Hard disk full without reason

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by freak_out, Apr 28, 2014.

  1. freak_out

    freak_out Private E-2

    Hi everybody
    few days ago something very strange happened on my laptop.
    While I was viewing some videos on youtube with Firefox, suddenly I had the windows message telling me that my HD was full and I that I should start the cleaning and file removal tool. I did not run the tool and when I opened the explorer to check for the space on C, instead of 60% of free space that I usually have on the HD, it was effectively almost full.
    The problem then disappeared as soon as I closed Firefox and Chrome (that was opened at the same time but idle) and my hard disk went back on the normal state, giving me again the 60% of free space.
    Worried about this weird behavior, I scrupulously followed the instruction found on your great Malware Removal/Cleaning Procedure.
    All the cleaning tools run without problem and now I have a bunch of logs that I would like to submit for further inquiry, hoping that someone can help to understand them better.
    I have a windows vista SP2 on a sony Vaio laptop.
    Thank you very much for your help.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Logs did not attach. :(
     
  3. freak_out

    freak_out Private E-2

    Hi, thanks for your answer.
    You'll find attached the requested logs.
    I would like also to have an aswer to the fact that, after having run the malware removal tools, I have now on my desktop 2 files named destop.ini:
    the 1st one on my user desktop with the following contents:


    Code:
    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
    IconResource=%SystemRoot%\system32\imageres.dll,-183
    [LocalizedFileNames]
    Windows Media Player.lnk=@%SystemRoot%\system32\unregmp2.exe,-4
    services.lnk=@%systemroot%\system32\filemgmt.dll,-2204
    Windows Explorer.lnk=@%SystemRoot%\system32\shell32.dll,-22067
    and the other one on the Public\Desktop with the following contents:

    Code:
    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799
    [LocalizedFileNames]
    Microsoft Office - 60 Day Trial.lnk=@C:\PROGRA~1\MICROS~4\mui\oaa.dll,-103
    
    There is also a third one, but empty, on my users folder under
    \AppData\Roaming\Microsoft\Windows\Network Shortcuts

    I have also on my desktop a folder named "RK_Quarantine" with 2 files on it: PhysicalDrive0_User.dat and RogueKiller.ini

    Is all this normal, can I delete them or just ignore them ?

    Thank you for your answer
     
    Last edited by a moderator: May 2, 2014
  4. freak_out

    freak_out Private E-2

    Actually the three desktop.ini files came out when I set the hidden file visualization to off.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Seems you have plenty free...

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\Users\Luigi\AppData\Local\Conduit
    
    :reg
    [-HKLM\SOFTWARE\Conduit]
    [-HKU\S-1-5-21-1284035600-301333250-2792822217-1000\Software\Conduit]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Give Ccleaner a run (not the reg scanner) just the cleaner itself to be rid of a chunk of temp files.


    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. freak_out

    freak_out Private E-2

    Hi, yes my HD space came back to the normal free space (around 60%) as soon as I closed Firefox and Chrome, which I was using at the time the HD became full without reason, I mean that I was not doing anything special whe it became full, I was just watching some videos on youtube when that happened.
    This is quoted on my first message, but maybe I did not explain the situation very well ( fault of my english, sorry).

    I came here for help because I thought the cause of that was a malware or a virus.
    Did you find anything on my logs? Virus or malware?

    I will follow your instructions you gave me in your last reply.
    Thanks
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No. Just minor junk... :)
     
  8. freak_out

    freak_out Private E-2

    Good, this is a relief....

    I run the last tools as you suggested and this is the result:

    After running OTM, I reboot as requested. Because I had forgotten to print out your instructions, I opened Google Chrome to read the next instruction you gave me and when I closed Chrome to lunch CCClenear I received a BSOD.

    So I restarted my laptop and lunched CCleaner.
    I also lunched JRT who gave me this message in the first run:

    I rebooted as requested and JRT finished to complete its job without problem.

    GetLogs.bat run without problem as well.

    Now I have a question for you:

    I noticed that the logs inside the MGlogs.zip file, specially the "newFiles.txt" contains a lot of sensitive data about my system and I am wonder if it is reasonable, from a point of view of security and privacy, to send all these information here, where everybody can read them.

    thanks again for you help.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Would you like me to remove the MGlogs.zip's?
     
  10. freak_out

    freak_out Private E-2

    yes, I would prefer, thanks
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  12. freak_out

    freak_out Private E-2

    Thank you very much for your help,
    I will follow the instructions on "How to Protect yourself from malware!"
    to avoid problems again.
    Can you please also remove the other logs I sent in the previous post as they contain sensitive information as well.
    thanks, cheers
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm sorry, I would. But I don't see where? :confused
     
  14. freak_out

    freak_out Private E-2

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes but which log specifically? None of those logs show anything sensitive. :confused Neither does the contents of the desktop.ini
     
  16. freak_out

    freak_out Private E-2

    All the logs there contain info about my OS, User name, access rights etc..
    Maybe I am paranoid, but I do not think they should not be on public domain, do you?

    thanks
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'll just remove them as you wish... :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds