Computer fills memory by it's self!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by JZN, Nov 20, 2005.

  1. JZN

    JZN Private E-2

    Hi

    I have read and executed the guide to nr 7. Want to have some help with the next step.

    I have still the same problem with the computer by it self filling up my harddrive when it's on.


    Attache my log file from hijackthis...
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was you HJT log obtain from normal boot mode? It looks to be from safe mode to me.
    We need logs from normal boot mode. Please repost.
     
  3. JZN

    JZN Private E-2

    Here is the normal mode log file!!!
     

    Attached Files:

  4. JZN

    JZN Private E-2

    I also made the trojanscan as it says in the guide and it found 3 malewares and I don't know where or how to delete them!!!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you have three Internet Explorer sessions running when you obtained you HJT log:

    C:\Program\Internet Explorer\iexplore.exe
    C:\Program\Internet Explorer\IEXPLORE.EXE
    C:\Program\Internet Explorer\iexplore.exe

    The sticky requests that no browsers be opened when using HijackThis.

    Are the below two setting something you need to have:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=proxy1.telia.com:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = login1.telia.com;<local>

    Can you post the log of what Trojanscan found?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O9 - Extra button: MultiPoker - {641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - C:\Program\MultiPoker\MultiPoker.exe
    O9 - Extra 'Tools' menuitem: MultiPoker - {641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - C:\Program\MultiPoker\MultiPoker.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\j44o0eh3eh4.dll (file missing)

    After clicking Fix, exit HJT.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. JZN

    JZN Private E-2

    Now I have done the hijack again as you sad. Will attach the file

    Also did a new spy sweeper scan an it always finds new problems attach that file to...

    Will do al of the scans buring the night and see what happens...

    Have still the same problem thou!!!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're last log in from SpySweeper just shows some minor cookies which you will always get anytime you surf. This is not a problem.

    Are you saying your harddisk is loosing space rapdily?
    How much is it changing and how fast?
    Where are the files being added? Any filenames and folders you can provide?

    What is the below program supposed to be for?

    O23 - Service: BackOnTrack Callback Service (BOTCbs) - SystemOK AB - C:\Program\SystemOK\BackOnTrack\BOTCbs.exe
     
  9. JZN

    JZN Private E-2

    The hard drive fills it self up really fast!!! I have been durning out dvd:s with stuff to make place but it takes 15 min I guess til the computer is warning that there is to little memory left. so 2-3 gb fills up in 15 til 30 min...

    The biggest problem is that I can't find out where the memory space is... All that I knows is that it is on my harddrive...

    the back on track file is fine know what it is and it not any problem with that one.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Memory and harddisk space are two different things. Don't mix them together.
    Are you have memory problems or harddisk space problems? Or are you having both?

    Does this only occur while burning DVDs?
    What did you mean by "stuff to make place"?
    What takes 15 minutes? Are you saying that when you burn DVDs 15 minutes later you have no harddisk space?

    What size is your total harddisk and how much free space is on it?
     
  11. JZN

    JZN Private E-2

    Sorry for my bad spelling/english!!!!

    I have harddisk problems!!! My total disk is on 80gb and about 75gb to use it says in the proberties tab.

    right now I have 2,5Mb of free space!!!

    There is no problem when burning dvd:s its a problem when the computer is on. It doesn't matter if the internet connection is on or not.

    "stuff to make place"? with this I mean that I have been forced to burn things on dvds because I don't have any free diskspace...

    With 15 min I mean that after I have deleted the files that I just burned on the dvd it takes 15 min for the disk to be full again...

    Have found 2 hidden files in C:/

    pagefile.sys that is 1.50gb big
    hiberfile.sys that is 0.99gb big

    Do you know anything about them???
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I understand 80gb total size. But what is the 75gb number. Is that how much space has been used already. If so it does not make sense that only 2.5Mb of free space would exist. It should be about 5 gb.

    They are valid files for your OS.

    Reboot your system and immediately (don't do anything else) get the below info in bytes:
    Used space:
    Free space:
    Capacity:

    Do this by right clicking on the drive and selecting properties.
    Then click the Disk Cleanup button and cleanup all the temp space.
    Now what do you get for the above numbers.

    Now come back here and report.
     
  13. JZN

    JZN Private E-2

    Hi

    when I started the computer now

    the used spece was: 80 021 950 464
    the free space was: 1 765 376
    the kapacity was: 80 023 715 840

    After the disk cleaning:

    used: 80 013 631 488
    free: 10 084 352
    kap: 80 023 715 840
     
  14. JZN

    JZN Private E-2

    Check one thing now.

    After opening a new internet page this was the difference in free space:

    before: 9 744 384
    after: 9 736 192

    Is that normal???
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the descrease in space is normal! But your problem is that you have your drive filled to the max. You need to get rid of whatever you are storing on it that is taking up 80Gb. Having only about 10Mb of free space left at boot up just does not work. The space will be gone in no time.
     
  16. JZN

    JZN Private E-2

    Yeah I know that I have to get rid of a lot of thing that takes up space but there's the original problem...

