Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Has my HD Gone Nuts???

Status
Not open for further replies.

brokenstartbutton

Technical User
Jul 27, 2004
5
US
ima running windows xp with 768 ram and the usual 2ghz pentium 4 processor. I have 2 harddrives, actually three harddrives one being in an enclosure running through usb. nevermind that drive. I got this one drive i am having a problem with. lets reffer to it as C:. that is teh drive with windows xp on it. I use D: for program files and c: has the common things, the os. Documents and unzipped files etc. etc. I calculated how much stuff i had on my harddrive one time while i was on the phone with dell. I calculated Roughly.. about 3 gig. Now this is a 14 gig harddrive so you'd ask why am i having problems with only 3 gig on it. Well -- its saying i only have 3 gig free. Now this was quite a few weeks ago. Now my computer is having a cardiac arrest once and a while and just completly slows down. i turned up the virtual memory but still no good. with this processor amd ram it should be mad fast. It's now saying i have less then 200 mb. i deleted stuff from teh harddrive and it makes it 176 mb. whewn i put stuff on it it makes it more. Its totally messed up. Any ideas. I feel that everything is reversed on this harddrive. you delete you are adding you add your deleting and its saying i only have free what i have on it. So any help is appreciated. thx.
smiletiniest.gif
 
Well... you could have a hacker using it?

go "netstat -an |more" and see if you have a lot of network connections?

Also you could do a custom search for say, files over 100MB? Perhaps they are depositing files on your computer to be shared to the IRC communities.

just an idea!

Good luck!
 
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\>netstat -a

Active Connections

Proto Local Address Foreign Address State
TCP GZRT121:epmap GZRT121:0 LISTENING
TCP GZRT121:microsoft-ds GZRT121:0 LISTENING
TCP GZRT121:1025 GZRT121:0 LISTENING
TCP GZRT121:1037 GZRT121:0 LISTENING
TCP GZRT121:2622 GZRT121:0 LISTENING
TCP GZRT121:4094 GZRT121:0 LISTENING
TCP GZRT121:4098 GZRT121:0 LISTENING
TCP GZRT121:4103 GZRT121:0 LISTENING
TCP GZRT121:4104 GZRT121:0 LISTENING
TCP GZRT121:4105 GZRT121:0 LISTENING
TCP GZRT121:4106 GZRT121:0 LISTENING
TCP GZRT121:4376 GZRT121:0 LISTENING
TCP GZRT121:5000 GZRT121:0 LISTENING
TCP GZRT121:netbios-ssn GZRT121:0 LISTENING
TCP GZRT121:1025 wbar9.chi1-4-11-086-160.dsl-verizon.net:56014 E
STABLISHED
TCP GZRT121:1025 211.98.226.5:3064 ESTABLISHED
TCP GZRT121:1025 220.174.115.5:1251 ESTABLISHED
TCP GZRT121:2622 ns1.tjc.no:http CLOSE_WAIT
TCP GZRT121:4094 amin.micfo.com:http CLOSE_WAIT
TCP GZRT121:4098 amin.micfo.com:http CLOSE_WAIT
TCP GZRT121:4103 amin.micfo.com:http CLOSE_WAIT
TCP GZRT121:4104 amin.micfo.com:http CLOSE_WAIT
TCP GZRT121:4105 amin.micfo.com:http CLOSE_WAIT
TCP GZRT121:4106 64.94.110.12:http CLOSE_WAIT
TCP GZRT121:4376 216.239.39.104:http ESTABLISHED
UDP GZRT121:microsoft-ds *:*
UDP GZRT121:isakmp *:*
UDP GZRT121:1029 *:*
UDP GZRT121:1059 *:*
UDP GZRT121:4489 *:*
UDP GZRT121:4490 *:*
UDP GZRT121:4491 *:*
UDP GZRT121:4492 *:*
UDP GZRT121:ntp *:*
UDP GZRT121:1882 *:*
UDP GZRT121:1900 *:*
UDP GZRT121:3778 *:*
UDP GZRT121:4113 *:*
UDP GZRT121:4238 *:*
UDP GZRT121:4944 *:*
UDP GZRT121:ntp *:*
UDP GZRT121:netbios-ns *:*
UDP GZRT121:netbios-dgm *:*
UDP GZRT121:1900 *:*

C:\>


any of these other people using it???
 
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\>netstat -a

Active Connections

Proto Local Address Foreign Address State
TCP GZRT121:epmap GZRT121:0 LISTENING
TCP GZRT121:microsoft-ds GZRT121:0 LISTENING
TCP GZRT121:1025 GZRT121:0 LISTENING
TCP GZRT121:1037 GZRT121:0 LISTENING
TCP GZRT121:2622 GZRT121:0 LISTENING
TCP GZRT121:4094 GZRT121:0 LISTENING
TCP GZRT121:4098 GZRT121:0 LISTENING
TCP GZRT121:4103 GZRT121:0 LISTENING
TCP GZRT121:4104 GZRT121:0 LISTENING
TCP GZRT121:4105 GZRT121:0 LISTENING
TCP GZRT121:4106 GZRT121:0 LISTENING
TCP GZRT121:4376 GZRT121:0 LISTENING
TCP GZRT121:5000 GZRT121:0 LISTENING
TCP GZRT121:netbios-ssn GZRT121:0 LISTENING
TCP GZRT121:1025 wbar9.chi1-4-11-086-160.dsl-verizon.net:56014 E
STABLISHED
TCP GZRT121:1025 211.98.226.5:3064 ESTABLISHED
TCP GZRT121:1025 220.174.115.5:1251 ESTABLISHED
TCP GZRT121:2622 ns1.tjc.no:http CLOSE_WAIT
TCP GZRT121:4094 amin.micfo.com:http CLOSE_WAIT
TCP GZRT121:4098 amin.micfo.com:http CLOSE_WAIT
TCP GZRT121:4103 amin.micfo.com:http CLOSE_WAIT
TCP GZRT121:4104 amin.micfo.com:http CLOSE_WAIT
TCP GZRT121:4105 amin.micfo.com:http CLOSE_WAIT
TCP GZRT121:4106 64.94.110.12:http CLOSE_WAIT
TCP GZRT121:4376 216.239.39.104:http ESTABLISHED
UDP GZRT121:microsoft-ds *:*
UDP GZRT121:isakmp *:*
UDP GZRT121:1029 *:*
UDP GZRT121:1059 *:*
UDP GZRT121:4489 *:*
UDP GZRT121:4490 *:*
UDP GZRT121:4491 *:*
UDP GZRT121:4492 *:*
UDP GZRT121:ntp *:*
UDP GZRT121:1882 *:*
UDP GZRT121:1900 *:*
UDP GZRT121:3778 *:*
UDP GZRT121:4113 *:*
UDP GZRT121:4238 *:*
UDP GZRT121:4944 *:*
UDP GZRT121:ntp *:*
UDP GZRT121:netbios-ns *:*
UDP GZRT121:netbios-dgm *:*
UDP GZRT121:1900 *:*

C:\>


i did netstat -an on this one and netstat -a on the other one. dont know if there is a difference. so this is what i get with netstat -an as you said to do.
 
I'd be questioning these three users connected to your RPC services :
TCP GZRT121:1025 wbar9.chi1-4-11-086-160.dsl-verizon.net:56014 E
STABLISHED
TCP GZRT121:1025 211.98.226.5:3064 ESTABLISHED
TCP GZRT121:1025 220.174.115.5:1251 ESTABLISHED


try
C:\>net file <enter>
tell us what that says :)
 
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\>net file
There are no entries in the list.


C:\>

grah...
 
Did you try doing an advanced search for files over 100MB?

try doing another "netstat -an" and then a "net file" right after it, that way if those RPC users are still there, we might be able to see what they're connected to.. "net file" shows open files on your computer.

Otherwise, there might be a rogue process running on your machine. Check your processes for anything unusual?
 
Check the partition sizes on the disk to ensure you do in fact have 14GB worth of partitions.
Run a complete virus scan with up to date definitions.
Scan for spyware.
Install a softare firewall such as Kerio or Zonealarm.

The above would be a good start.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top