Pen Drive shows too lesser space

Closed
avinash027 Posts 9 Registration date Monday June 16, 2014 Status Member Last seen June 21, 2014 - Jun 16, 2014 at 03:53 AM
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 - Jun 21, 2014 at 12:22 PM
My 32 Gb Pen Drive showing only 68 Mb space since last one year.

Today I use "HP USB Disk Storage Format Tool" on it then it started showing 125 Mb.

It's good at have been increase a little bit But It's original functional capacity was 32 Gb earlier !

Out of 32 Gb only 125 Mb space available, It's looking funny in it self.

I have tried a lot again again with the same software to fix it but nothing happen.

Could you please suggest any other Better Procedure !!!

Thanks
Avinash
Related:

10 responses

2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Jun 20, 2014 at 04:17 AM
Hello,

Yes it's normal for MBR.

After run ZHPDiag, you click on Full options button ?

Gabriel.
1
avinash027 Posts 9 Registration date Monday June 16, 2014 Status Member Last seen June 21, 2014
Jun 20, 2014 at 04:47 AM
Hello,

Yes, I clicked on Full Option button then a dialog box appear, I closed that after that 0% screen remain continue for approx 2 hours.

Avinash
0
avinash027 Posts 9 Registration date Monday June 16, 2014 Status Member Last seen June 21, 2014
Jun 16, 2014 at 11:45 PM
No, I didn't formatted it using windows inbuilt format software Yet,

Please tell me the process of that !

Thanks
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Jun 17, 2014 at 05:42 AM
Hello,

# Download UsbFix on your computer, and execute it.
# It will launch automatically, and a shortcut will be created on your desktop.
# Connect all your external data sources to your PC (Usb keys, external drives, etc...) Do not open them.
# Choose Option -> BBCode -> Kioskea -> Apply
# Now press "Clean" buton.


# After cleaning, copy/paste the report on your reply.
->> Tutorial

Gabriel.
0
avinash027 Posts 9 Registration date Monday June 16, 2014 Status Member Last seen June 21, 2014
Jun 17, 2014 at 11:17 AM
Hello,

When I run USB Fix as per your instruction it shows an error message and stop after 98% and at that point of time it shows Infected Element: 0 & an "AutoIt Error" box appears with message,

Line 35582 (File "C:\UsbFix\UsbFix.exe"):
Error: Subscript used on non-accessible variable.

Here I'm pesting the Log report from UsbFix Folder in C Drive :

############################## | UsbFix V 7.171 | [Clean]

User: Avinash (Administrator) # AVINASH-PC
Updated 18/05/2014 by El Desaparecido - SosVirus
Started at 20:27:25 | 17/06/2014

Website : http://www.en.usbfix.net/
Changelog : http://www.en.usbfix.net/changelog/
Support : https://ccm.net/forum/viruses-security-7
Upload Malware : http://www.sosvirus.net/upload_malware.php
Contact : http://www.en.usbfix.net/contact/

PC: Dell Inc. (0U315R)
CPU: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
RAM -> [Total : 3032 Mo| Free : 1954 Mo]
Bios: Dell Inc.
Boot: Normal boot

OS: Microsoft Windows 7 Ultimate (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16521
WB: Google Chrome : 33.0.1750.149
WB: Mozilla Firefox : 27.0.1

SC: Security Center [Enabled]
WU: Windows Update [Enabled]
AS: Windows Defender [Enabled | (!) Outdated]
FW: Windows FireWall [Enabled]

C:\ (%SystemDrive%) -> Fixed drive # 154 Gb (78 Mb free - 51%) [Boot] # NTFS
D:\ -> Fixed drive # 120 Gb (74 Mb free - 61%) [Bhago yahan se] # NTFS
E:\ -> CD-ROM
F:\ -> Removable drive # 126 Mb (126 Mb free - 100%) [] # FAT
Z:\ -> Fixed drive # 24 Gb (24 Mb free - 100%) [] # NTFS

################## | Stopped processes |

C:\Windows\System32\WUDFHost.exe (ID: 3424|ParentID: 1192|LOCAL SERVICE)
C:\Windows\explorer.exe (ID: 4496|ParentID: 2180|Avinash)
C:\Windows\System32\SearchIndexer.exe (ID: 4660|ParentID: 192|SYSTEM)
C:\Windows\System32\SearchProtocolHost.exe (ID: 3132|ParentID: 4660|SYSTEM)
C:\Windows\System32\SearchFilterHost.exe (ID: 3736|ParentID: 4660|SYSTEM)
C:\Windows\System32\SearchProtocolHost.exe (ID: 4884|ParentID: 4660|Avinash)
C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (ID: 5376|ParentID: 192|SYSTEM)
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (ID: 5600|ParentID: 192|SYSTEM)

################## | Autorun |


################## | Generic Research |


(!) Temporary files deleted.

################## | Registry |


################## | Regedit Run |

F2 - HKLM\..\Winlogon : [Shell] Explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] Explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe,
F2 - [x64] HKLM\..\Winlogon : [Userinit] userinit.exe,
04 - HKCU\..\Run : [XUS Desktop] C:\Program Files (x86)\XUSSoft\XUS Desktop\XUSDesktop.exe
04 - HKCU\..\Run : [PC Suite Tray] "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
04 - HKCU\..\Run : [Google Update] "C:\Users\Avinash\AppData\Local\Google\Update\GoogleUpdate.exe" /c
04 - HKCU\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\Run : [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot
04 - HKLM\..\RunOnce : [Trojan Remover] "C:\Program Files (x86)\Trojan Remover\RMVTRJAN.EXE" /restart
04 - [x64] HKLM\..\Run : [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
04 - [x64] HKLM\..\Run : [Apoint] C:\Program Files\DellTPad\Apoint.exe
04 - [x64] HKLM\..\Run : [IgfxTray] C:\Windows\system32\igfxtray.exe
04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\Windows\system32\hkcmd.exe
04 - [x64] HKLM\..\Run : [Persistence] C:\Windows\system32\igfxpers.exe
04 - [x64] HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
04 - [x64] HKLM\..\Run : [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-1821987250-656801231-3077148635-1000\..\Run : [XUS Desktop] C:\Program Files (x86)\XUSSoft\XUS Desktop\XUSDesktop.exe
04 - HKU\S-1-5-21-1821987250-656801231-3077148635-1000\..\Run : [PC Suite Tray] "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
04 - HKU\S-1-5-21-1821987250-656801231-3077148635-1000\..\Run : [Google Update] "C:\Users\Avinash\AppData\Local\Google\Update\GoogleUpdate.exe" /c
04 - HKU\S-1-5-21-1821987250-656801231-3077148635-1000\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe

################## | C:\ %SystemDrive% - Fixed drive (NTFS) |

[17/06/2014 - 08:43:58 | ASH | 2328852 Ko] - C:\hiberfil.sys
[06/02/2013 - 14:45:22 | N | 0 Ko] - C:\extensions.sqlite
[01/04/2012 - 13:40:59 | N | 0 Ko] - C:\trialC.sca
[01/04/2012 - 13:41:04 | N | 0 Ko] - C:\trialC2.sca
[01/04/2012 - 13:41:08 | N | 0 Ko] - C:\trialC3.sca
[02/04/2012 - 14:55:50 | N | 4447 Ko] - C:\Spring Publisher.msi
[18/03/2013 - 11:52:48 | N | 0 Ko] - C:\user.js
[15/09/2012 - 11:38:21 | N | 0 Ko] - C:\symlinks.ini
[13/11/2003 - 12:00:00 | N | 440 Ko | SHA1: C64E3ED82DAC24575F166FDF8B63CFEF3674FFD8] - C:\HPUSBF.EXE
[21/04/2004 - 10:38:06 | N | 436 Ko | SHA1: D2052F51BDA80B66E7ED8507298B21F066E7BC2F] - C:\HPUSBFW.EXE
[24/10/2003 - 15:50:00 | N | 17 Ko] - C:\EULA.doc
[01/12/2006 - 23:37:14 | N | 884 Ko | SHA1: 9E32797D7CBCD599BA64BA28C0EB93EC06840C1E] - C:\msdia80.dll
[19/02/2013 - 14:14:14 | N | 34 Ko | SHA1: EB212D76AF308F9AA99F0100E49C00C36306DF86] - C:\ScriptFF.dll
[10/02/2013 - 14:17:20 | SHD] - C:\$RECYCLE.BIN
[14/07/2009 - 10:38:56 | SHD] - C:\Documents and Settings
[02/03/2012 - 21:00:06 | SHD] - C:\Recovery
[07/03/2012 - 15:59:34 | D] - C:\dell
[24/03/2012 - 13:54:47 | D] - C:\FileStream Sync TOGO
[03/05/2012 - 09:09:57 | D] - C:\PDFPasswordRemover
[24/05/2012 - 14:52:29 | D] - C:\MultiSet
[02/07/2012 - 13:15:34 | D] - C:\JPG2PDF
[13/07/2012 - 19:47:02 | D] - C:\Intel
[08/10/2012 - 00:24:17 | D] - C:\PDFOCR_Output
[26/12/2012 - 23:06:41 | D] - C:\recovered
[10/02/2013 - 01:38:59 | D] - C:\temp
[10/02/2013 - 11:37:03 | RHD] - C:\MSOCache
[16/05/2013 - 18:57:13 | N | 0 Ko] - C:\(ö
[09/08/2013 - 00:26:53 | D] - C:\output
[27/09/2013 - 11:04:26 | D] - C:\Users
[14/10/2013 - 11:42:11 | D] - C:\inetpub
[16/10/2013 - 22:38:41 | D] - C:\perflogs
[12/06/2014 - 10:32:07 | D] - C:\M
[17/06/2014 - 08:57:17 | D] - C:\ActiveX
[17/06/2014 - 08:57:18 | D] - C:\Windows
[17/06/2014 - 08:58:16 | D] - C:\System Volume Information
[17/06/2014 - 10:13:03 | HD] - C:\ProgramData
[17/06/2014 - 10:35:17 | D] - C:\Program Files
[17/06/2014 - 10:40:04 | D] - C:\FreeOCR
[17/06/2014 - 12:56:39 | D] - C:\Program Files (x86)
[17/06/2014 - 20:25:21 | D] - C:\UsbFix

################## | D:\ - Fixed drive (NTFS) |

[01/04/2012 - 13:40:59 | N | 0 Ko] - D:\trialC.sca
[01/04/2012 - 13:41:04 | N | 0 Ko] - D:\trialC2.sca
[01/04/2012 - 13:41:08 | N | 0 Ko] - D:\trialC3.sca
[17/06/2014 - 08:46:27 | SHD] - D:\$RECYCLE.BIN
[06/02/2013 - 16:04:29 | SHD] - D:\System Volume Information
[26/10/2013 - 14:36:57 | D] - D:\Audio
[26/10/2013 - 16:19:01 | D] - D:\Advertisement Unique Vedios
[26/10/2013 - 16:19:04 | D] - D:\Akshar dhaam
[26/10/2013 - 16:32:51 | D] - D:\raju shrivastawa
[26/10/2013 - 16:33:11 | D] - D:\Vaibhav Songs
[05/06/2014 - 17:51:24 | D] - D:\~ Movies
[14/06/2014 - 11:32:08 | D] - D:\DELL Drivers
[17/06/2014 - 08:48:58 | D] - D:\Old C Drive Data

################## | F:\ - Removable drive (FAT) |



Is there any thing could happen in this case !

Thanks
Avinash
0

Didn't find the answer you are looking for?

Ask a question
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Jun 17, 2014 at 12:48 PM
Hello,

OK.

Is this drive which has a problem ?
F:\ -> Removable drive # 126 Mb (126 Mb free - 100%) [] # FAT

Gabriel.
0
avinash027 Posts 9 Registration date Monday June 16, 2014 Status Member Last seen June 21, 2014
Jun 17, 2014 at 11:41 PM
Yes,

It is the same drive "F" which appears when I plug Pen drive in pc.

Avinash
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Jun 18, 2014 at 04:22 AM
Hello,

Okay. It's strange, because it shows that the capacity is 126 Mb. Are you sure that is a 32 Gb ?
Have you tried on another computer ?

Gabriel.
0
avinash027 Posts 9 Registration date Monday June 16, 2014 Status Member Last seen June 21, 2014
Jun 18, 2014 at 06:12 AM
Hello,

Yes, It was with 32 Gb functional memory one year back. But I used to keep back up of approx 12 gb data on it since that time problem started & shows less memory. I have tried it on several other computers but the result is same every time.

Actually it is not a proper Pen drive, It is a SpyCam Pen which have inbuilt pendrive. Is it the could be the main cause of problem ?

More over I don't have proper receipt of it for warranty kind of thing B'coz it was a gifted item.

Now I think nothing could be done in this case.

Thanks for UR support
Avinash
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Jun 18, 2014 at 01:31 PM
Hello,

And have you tried to format it ?

Gabriel.
0
avinash027 Posts 9 Registration date Monday June 16, 2014 Status Member Last seen June 21, 2014
Jun 18, 2014 at 11:13 PM
Hello,

Yes, I have format it several times even I used HP USB Disk Storage Format Tool on it but nothing good happen. It remain with the same reduced space of 125 Mb only.

Avinash
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Jun 19, 2014 at 08:06 AM
Hello,

Strange...

1. Open this link and download ZHPDiag2 :

https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

(Don't be alarmed is the site is in French, it sometimes happens, the tool will take your system language and allow the download if you get a warning message.)

2. Save the file on your Desktop.

3. Double click on ZHPDiag.exe and follow the installation instructions.

(For Vista and Win 7 users, click right to ensure you execute with admin right)

The tool creates three icons ZHPDiag, MRB, and ZHPFix (If necessary,we will use ZHPFix after log analysis).

4. Double click on the short cut ZHPDiag on your Destktop.

5. If you need to change the language, click on the little house, (bottom right) and change to English

6. Click on Full options.

Wait for the tool to finished (maybe a long time)

7. Close ZHPDiag.

8. To transmit the report, click on this link :

https://authentification.site

9. Search the directory where you installed ZHPDiag (usually C:\desktop\zhpdiag.txt).

10. Select the file ZHPDiag.txt.

11. Click on "upload »

12. Copy the URL and post it here.

Gabriel.
0
avinash027 Posts 9 Registration date Monday June 16, 2014 Status Member Last seen June 21, 2014
Jun 19, 2014 at 09:36 PM
Hello,

I have installed this but only 2 icons ZHPDiag and ZHPFix created, MRB is missing. Then I it again after uninstalling it but again MRB icon not appears.

When I run programme as per your instructions then nothing happen for 2 hours, it shows only 0 % then I shut down.

Again this morning I am running it but same result of 0 % growth appears for long time.


Avinash
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Jun 20, 2014 at 07:56 AM
Hello,

Can you try in safe mode please ? https://ccm.net/faq/223-how-to-start-windows-computer-in-safe-mode

Gabriel.
0
avinash027 Posts 9 Registration date Monday June 16, 2014 Status Member Last seen June 21, 2014
Jun 21, 2014 at 03:03 AM
Hello,

I have tried it on Safe Mode also But nothing happen.

Same result, after half an hour running programme it shows only 0% status.

Avinash
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Jun 21, 2014 at 12:22 PM
Hello,

OK, try to use NCDiag : http://www.nicolascoolman.fr/download/ncdiag/
Run it, wait a moment, and a report will be open at the end.
Host it and paste the link.

Gabriel.
0