    I have only between 35gb of files that I can find and knows about. I have about 25 to 30 gb of movies, tv shows and music and than there are the windows files and program files!!!

    So I have about 40 gb of unknown used space that I have to find!!!

    And everything is stored somewhere on C:/

    Attach a print screen of my hard drive... and other doc with the total of what all the files in C:/ uses!!!

    So where is the other 40 gb???
     

    Attached Files:

    • Dok1.doc
      File size:
      79 KB
      Views:
      8
    • c.doc
      File size:
      66.5 KB
      Views:
      5
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter cmd and click OK. This will open a command prompt window.
    Enter the below command at the command prompt and wait for it to complete:

    chkdsk

    When it finishes, the last 15 or so lines should have info like below. Report back your results. You can copy it from the command prompt by right click on the top title bar of the Window and using Mark to select the lines using your mouse. The right click on the top again to select Copy. Then you can use Paste in notepad or a message here to save to results.
    Code:
    Run CHKDSK with the /F (fix) option to correct these.
     117154012 KB total disk space.
      54121520 KB in 79325 files.
    	 31444 KB in 8115 indexes.
    		 0 KB in bad sectors.
    	231252 KB in use by the system.
    	 65536 KB occupied by the log file.
      62769796 KB available on disk.
    	  4096 bytes in each allocation unit.
      29288503 total allocation units on disk.
      15692449 allocation units available on disk.
     
  18. JZN

    JZN Private E-2

    Here is what I got from the disk check!!! Hope you can figure it out even when it's in Swedish... Let me know if there is something wrong...

    Kör CHKDSK med argumentet /F för att åtgärda problemen.

    78148160 kB diskutrymme totalt.
    76740488 kB i 74214 filer.
    27876 kB i 6464 index.
    0 kB i skadade sektorer.
    149992 kB används av operativsystemet.
    65536 kB hårddisksutrymme används av loggfilen.
    1229804 kB ledigt utrymme.

    4096 byte i varje allokeringsenhet.
    19537040 allokeringsenheter finns totalt på disken.
    307451 allokeringsenheter är tillgängliga på disken.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As suspected, you only have about 1.2 Gb (1229804 kB ) of free space left on your disk. You need to cleanup. The above gives the true space available on your system. Whatever you were looking at before was not giving you all of the disk actual useage.
     
  20. JZN

    JZN Private E-2

    Yes I know that but the thing is that it doesn't change the fact that I have 40gb somewhere hidden that I can't delete!!!

    And that is what I have to find because the numbers I presented berfore is the actual used space that I can find!!!
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you don't! It is used by your files according to chkdsk. The size of a file is not necessarily what it takes up in real space on a harddisk.

    If you bring up Windows explorer and select your C drive root folder and then in the right window pane select all the folders and files using your mouse, then right click and select Properties. This will take awhile but it will show you that actual space (called Size on disk )

    Also you must make sure viewing of hidden files and folders is enable per the READ ME to get a proper reading otherwise some item will remain hidden from you.
     
  22. JZN

    JZN Private E-2


    Here is the funny this and as I sad before... the disk isn't full when I do this disk search...

    31,9 GB (34*320*687*995 byte)

    This is how much there is on the disk and yes I have already enable viewing of hidden files...
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you mean by disk search?

    Click Start, Run, and enter msinfo32 and click OK! When the System Information window opens, click File and select Save. Give it a filename like sysinfo.nfo (the .nfo extension will be added automatically).

    Now put this sysinfo.nfo file into a ZIP file (to compress it and make it uploadable) and attach it here to your next message.
     
  24. JZN

    JZN Private E-2

    Sorry I mean that I did a disk check (chkdsk)

    I have a problem with uploading the sysinfo file can't compress it more then to 159kb the orginal uncompressed file is 4856kb... Am I doing anything wrong???

    I think that the rapidly decreasing in harddisk space has stoped now but I still have this problem with the "missing" 40 gb...
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I knew it would be big. That is why I said to ZIP it. But I did not expect it to be over 4Mb. The upload limit here is 97kb.

    I sent you a PM on what to do.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your own report:

    You only have 5.42 Gb available. Not 40 Gb.
     
  27. JZN

    JZN Private E-2

    Just mailed you a new zip file check it out!!!
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not seeing all of the files in one of those snapshots. The chkdsk command showed:

    76740488 kB i 74214 filer.

    That's 74214 files. One snapshot only showed 46,627 .

    Sounds like a load of hidden/system files are not being counted. For example, how much stuff is in you System Volume Information folder (this is System Restore). One of the previous files you uploaded reported 0 bytes for System Volume Info. I doubt that is true unless it is disabled and all restore points have been deleted.
     
  29. JZN

    JZN Private E-2

    Okay... how do I see how much there are in that file then??? Don't know there to look for those files...
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is System Restore actually enabled?

    You can see the files in the System Volume Information folder with Windows Explorer. You can also right click on the folder and get Properties on it to tell you how many files and how much space it takes up.
     
  31. JZN

    JZN Private E-2

    found it and it's empty!!!


    Don't know if it's enable either so I need help with that... don't know where do enable it!
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said you ran the READ & RUN ME in your first message. See step 1.

