Memory disappearing on its own from my C: drive....malware?????

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Lilith02, Oct 26, 2008.

  1. Lilith02

    Lilith02 Private E-2

    Hi,

    About 2 months ago it was called to my attention by a friend that I had very little memory left on my C:drive (30Mb out of 38Gb). I assumed it was because of photos and other such files and either removed them to the D: drive or to my external hard drive. I did get back 3Gb of memory and considered myself "safe".
    Recently though, and for no reason at all, I have been losing memory again. No matter what I take out, how many malware sweeps or defragmentations I go through, I only manage to go from 20Mb to about 60 and back again. I've even been down to 0Mb....
    I haven't installed any new software, other than the one from my webcam (and I think I was already having some problems by then).

    I went through the Read & Run Me procedures hoping that would be enough, unfortunately it wasn't. It did find some malware though, so I know something good came out of it :).

    I believe I have some sort of malware, because otherwise I don't understand how memory would just disappear on its own....

    I use Windows XP Service Pack 2. My computer is an Acer Aspires 9104WLMI.

    I have attached the logs for SAS, Combofix and MBAM as per the instructions in R&RM.

    If anyone can guess at what the problem might I'll be very thankful for your help.

    Lilith02
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    First just and FYI for you. It is not "memory" space it is hard disk drive space or storage space. Memory is RAM ( Random Access Memory ) which the programs on your PC use to run. Any information in RAM is lost when you turn your PC off. You are probably not losing disk space due to malware. You are probably just noticing loss of space due to System Restore points being created each time you boot your PC. You should consider reducing the amount of disk space being used for System Restore. You can work issues like this in the Software Forum or you can read things like the below:

    http://vistasupport.mvps.org/decrease_storage_space-allocated_to_system_restore.htm

    I due see some questionable items in your ComboFix log that are not related to your disk space problems, but I need the log from MGtools that was requested before I can continue.
     
  3. Lilith02

    Lilith02 Private E-2

    Hi!
    Thanks for getting back to me, and I apologize for not answering back sooner. I had no internet connection where I was staying.

    I did as you told me and reduced the amount of disk space allocated to System Restore. It went from 12% (about 4GB) to 3% (about 1GB). I gained 1,5 GB of disk space, of which I somehow lost a huge chuck the enxt day (down to about 350Mb then 250Mb). So I reduced it to 2% (about 650Mb). I thus gained over 400 Mb of disk space, which I kept until I defragmented my disk (it is now 360Mb). Still, it's stayed at 360Mb for over 24h, which is a huge advancement. I'm still a little bit worried about what can be eating so much space though, nothing I find seems to be doing it....

    I hadn't realized that the MG scan was missing and I apologize for it. I've attached the log to this message.

    Once again, thanks for everything.

    Lilith02
     

    Attached Files:

  4. Lilith02

    Lilith02 Private E-2

    Hi,

    A friend of mine found what was eating up my c: drive and fixed it. the installer folder was keeping a copy of ALL the incomplete windows updates...anyway, I managed to get back 27GB of space...!!!!

    Still, if there's something off with the scan-logs I'd like to deal with it.

    Thanks,
    Lilith 02
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are in pretty good shape. I just have one thing for you to do and then final steps.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    And delete the below file if it exists:
    C:\Windows\Knight.exe

    Also look for this knight.exe file on any other hard disk partitions or removal drives and delete it if found.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds