This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hard Disk Space 1% [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is running slow, and at first glance I thought it was a hard drive capacity problem. I did the disk cleanup, removed some programs, and ran CC Cleaner. However, the disk capacity did not change. MS-Essentials recently caught the Rogue: Win32 virus on the computer. I was wondering if my hard drive capacity is being eaten up by a virus or some sort of malware. I run a P4 clone, 40MB RAM and have a 20GB hard disk. Any help would be appreciated. Thanks.
Hi aramage,

A 20GB hard drive is very small in this day and age. I doubt that any malware is eating up your hard drive space, but I can surely take a look for you.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
As requested below is the DDS file. I have attached the requested files.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 18:53:37 on 2012-03-02
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.383.78 [GMT -7:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Executive Software\DiskeeperLite\DkService.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/?rlz=1V1IPYX
uURLSearchHooks: Ad-Aware Security Toolbar: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - c:\program files\adawaretb\adawareDx.dll
mURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Ad-Aware Security Toolbar: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - c:\program files\adawaretb\adawareDx.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
BHO: {BDF3E430-B101-42AD-A544-FADC6B084872} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Ad-Aware Security Toolbar: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - c:\program files\adawaretb\adawareDx.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Ad-Aware Browsing Protection] "c:\documents and settings\all users\application data\ad-aware browsing protection\adawarebp.exe"
mRun: [DameWare MRC Agent] c:\windows\system32\DWRCST.exe
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…t;ver=10.0.1411
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [adaware] reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f
dRunOnce: [adaware_XP] reg.exe delete "HKCU\Software\adaware" /f
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1223831647158
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{70DF02A9-D788-423E-9DF1-792484AC5488} : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{9C1B9261-08CD-416D-A200-031665D155A5} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{FF325C86-56C3-4523-9F89-416144926F6E} : DhcpNameServer = [removed] [removed]
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-6-6 64512]
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;c:\windows\system32\drivers\dwvkbd.sys [2007-2-15 26624]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl9ec34a75;MpKsl9ec34a75;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d5f454c3-c1f9-4a12-a993-3d2f7370f823}\MpKsl9ec34a75.sys [2012-3-2 29904]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [2006-10-15 547744]
R3 DwMirror;DwMirror;c:\windows\system32\drivers\DamewareMini.sys [2007-2-7 3712]
S0 igxsf;igxsf; [x]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\admini~1\locals~1\temp\superantispyware\sasdifsv.sys –> c:\docume~1\admini~1\locals~1\temp\superantispyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\admini~1\locals~1\temp\superantispyware\saskutil.sys –> c:\docume~1\admini~1\locals~1\temp\superantispyware\SASKUTIL.SYS [?]
S2 gupdate1c9a06f5f609930;Google Update Service (gupdate1c9a06f5f609930);c:\program files\google\update\GoogleUpdate.exe [2009-3-8 133104]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-3-8 133104]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-12-23 2152152]
S3 libusb0;libusb-win32 - Kernel Driver, Version 1.2.4.0;c:\windows\system32\drivers\libusb0.sys [2011-12-19 21504]
S3 SASENUM;SASENUM;\??\c:\docume~1\admini~1\locals~1\temp\superantispyware\sasenum.sys –> c:\docume~1\admini~1\locals~1\temp\superantispyware\SASENUM.SYS [?]
.
=============== Created Last 30 ================
.
2012-03-03 01:51:53 56200 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d5f454c3-c1f9-4a12-a993-3d2f7370f823}\offreg.dll
2012-03-03 01:51:53 29904 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d5f454c3-c1f9-4a12-a993-3d2f7370f823}\MpKsl9ec34a75.sys
2012-03-03 00:14:25 6552120 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d5f454c3-c1f9-4a12-a993-3d2f7370f823}\mpengine.dll
2012-02-25 23:58:46 ——– d—–w- c:\documents and settings\all users\application data\529C536C000077010003E181D151FC4E
2012-02-25 16:52:56 ——– d—–w- c:\documents and settings\kids\local settings\application data\adaware
2012-02-25 16:52:50 ——– d—–w- c:\documents and settings\all users\application data\Ad-Aware Browsing Protection
2012-02-25 16:52:43 ——– d—–w- c:\program files\Toolbar Cleaner
2012-02-25 16:52:10 ——– d—–w- c:\documents and settings\kids\application data\adawaretb
2012-02-25 16:51:43 ——– d—–w- c:\program files\adawaretb
2012-02-17 04:43:43 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll
2012-02-17 04:43:43 3072 ——w- c:\windows\system32\iacenc.dll
2012-02-16 03:45:59 ——– d—–w- c:\documents and settings\kids\application data\PriceGong
2012-02-16 03:45:42 ——– d—–w- c:\program files\Conduit
2012-02-16 03:45:33 ——– d—–w- c:\documents and settings\kids\local settings\application data\Conduit
.
==================== Find3M ====================
.
2012-02-25 17:18:15 16432 —-a-w- c:\windows\system32\lsdelete.exe
2012-01-31 12:44:05 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-01-12 16:53:24 1859968 —-a-w- c:\windows\system32\win32k.sys
2011-12-23 14:12:12 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-12-20 02:46:50 37376 —-a-w- c:\windows\system32\libusb0.dll
2011-12-20 02:46:50 21504 —-a-w- c:\windows\system32\drivers\libusb0.sys
2011-12-17 19:46:36 916992 —-a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46:36 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46:36 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22:58 385024 —-a-w- c:\windows\system32\html.iec
2011-12-10 22:24:06 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
.
============= FINISH: 18:54:43.98 ===============
Hi aramage, You're definitely running out of hard drive space as well as memory. I'd highly recommend upgrading your memory and hard drive if purchasing a new PC is not an option (your PC is growing a bit long in the tooth :)). Nothing in your logs indicate that malware is eating up hard drive space. We could proceed with a few more scans to see if there is any malware on the system to remove, but I suggest you uninstall a few programs to free up disk space first. Ad-Aware is not really necessary since you already have Microsoft Security Essentials. You can also remove Diskeeper Lite and just use the built-in Windows defragmenter. The lack of free hard drive space is also preventing Windows and Security Essentials updates from being installed, which is a huge security risk. Please let me know if removing the above programs frees up some hard drive space.
I have been deleting programs, but with little result in increased disk space. I have had some issues trying to delete programs because the uninstall programs cannot operate with so little disk space. I will continue deleting and transferring data, and let you know the outcome. It may take a few days. Thanks
Hi aramage, No problem. Let me know how things work out for you. Worst come to worst, you may need to get a bigger hard drive :)
I have been deleting data and programs but haven't had much success. In fact, I have been losing ground, and don't understand why. For example, I deleted about a 1GB of information, but lost 20MB in disk capacity according to Windows. It seems that as fast as I make room, something occupies that space. This is why I thought that it was a virus or something. Could it be the Windows swap file? Thanks again.
Hello aramage,

I would like for you to download and install WinDirStat. Next, run WinDirStat. When prompted, make sure All Local Drives is selected, then press OK and let it run. Please post a screenshot of the results when it has finished running.
Hi aramage,

Looks like your Documents and Settings folder is taking up all the space. You could expand the folder by clicking the plus sign. That would give you more detail as to what is consuming all your disk space. It looks like MP3's might be consuming all the disk space.

I also noticed that you have tried running ComboFix. Would you mind posting the log? It can be found here: C:\ComboFix.txt.
ComboFix 11-12-10.01 - Kids 12/11/2011 11:27:29.7.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.383.100 [GMT -7:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\CSC\d6
.
.
((((((((((((((((((((((((( Files Created from 2011-11-11 to 2011-12-11 )))))))))))))))))))))))))))))))
.
.
2011-12-11 09:13 . 2011-12-11 09:13 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F3B1786D-3B17-4256-A7DF-E25A83FA33C2}\MpKsl42b207c3.sys
2011-12-11 09:11 . 2011-12-11 09:11 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F3B1786D-3B17-4256-A7DF-E25A83FA33C2}\offreg.dll
2011-12-11 09:11 . 2011-11-21 10:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F3B1786D-3B17-4256-A7DF-E25A83FA33C2}\mpengine.dll
2011-11-21 01:36 . 2001-08-18 05:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2011-11-21 01:35 . 2008-04-14 12:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2011-11-21 01:35 . 2008-04-14 07:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2011-11-21 01:35 . 2008-04-14 07:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2011-11-19 00:57 . 2011-11-19 00:57 ——– d—–w- c:\program files\KingsIsle Entertainment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2011-10-16 17:48 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-10 14:22 . 2007-01-29 23:46 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 17:41 . 2007-10-09 19:03 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 17:41 . 2004-08-04 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 17:41 . 2004-08-04 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-09 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 61952]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 14854144]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...10.0.1411" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Kids^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Kids\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-07-16 13:41 141608 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5900:TCP"= 5900:TCP:vnc
"6129:TCP"= 6129:TCP:DameWare Mini Remote Control Service
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/6/2011 6:55 PM 64512]
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;c:\windows\system32\drivers\dwvkbd.sys [2/15/2007 2:00 AM 26624]
R1 MpKsl42b207c3;MpKsl42b207c3;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F3B1786D-3B17-4256-A7DF-E25A83FA33C2}\MpKsl42b207c3.sys [12/11/2011 2:13 AM 29904]
R1 MpKsl5cbd9de2;MpKsl5cbd9de2;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BA727060-F3D6-4408-B308-80B4601F233B}\MpKsl5cbd9de2.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BA727060-F3D6-4408-B308-80B4601F233B}\MpKsl5cbd9de2.sys [?]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [10/15/2006 11:58 PM 547744]
R3 DwMirror;DwMirror;c:\windows\system32\drivers\DamewareMini.sys [2/7/2007 2:00 AM 3712]
S0 igxsf;igxsf; [x]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\SuperAntiSpyware\SASDIFSV.SYS –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\SuperAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\SuperAntiSpyware\SASKUTIL.SYS –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\SuperAntiSpyware\SASKUTIL.SYS [?]
S2 gupdate1c9a06f5f609930;Google Update Service (gupdate1c9a06f5f609930);c:\program files\Google\Update\GoogleUpdate.exe [3/8/2009 9:27 PM 133104]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [3/8/2009 9:27 PM 133104]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [5/25/2011 1:00 AM 2152152]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [5/25/2011 1:00 AM 15232]
S3 SASENUM;SASENUM;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\SuperAntiSpyware\SASENUM.SYS –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\SuperAntiSpyware\SASENUM.SYS [?]
S4 MpKslfb0aaf25;MpKslfb0aaf25;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{68811444-8D2A-4D78-8082-3870B54A890B}\MpKslfb0aaf25.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{68811444-8D2A-4D78-8082-3870B54A890B}\MpKslfb0aaf25.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL052BC664
*NewlyCreated* - MPKSL07E03F84
*NewlyCreated* - MPKSL0C00A0F0
*NewlyCreated* - MPKSL159E3B35
*NewlyCreated* - MPKSL42B207C3
*NewlyCreated* - MPKSL60600C51
*NewlyCreated* - MPKSL6FB4A4AB
*NewlyCreated* - MPKSL7412F867
*NewlyCreated* - MPKSL8D3B9F0A
*NewlyCreated* - MPKSL8D6A0CFF
*NewlyCreated* - MPKSL9E077354
*NewlyCreated* - MPKSLD06F914B
*NewlyCreated* - MPKSLE6EDF879
*NewlyCreated* - MPKSLF9E59367
*NewlyCreated* - MPKSLFB0AAF25
*Deregistered* - MpKsl052bc664
*Deregistered* - MpKsl07e03f84
*Deregistered* - MpKsl0c00a0f0
*Deregistered* - MpKsl159e3b35
*Deregistered* - MpKsl60600c51
*Deregistered* - MpKsl6fb4a4ab
*Deregistered* - MpKsl7412f867
*Deregistered* - MpKsl8d3b9f0a
*Deregistered* - MpKsl8d6a0cff
*Deregistered* - MpKsl9e077354
*Deregistered* - MpKsld06f914b
*Deregistered* - MpKsle6edf879
*Deregistered* - MpKslf9e59367
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-09 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-05-25 07:40]
.
2011-12-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
2011-12-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-09 22:41]
.
2011-12-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-09 04:27]
.
2011-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-09 04:27]
.
2011-12-11 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 21:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.0.1
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-DameWare MRC Agent - c:\windows\system32\DWRCST.exe
Notify-68d0fca0579 - (no file)
MSConfigStartUp-CTFMON - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-11 11:48
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(720)
c:\windows\system32\igfxsrvc.dll
c:\windows\system32\hccutils.DLL
.
- - - - - - - > 'explorer.exe'(4884)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-11 11:53:36
ComboFix-quarantined-files.txt 2011-12-11 18:53
.
Pre-Run: 3,264,917,504 bytes free
Post-Run: 3,919,728,640 bytes free
.
- - End Of File - - 6A45EAF794FE4A3A1F969636AE2402FB
Hi aramage,

Looks like ComboFix didn't take out much. I think it would be safe to say that your disk space issues are not being caused by malware, but rather too many mp3 files.

We can remove ComboFix now.

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI