Computer fills memory by it's self!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by JZN, Nov 20, 2005.

  1. JZN

    JZN Private E-2


    Yes I am at GMT +1

    Can't find a way to delete the desktop folder, it's a Windows system folder and can't be deleted.

    Can't find a way to delete the files either.

    And no I don't know if I have more bad filenames... Do I have to check every folder one by one to find them or is there another way?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First make sure you have backed up all the items in the Desktop folder that you want to keep. All the desktop icon etc.

    Then I would say to login as a different user that has Administrator priviledges and then delete the Desktop folder for the user that has these bad filenames. The Desktop folder should be deletable. If it is not then it would have to be due to the bad filenames that are in the folder.

    Right now I do not know of any tools to locate bad file names. You will have to start searching yourself manually.

    I would also suggest you open a command prompt window and type in the below commands and save the output:
    diskpart
    list disk <--- this will give you a Disk number (like 0) which we will need below
    select disk # <--- replace # with the Disk number from above
    list partition <--- this will list Disk # partition info
    list volume <--- this will list Disk # volume info
    exit <--- quits the diskpart utility.
     
  3. JZN

    JZN Private E-2

    Can't delete the bad files even with admin login. Can only find a admin acount when I'm in safe mode could that be the problem.

    any ideas now???

    I guess format C: is comming closer???
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not need to log in with the Administrator account. All you should need to do is make sure the account you are using has administrator priviledges. Then you would not have to boot in safe mode. But it should not matter. If anything, it should be easier to delete the files in safe mode.

    Let's just check a couple more thinks:
    1) look for possible rootkit infections. Download and run F-Secure Blacklight from: http://www.f-secure.com/blacklight/try.shtml

    2) look for Alternate Data Streams (ADS) which could also make files not deletable and could also report their sizes as 0 when they could be anything. Download and run ADS SPY - Alternate Data Streams Spy from Merijn. Make sure you uncheck the option that says Quick Scan (otherwise it will only scan the c:\windows folder). DO NOT DELETE ANYTHING YET. Some ADS files are valid as noted below. When the scan finishes, right click in the results area and select Save scan results to disk. Save the file and upload it here as an attachment. Also tell me if you see any of the files you are having a problem deleting in the list.

    Note: this app also displays legitimate ADS streams. Don't delete streams if you are not completely sure they are malicious! You should consult with an expert before deleting any files with this tool.
     
  5. JZN

    JZN Private E-2

    Now I have run both programs... Didn't find anything with ADSSpy and found 30 000 hidden files with blacklight... Is it safe to delete the files I found with blacklight?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were there any hidden processes?
    What are some of the filenames that Blacklight found? How large are the files?
    Do any of them look like the names of files you know you need?
    Do any of them match the filenames you were seeing in the Desktop folder we could not delete?

    For more background on Blacklight, you may want to also read thru the following help information:

    http://www.f-secure.com/blacklight/help/
     
    Last edited: Dec 4, 2005
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just in case you missed the link in my last post (I did not notice you were on line when I added it), make sure to read it. Also a key part of that help file is:
     
  8. JZN

    JZN Private E-2

    All the files is in the same folder... Haven't checked them out yet but the folder path is

    C:\##\restore\s001\b\WINDOWS\
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That does not seem to be valid! Did you save the Blacklight log?

    You really need to read thru that link I gave to you too. They do have a rename option which may be safer than deleting just in case. But you need to determine that they are not valid files. I tend to doubt it if they are located there.

    Do you use any other kind of backup programs (similar to System Restore)?
     
  10. JZN

    JZN Private E-2

    No it is'nt valid and I found 44Gb in it to so it seems to add up with my problems... And I found alot of copies of some downloaded files.

    It seems that it is a full copy of my C: folder

    Don't know if al files should be deleted but I have a backup program "back on track"

    Have read the link but will do it again.

    Haven't saved nothing because I'm still on "step 2 cleaning" is it safe to finish the program?

    If I klick next without rename any thing nothing will change?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before doing anything with Blacklight, perhaps you should figure out what your BackOnTrack program is doing. Sounds to me like you do not have a problem and that it is just a misunderstanding of how some software you installed works. This is not a malware problem. If you do not need this program and all that is has backed up, uninstall or disable it or whatever it takes to recover the diskspace that it is using.
     
  12. JZN

    JZN Private E-2

    Thanks man!!! You where right!!!

    The problem where the backup program!!!

    so everything is back to been right...

    Thanks again... Hopefully I don't come back here for more help but I think I will...

    hehe...
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds