Virus
-
Re: Virus
AhnLab-V3 2008.5.22.1 2008.05.23 -
AntiVir 7.8.0.19 2008.05.25 -
Authentium 5.1.0.4 2008.05.25 -
Avast 4.8.1195.0 2008.05.25 -
AVG 7.5.0.516 2008.05.25 -
BitDefender 7.2 2008.05.25 -
CAT-QuickHeal 9.50 2008.05.24 -
ClamAV 0.92.1 2008.05.25 -
DrWeb 4.44.0.09170 2008.05.25 -
eSafe 7.0.15.0 2008.05.25 -
eTrust-Vet 31.4.5817 2008.05.23 -
Ewido 4.0 2008.05.25 -
F-Prot 4.4.4.56 2008.05.23 -
F-Secure 6.70.13260.0 2008.05.25 -
Fortinet 3.14.0.0 2008.05.25 -
GData 2.0.7306.1023 2008.05.23 -
Ikarus T3.1.1.26.0 2008.05.25 -
Kaspersky 7.0.0.125 2008.05.25 -
McAfee 5302 2008.05.23 -
Microsoft None 2008.05.25 -
NOD32v2 3128 2008.05.23 -
Norman 5.80.02 2008.05.23 -
Panda 9.0.0.4 2008.05.25 -
Prevx1 V2 2008.05.25 -
Rising 20.45.42.00 2008.05.23 -
Sophos 4.29.0 2008.05.25 -
Sunbelt 3.0.1123.1 2008.05.17 -
Symantec 10 2008.05.25 -
TheHacker 6.2.92.318 2008.05.23 -
VBA32 3.12.6.6 2008.05.25 -
VirusBuster 4.3.26:9 2008.05.25 -
Webwasher-Gateway 6.6.2 2008.05.25 -
Additional information
File size: 21 bytes
MD5...: dd86aac8b0b03874bc769e29dcfb7abe
SHA1..: ab0dff4e4baf22ba7f0148793a04711d4f2f5577
SHA256: 9e280551cada3529c2b366d0d1f6706b43b3b554fe13802739 9087cf14e62593
SHA512: 41d94d7bbfdf72d688ea00c69ec89fea03d19a17d3bccabfc8 fb0769a6cfa82a
f8d6ccf373f7f0d236eeefe39f61f444243fba0a814cf14073 288d2b3d997c5d
PEiD..: -
PEInfo: -
-
There is not any malware showing anywhere, try this scanner to see if it can find something on your PC:
* Click here to use the F-Secure Online Scanner- Then click the Start Scanning button below.
- You should get a notification (bar on top) to install the activeX. Click on it and select to install the ActiveX.
- Once the ActiveX is installed, you should accept the License terms by clicking OK below to start the scan.
- In case you are having problems with installing the ActiveX/starting the scan, please read here.
- Click the Full System Scan button.
- It will start to download scanner components and databases. This can take a while.
- The main scan will start.
- Once the scan finished scanning, click the Automatic cleaning (recommended) button
- It could be possible that your firewall gives an alert - allow it, because that's a connection you establish to submit infected files to F-Secure.
- The cleaning can take a while, so please be patient.
- Then click the Show report button and copy and paste what's present under results in your next reply.
-
Scanning Report
Wednesday, May 28, 2008 02:27:54 - 10:13:15
Computer name: WINDOWS-ELYQ8TS
Scanning type: Scan system for malware, rootkits
Target: C:\ F:\
Result: 1 malware found
Tracking Cookie (spyware)
* System
Statistics
Scanned:
* Files: 26336
* System: 3647
* Not scanned: 18
Actions:
* Disinfected: 0
* Renamed: 0
* Deleted: 0
* None: 1
* Submitted: 0
Files not scanned:
* C:\PAGEFILE.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\COMPONENTS
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\WINDOWS\SYSTEM32\CONFIG\SAM
* C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
* C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
* C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
* C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\COMPONENTS
* C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\DEFAULT
* C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SAM
* C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SECURITY
* C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SOFTWARE
* C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SYSTEM
* C:\WINDOWS\SYSTEM32\CATROOT2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\CATDB
* C:\WINDOWS\SYSTEM32\CATROOT2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATDB
* C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{5A8586 50-BB67-46DC-A8B5-A22A2F37F9E0}.BIN
* C:\USERS\ALL USERS\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\698D007164B 21F3962AB79900D1FE2E0_A57AC044-3EB8-41BF-A6C1-72A11288D499
* C:\PROGRAMDATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\69 8D007164B21F3962AB79900D1FE2E0_A57AC044-3EB8-41BF-A6C1-72A11288D499
Options
Scanning engines:
* F-Secure USS: 2.30.0
* F-Secure Hydra: 2.8.8110, 2008-05-28
* F-Secure Pegasus: 1.20.0, 2008-04-14
* F-Secure AVP: 7.0.171, 2008-05-28
Scanning options:
* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
* Use Advanced heuristics
My HD space is still very low and whenever i try to install a program it will go down to 0 MB, something has to be up, I know at the very least I should have a few GB of space however it's only showing less than 100 MB
-

There is not any malware showing anywhere.
One last scan and if this comes up empty you need to look else where for the problems you are having:
Do an online scan (scan only tool) with Kaspersky WebScanner
[Internet Explorer required]
Click on Kaspersky Online Scanner
You will be prompted to install an ActiveX component from Kaspersky, Click Yes.- The program will launch and then begin downloading the latest definition files:
- Once the files have been downloaded click on NEXT
- Now click on Scan Settings
- In the scan settings make sure that the following are selected:
- Scan using the following Anti-Virus database:
- Extended (if available otherwise Standard) - Scan Options:
- Scan Archives
- Scan Mail Bases
- Click OK
- Now under select a target to scan:
- This program will start and scan your system.
- The scan will take a while so be patient and let it run.
- Once the scan is complete it will display if your system has been infected.
- Now click on the Save as Text button:
- Save the file to your desktop.
Post the results of the scan back here please and a new hijackthis log.