Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Hard disk will be very busy [RESOLVED]


  • This topic is locked This topic is locked

#1
paper

paper

    Member

  • Member
  • PipPip
  • 48 posts
Hi Experts,

I have found problems in my WindowsXP:

My hard disk will be very busy after I not tutch it for a while until I move the mouse. So, I tried to scan my system by ewido and found Adware.CoolWebSearch and orther cookies, the "Infected Objects" showed 11. As suggested, I selected "Remove" and then press "OK". However, the "Cleaned infected items" still showed 0. Next time I run ewido again and found Adware.CoolWebSearch and orther cookies again.

Can you help?
  • 0

Advertisements


#2
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Run CWShredder and see if it finds anything:

Download CWShredder at http://www.greyknigh.../CWShredder.exe and run it. Click on 'I Agree' button if you agree. Click on 'Fix' (it will automatically fix anything it finds for you) and then click OK. If it asks if you want to delete a certain random file, choose No and post that filename here. Let it finish the scan and then hit Next and Exit.

Then post your HijackThis log here.
  • 0

#3
paper

paper

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Thank you.
Strange, nothing found by CWSherdder:

Restoring Internet Explorer pages 0 Restored
Restoring hidden IE Options tabs Done
Removing hosts file redirections None Infected

CoolWebSearch was not found on this system.
--------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 10:00:24, on 21/02/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Lin\Tool\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Lin\Tool\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\mdm.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\MICROS~3\Office\OUTLOOK.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Lin\Tool\hijackthis_199\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Lin\Tool\PDF\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Lin\Tool\SpybotSD14\SDHelper.dll
O4 - HKLM\..\Run: [Zone Labs Client] C:\Lin\Tool\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Lin\Tool\Kaspersky\kav.exe" /minimize
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zone...canner37240.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...509/mcfscan.cab
O23 - Service: ewido security suite control - ewido networks - C:\Lin\Tool\ewido\security suite\ewidoctrl.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Lin\Tool\Kaspersky\kavsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
  • 0

#4
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Nothing in HijackThis log...

Download AboutBuster http://www.greyknigh...AboutBuster.zip and unzip the files to a folder on your Desktop. Don't run it yet.

Restart your computer and boot into Safe Mode (if you don't know how, go to http://www.bleepingc...showtutorial=61 ). Make sure to close any open browsers.

Run AboutBuster and click Begin Removal. Once that's done, just hit the OK button. Click Exit once you are done. Click the OK button and it should exit.

Boot back to Normal Mode (just restart your computer).

Run AboutBuster again and click Begin Removal. Once that's done, just hit the OK button. Click Exit once you are done. Click the OK button and it should exit. Open up the 'Ab LogFile.txt' (which was created in the same folder as AboutBuster) and post the log here.

Then do the Panda scan:

Perform an online scan with Internet Explorer at Panda ActiveScan http://www.pandasoft.../activescan.htm

* Click on 'Scan your PC' button. There should be a popup - if you have a pop-up blocker, make sure it's not blocking it.
* Click 'Check Now' & a pop-up window will appear.
* Enter your Country, State and E-mail Address & click 'Scan Now' - begin downloading Panda's ActiveX controls (8 MB size).
* Begin the scan by selecting My Computer.
* If it finds any malware, it will offer you a report. Ignore any entry it finds (since it wants you to buy the program for removal) as we will address this later.
* Click on see report. Then click Save report.
* Please post that log in your next reply.
  • 0

#5
paper

paper

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
AboutBuster removed many files?! Panda found many cookies.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
AboutBuster 6.0
Scan started on [21/02/2006] at [23:21:43]
-------------------------------------------------------------
Internet Explorer Instances Terminated!
HomeSearch Service stopped if present
-------------------------------------------------------------
Streams(ADS) not scanned: System not NTFS
-------------------------------------------------------------
Removed File! : C:\WINDOWS\fhpmv.log
Removed File! : C:\WINDOWS\dggsgv.txt
Removed File! : C:\WINDOWS\xayho.dat
Removed File! : C:\WINDOWS\evkasb.dat
Removed File! : C:\WINDOWS\qxvbb.dat
Removed File! : C:\WINDOWS\bfkmj.log
Removed File! : C:\WINDOWS\ydubpz.txt
Removed File! : C:\WINDOWS\qengkb.log
Removed File! : C:\WINDOWS\mknur.dat
Removed File! : C:\WINDOWS\wwigzg.dat
Removed File! : C:\WINDOWS\hwatbi.dat
Removed File! : C:\WINDOWS\dfojfo.log
Removed File! : C:\WINDOWS\vgyoar.log
Removed File! : C:\WINDOWS\ybwysd.txt
Removed File! : C:\WINDOWS\xsgun.dat
Removed File! : C:\WINDOWS\ackpq.log
Removed File! : C:\WINDOWS\System32\mzvos.txt
Removed File! : C:\WINDOWS\System32\jirom.dat
Removed File! : C:\WINDOWS\System32\fvkrf.dat
Removed File! : C:\WINDOWS\System32\ncrqt.log
Removed File! : C:\WINDOWS\System32\trupx.txt
Removed File! : C:\WINDOWS\System32\zwsaq.txt
Removed File! : C:\WINDOWS\System32\mqvbz.dat
-------------------------------------------------------------
Removed Temp Files
Internet Explorer Settings Reset!
-------------------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 23:30:28


AboutBuster 6.0
Scan started on [21/02/2006] at [23:37:14]
-------------------------------------------------------------
Internet Explorer Instances Terminated!
HomeSearch Service stopped if present
-------------------------------------------------------------
Streams(ADS) not scanned: System not NTFS
-------------------------------------------------------------
No Files Found!
-------------------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 23:39:49

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Incident Status Location

Adware:adware/ideskbar Not disinfected C:\WINDOWS\SYSTEM32\dgprpsetup.exe
Adware:adware/searchaid Not disinfected C:\WINDOWS\SYSTEM32\sdkgx32.exe
Adware:adware/sbsoft Not disinfected Windows Registry
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Lin\Cookies\lin@azjmp[2].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Lin\Cookies\lin@xmts[2].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Lin\Cookies\lin@ask[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Lin\Cookies\lin@belnk[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Lin\Cookies\lin@offeroptimizer[1].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Lin\Cookies\lin@kinghost[2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Lin\Cookies\lin@adultfriendfinder[2].txt
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Lin\Cookies\lin@rn11[2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Lin\Cookies\lin@casalemedia[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Lin\Cookies\lin@realmedia[1].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Lin\Cookies\lin@zedo[2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Lin\Cookies\lin@ccbill[1].txt
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Lin\Cookies\lin@kinghost[3].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Lin\Cookies\lin@ask[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Lin\Cookies\lin@yadro[1].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Lin\Cookies\lin@maxserving[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][1].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Lin\Local Settings\Temp\Cookies\lin@xmts[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Lin\Local Settings\Temp\Cookies\[email protected][2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Lin\Local Settings\Temp\Cookies\lin@belnk[1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Lin\Local Settings\Temp\Cookies\lin@toplist[1].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Lin\Cookies\lin@azjmp[2].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Lin\Cookies\lin@xmts[2].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Lin\Cookies\lin@ask[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Lin\Cookies\lin@belnk[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Lin\Cookies\lin@offeroptimizer[1].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Lin\Cookies\lin@kinghost[2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Lin\Cookies\lin@adultfriendfinder[2].txt
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Lin\Cookies\lin@rn11[2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Lin\Cookies\lin@casalemedia[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Lin\Cookies\lin@realmedia[1].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Lin\Cookies\lin@zedo[2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Lin\Cookies\lin@ccbill[1].txt
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Lin\Cookies\lin@kinghost[3].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Lin\Cookies\lin@maxserving[2].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Lin\Cookies\lin@ask[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Lin\Cookies\lin@yadro[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt
Adware:Adware/PsGuard Not disinfected C:\Lin\Tool\Virus\!KillBox\Desktop.htt
  • 0

#6
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Delete these:

C:\WINDOWS\SYSTEM32\dgprpsetup.exe
C:\WINDOWS\SYSTEM32\sdkgx32.exe
C:\Lin\Tool\Virus\!KillBox\


Download CleanUp! http://cleanup.stevengould.org/ (Alternate Link if main link don't work - http://www.greyknigh...spy/CleanUp.exe ) and install it. CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp!. Run CleanUp! and click on the Options button. Uncheck 'Scan local drives for temporary files'. Also uncheck those two Newsgroup entries if you don't want to delete them. Click OK and then click on the CleanUp! button. Let it run. After it's done, choose Yes to logoff.

Restart your computer and run a new Panda scan. Post that log here along with a new HijackThis log.
  • 0

#7
paper

paper

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Looks cleaned many, but got two new adwares!!

~~~~~~~~~~~from Panda~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Incident Status Location

Adware:adware/searchaid Not disinfected C:\WINDOWS\SYSTEM32\sdkhu32.exe
Adware:adware/ideskbar Not disinfected Windows Registry
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][1].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Lin\Cookies\lin@maxserving[2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][1].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Lin\Cookies\lin@maxserving[2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Lin\Cookies\[email protected][2].txt

~~~~~~~~~~~~from HijackThis~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Logfile of HijackThis v1.99.1
Scan saved at 12:40:31, on 23/02/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Lin\Tool\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Lin\Tool\ZoneAlarm\zlclient.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\MICROS~3\Office\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Lin\Tool\hijackthis_199\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Lin\Tool\PDF\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Lin\Tool\SpybotSD14\SDHelper.dll
O4 - HKLM\..\Run: [Zone Labs Client] C:\Lin\Tool\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Lin\Tool\Kaspersky\kav.exe" /minimize
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zone...canner37240.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...509/mcfscan.cab
O23 - Service: ewido security suite control - ewido networks - C:\Lin\Tool\ewido\security suite\ewidoctrl.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Lin\Tool\Kaspersky\kavsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
  • 0

#8
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Download KillBox http://www.greyknigh...spy/KillBox.exe. Run KillBox and check the box that says 'End Explorer Shell While Killing File'. Next click on 'Delete on Reboot'. Right click and copy the below lines. Go back to KillBox. Go to File->Paste from Clipboard and then hit the button with a red circle and white X. Confirm to delete and when asked if you want to reboot, say Yes:

C:\WINDOWS\SYSTEM32\sdkhu32.exe

If you get a PendingOperations message, just close it and restart your computer manually.

Restart...Run CleanUp program again. Then delete everything inside this folder if found:

C:\Documents and Settings\Lin\Cookies\

After that, your log should be clean :tazz:

To help prevent future spyware installations/infections, please read the Anti-Spyware Tutorial and use the tools provided.

Are there any problems now? If not, you should be set to go.
  • 0

#9
paper

paper

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
I have just finished KillBox and CleanUp jobs! Thank you for your help.

Just want to ask you that if my busy hard disk problem can be solved or not? I think the hard disk will start busy when the screen saver appears. Sorry, I don't know if this problem is relacted to virus or not. If not, I will try to found some whrer else.

Thank you again.
  • 0

#10
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
It's only busy spinning when the screensaver comes up? That is strange...

I do see something that might be causing issues (not sure if it will cause the hard disk to be busy in screensaver though). You have Norton installed before right? I see it's still running as a service there. Let's get rid of it completely since you have Kaspersky.

Go to Start->Run and type in notepad and hit OK. Then copy and paste the following into Notepad:

sc stop SNDSrvc
sc delete SNDSrvc
del delete.bat


Save the file as "delete.bat". Make sure to save it with the quotes. Double click on it.

Delete this folder:

C:\Program Files\Common Files\Symantec Shared\

Restart. Any better? If not, boot into Safe Mode and let the screensaver turn on to see if it also makes the hard drive spin a lot.
  • 0

#11
paper

paper

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
greyknight17,

Great news, I solved my busy hard disk problem by use your strange method! Thank you so much.
  • 0

#12
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP