Please Help me~~~~Un-identified Trojan in my computer, eating my Hard Disk space

Discussion in 'malware problems & news' started by ramu50, Mar 6, 2008.

Thread Status:
Not open for further replies.
  1. ramu50

    ramu50 Registered Member

    Joined:
    Mar 6, 2008
    Posts:
    1
    So my computer Hard Drive have been eaten away by virus from 66% down to 36% currently without installing anything.

    My hard Drive is IDE (not sure which UATA type is it)
    Totaly hard drive size: 74.52GB
    C 38.09GB (before virus I had 66% empty space, now I only have 36%)
    D 18.55GB
    E 17.88GB

    I check Virtual Memory size, which was normal 768MB~1.536GB
    Hard Drive Indexing was normal
    and System Backup was closed.

    I also went to Control Panel --> Adminastrative Tools --> Service
    running services.msc I notice the process "npkcsvc"
    C:\WINDOWS\system32\npkcsvc.exe after searching online info, it says that this is a [Trojan-Downloader.Win32.Agent] from INCA entertainment.
    ---Note: INCA entertainment is a anti-hacking company for Maiet, Gunz gaming, so I am not sure is this a mistake, or it is an actually virus.

    (note: I am not using english Window OS, I am using Window XP Professional 5.1.2600
    [Service Pack 2])

    So I use AVG AntiSpyware, AVG AntiVirus, Avira AntiVir, Spybot Search and Destroy
    --only AVG AntiVirus found 2 trojan
    (note both of these are """keygen""", and they have no affect on previous Window XP system)
    Trojan horse VB.CSK
    Trojan horse PSW.Generic5.AFkD


    The virus created 4 folders in the directory: (C:\Documents and Settings)
    LocalService, NetworkService, Adminastrator, RECYCLER [note that I didn't create ANY users at all]
    ---I was unable to delete 3 of these folder (LocalService, NetworkService, RECYCLER) even in safe mode, because the process were running.
    ---I also attemp to end the process by force by using "Process Explorer v11.11" provided by Microsoft, but apparently they weren't shown in the process section

    this was the "Process Explorer v11.11"
    http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx


    Also, how do you backup Registry?


    Below is a report from System Repair Engineer 2.5.16.900
    from this site: http://www.kztechs.com/eng/download.html
     

    Attached Files:

    Last edited: Mar 6, 2008
  2. thanatos_theos

    thanatos_theos Registered Member

    Joined:
    Apr 28, 2007
    Posts:
    582
    Maybe something's wrong with your hard drive. A member had the same problem and the culprit was his failing hard drive. I forgot who he is and I can't find his thread.

    Try cleaning your temp files, prefetch, etc with this. Also please defrag. Problem fixed?

    I doubt this is the work of a trojan (killdisk wipes the whole drive). You probably have a nasty worm. To be sure you're clean post a hijackthis log here.

    EDIT: Your problem is quite similar to DVD+R's. Please check out his thread.

    thanatos
     
    Last edited: Mar 8, 2008
  3. Niels

    Niels Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    466
    Location:
    Belgium
    Check also how many disk space is currently reserved for system restore. Go to start,right click on my computer choose properties,press on the system restore tab,click on settings,the chance is high that the slider is set to the right side. So that can explain why so much space has been used without installing software. Put the slider to the left and press on ok so you will reduce the space used.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.