    Have you run a disk Error check lately on your drive?
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try something to see if you can discover where the space is being used. Download the below small utility and install it an run it. It has an Explorer like look but shows space being used. It sorts by size used and uses colors to highlight big users.

    TreeSize Free 1.77 (1.7.7.87)

    You can use it to navigate thru the folders and find where the space is being used easily. Let me know if this helps.
     
    Last edited: Nov 23, 2005
  34. JZN

    JZN Private E-2


    Hi!!! Yes I have read the and ran the READ & RUN ME but I didn't memories what I did that's why I didn't know what to do... :)

    No haven't run disk error check... don't know that it is either...

    Now I can't enable system restore!!! I get a error message that says that "one or more units couldn't be activeted/deactivated. Restart you computer and try again"

    Have restarted 3 time and I stilll can't enble it
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what is up with System Restore right now. Nothing we did should cause any problems with trying to re-enable it. We can look to see if the service has been disabled. But first I wanted to see where things with your Missing Diskspace stand. Did you run the program I gave you a link too?

    It could also be that there is not enough space left on your hard drive to enable system restore. There are settings in the Restore tab to adjust what size the restore area will be. Try reducing it to something small enough to fit in the space you have available. But remember that this will now reduce your free space even more.
     
  36. JZN

    JZN Private E-2

    Have tried to adjust the size to 1% but it still don't work...
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run disk Error check on your drive. Right click on the drive from Windows Explorer and select Properties. Then select Tools and then under Error-Checking click the Check now button. In the next window click to select the two check boxes and then click Start.

    Let me know the results.
     
  38. JZN

    JZN Private E-2


    Have done that now and it's nothing wrong with the disk.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  40. JZN

    JZN Private E-2


    I'm going to check it out. Have read the first parts and I recognise some things that I have read so I probably will be able to fix it now...

    Will be back with info when I have tried it.
     
  41. JZN

    JZN Private E-2

    Invalid File Names
    Folders or files that contain invalid or reserved file names may also be excluded from file and folder statistics. Folders or files that contain leading or trailing spaces are acceptable in NTFS; however, these files are not acceptable in the Win32 subsystem. Therefore, neither Windows Explorer nor a command prompt can reliably handle files that have leading or trailing spaces.

    For additional information, click the article number below to view the article in the Microsoft Knowledge Base:
    120716 (http://support.microsoft.com/kb/120716/EN-US/) How to Remove Files with Reserved Names in Windows NT
    Typically, it is not possible to rename or delete files or folders that have leading or trailing spaces. If you try to rename or delete these folders of files, you may receive one of the following error messages:
    Error renaming file or folder

    Cannot rename file: Cannot read from the source file or disk.
    -or-
    Error deleting file or folder

    Cannot delete file: Cannot read from the source file or disk.


    Do you know how to delete files like that or do I have to contact the microsoft support for that...

    Don't really know what to do right now have read almost everything now. I should now how to check and explore NTFS but I have totally forgotten where to do that.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume this means you have found some bad filenames. What and where are they?

    First I would try giving the below tool a run. It is much more powerful than Windows Explorer.

    ExplorerXP
     
  43. JZN

    JZN Private E-2


    Well there are some bad filenames... and I have them I my desktop?

    C:\Documents and Settings\All Users\desktop

    And they are from when I ripped a stream from a streamsite. Don't know if there is something wrong with it but they are there now. The site is for streaming sports on tv.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can try to see if you can copy the files to a shorter valid filename elsewhere (maybe using ExplorerXP). And then delete the ones from the Desktop.
     
  45. JZN

    JZN Private E-2


    I can't delete them... There isn't any thing in them (0 byte) It's just annoying to have them laying around.

    Maybe have to talk to microsoft support to get rid off them, that is if you can't help me

    How do I do to check the partitions on the disk??? think that that's where the problem is...
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not say whether you tried using ExplorerXP.
     
  47. JZN

    JZN Private E-2

    Sorry

    I did use ExploreXP and it didn't work but I will try some more tomorrow beginning to get late her in Sweden...

    What about the partitions then?? any suggestions???
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What's the time difference....5 hrs??? It's 9:45 PM here.

    What is it that you want to look at with the partitions? I don't remember that msinfo32 showed any other partitions?
     
  49. JZN

    JZN Private E-2

    I guess it's 6 hours. your on CET aren't you.

    Thought that it could be something wrong with the partitions because the 40 gb are still gone.

    when I using ExplorerXP it says that I now have 26 gb in C: but when I highlight C: it shows 74 gb something...

    And I don't think it has something to to with the bad files but how knows... Am trying to remember if it started when I recieved those file...
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm in EST but that may still be 6 hours. Are you at GMT + 1:00?

    If the bad files are not registering their sizes properly, how do you know that they are not using a bunch of space. Perhaps you need to make a backup of all valid items in your Desktop folder (into a new folder called NewDesktop). And then delete the current Desktop folder to see if that will remove the bad files. If so, then just rename NewDesktop to Desktop afterwards.

    Are you sure this is the only place where you have bad file names?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds