the best thing to do any time you have something like this because it keeps the processes that usually respawn files from starting up). Just restart and keep clicking the F8 key and that should bring up the option. I usually go into Safe Mode with Networking in case I need to get online and find instructions. Run both Microsoft Spyware and Ad-aware if that's what you have and then run that GarbageClean. Run Hijack This again and select all those O4s, if they are still there, with the random letters and numbers. Or you can use all the ones from above one by one if you need.

Go to Start > Run > regedit

Then navigate to HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run and see if any of those are in there. If they are, select and delete them if they are until that and all the "Run" folders are clear of them. Then restart and hopefully you will be ok.

Good luck. If I remember anything else I'll post it. Tell me how it goes.

Last edited by DS; 08-22-2005 at 07:41 PM.
DS is offline