Kavu Posted October 16, 2006 Share Posted October 16, 2006 ok well i recently got this virus that nod32 picked up and it poped up a few times then just went away i restarted my computer and it says system memory has changed i noticed my ram has lowered.. to 640? i restart again i have 768.. can a virus affect my ram and does anybody know anything i should do to see if im still infected Link to comment Share on other sites More sharing options...
nsane Posted October 16, 2006 Share Posted October 16, 2006 it's possible...but try running HiJackThis and posting the log here, will make helping you 10x easier :) Link to comment Share on other sites More sharing options...
Kavu Posted October 16, 2006 Author Share Posted October 16, 2006 Logfile of HijackThis v1.99.1Scan saved at 4:29:18 AM, on 10/16/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\System32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\AlienGUIse\wbload.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Eset\nod32krn.exeC:\Program Files\Eset\nod32kui.exeC:\Program Files\Common Files\{BC7029A5-0AE9-1033-0826-040921040001}\Update.exeC:\Program Files\ATI Technologies\ATI.ACE\CLI.EXEC:\Program Files\ATI Technologies\ATI.ACE\cli.exeC:\Program Files\ATI Technologies\ATI.ACE\cli.exeC:\Program Files\Opera\Opera.exeC:\DOCUME~1\Kavu\LOCALS~1\Temp\Rar$EX00.469\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3C7029A5-0AE9-1033-0826-040921040001}\MyToolBar.dllO4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICEO4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1160576975203O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLLO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLLO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exeO23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exeO23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing) Link to comment Share on other sites More sharing options...
nsane Posted October 16, 2006 Share Posted October 16, 2006 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3C7029A5-0AE9-1033-0826-040921040001}\MyToolBar.dllAVG antispy should remove it...http://www.nsaneproductions.com/?request=3352734 Link to comment Share on other sites More sharing options...
Kavu Posted October 16, 2006 Author Share Posted October 16, 2006 well its fond all this so far :) btw your link is broken for the avg anti spyware Link to comment Share on other sites More sharing options...
Kavu Posted October 16, 2006 Author Share Posted October 16, 2006 oh.. just relized what the trojan.mygot is lol not a threat or anything to worry about heh Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.