Need some help- Hard disk being filled by ????

Joined
Sep 2, 2014
Messages
4
Reaction score
0
Points
1
Hi Folks-

So after a night of searching the web and reading just about everything out there I’ve decided no one seems to take this problem I am having seriously, but it is something real and I think I’ve got a start to finding it but need some good help. Please note I’m going to post this same message to 3 or 4 forums around the web. I am hoping by the time I am done getting help to come back to any of these threads and update them all so any legit solution can be found for future folks.

Here’s the problem in a nutshell-

At some point on 1-Sep-14 I got a virus or malware program that has hidden itself well within my Mac Book pro. I’ve used used 2 different virus programs (Sophos [business edition] and ClamXav) to scan my computer 4 times. Nothing was ever found. What this awful code does is write to your hard drive until it fills up. And once you delete anything it does it again. But it is very quick- It can fill 2 GB in under 1 min. One at least useful thing is that if you are NOT connected to the internet it does not work.

What I have figured out was by using an app called GrandPerspective you can visualize your entire hard drive. It lets you see how big and how many files you have- more importantly it also tells you what files each block is and where it is located. I have linked out to this pic…

https://www.dropbox.com/s/b33d77vhm7wfk5y/Affected%20file.jpg?dl=0

So basically in this pic for my hard drive you see the giant file in the middle- that is a video of my kid playing on a playground. The problem is the original version of that file is just 122mb, that giant one is 128GB!! And if you look more at that pic you will also see a bunch of greenish blocks in the bottom left. Those are “online backups/gmail” except I don’t back-up gmail and they range from 2 gb to 17 gb which the latter is larger than my gmail account . [I am also having trouble finding these files as they are hidden, but I can ask for help later on that]



So obviously this code takes potentially legit files and hijacks them.

What I need to figure out is how to find this code, isolate it and get help to potentially protect from getting it again.

As for how I got it, I believe it is from visiting a page to download a font that I have never been to before – as that was my only new thing I did yesterday.


So any help would be great. I won’t be here quickly again today as I am very busy and because I can’t access the internet easily since I have to borrow computers for now. But I promise to check back soon.

Cheers
 
Joined
Sep 3, 2010
Messages
622
Reaction score
13
Points
18
Location
Charlotte, NC
Your Mac's Specs
mid-2010 Mac Mini OS 10.12.6 Sierra, 2.66 GHz C2D, 8GB RAM, 30 in. Cinema Display
Do you have a Time macine backup?
 
OP
G
Joined
Sep 2, 2014
Messages
4
Reaction score
0
Points
1
Nope. I use a different back-up method. I am not afraid to go back to a previous state and will do so. But I want to know what is going on here and prevent it from happening again. And yes if I did I'd be able to find out what is causing it.

From discussions on other boards I think I've narrowed it down to a google chrome problem and the 128gb file may be a strange occurrence of a file getting corrupted at the same time by chance.
 
OP
G
Joined
Sep 2, 2014
Messages
4
Reaction score
0
Points
1
Okay a bit of an update..

So I did some capturing of what is happening.

This is before I get hit by the programs:
https://www.dropbox.com/s/39k79swpx0gbt0o/before.jpg?dl=0

This is during the hit - sadly Grab captured the screen as the "full" window popped up

https://www.dropbox.com/s/w4l25h53i7iidab/going%20on.jpg?dl=0


And here are the 2 programs that seem responsible for it-- they disappear just as quick as they appear

https://www.dropbox.com/s/k3qj6qttmovvdzq/programs.jpg?dl=0


Now please note yes I could just "kill the programs", but that doesn't solve my problem at all as it just keeps coming back and filling up the empty space in seconds.

They seem to be associated with chrome/gmail and happen with something with it. I can't get it to occur by anything I specifically do (ie refreshing, logging in, etc). It sometimes occurs with that, but not everytime.

Hope this may clue in some folks.
 
Joined
Dec 11, 2010
Messages
1,808
Reaction score
40
Points
48
Location
Chicago
Your Mac's Specs
late 2012 mini w/SSD
Try a Safe Boot - it does some repairs in the background - like deleting some system caches.
OS X Mavericks: Start up in safe mode
(it takes much longer than normal. after it's done, see if you're having the same problem, then restart normally.)

Go to Users and Groups and delete unneeded startup (login) items.
 

IWT


Joined
Jan 23, 2009
Messages
10,263
Reaction score
2,210
Points
113
Location
Born Scotland. Worked all over UK. Live in Wales
Your Mac's Specs
M2 Max Studio Extra, 32GB memory, 4TB, Sonoma 14.4.1 Apple 5K Retina Studio Monitor
@Gatorrock

Just interested, and you might not want to say (fair enough); but what Back Up method do you have which allows you to "go back to a previous state"?

Ian
 

chscag

Well-known member
Staff member
Admin
Joined
Jan 23, 2008
Messages
65,248
Reaction score
1,833
Points
113
Location
Keller, Texas
Your Mac's Specs
2017 27" iMac, 10.5" iPad Pro, iPhone 8, iPhone 11, iPhone 12 Mini, Numerous iPods, Monterey
@Gatorrock

Just interested, and you might not want to say (fair enough); but what Back Up method do you have which allows you to "go back to a previous state"?

Ian

It appears he's using an on line backup service.
 
Joined
Nov 1, 2007
Messages
1,251
Reaction score
80
Points
48
Location
Swansea - South Wales
Your Mac's Specs
21 M1 Pro 14" MBP, 23 M2 Pro Mac Mini (MacOS 14), iPhone 15 Pro Max (iOS 17), iPad 6 (iPadOS 17)
have you tried to send the video by email?

I had an issue a couple of years ago where I was trying to send an email with a large attachment - it kept failing and then re-trying to send over and over. Each time it tried to re-send, it added a new copy of the attachment to my hard drive until it pretty well filled it up. It didn't matter that I deleted the email - it still kept trying to send and duplicating the attachment.

I used an app called omnidisksweeper to find the offending file and remove it.
 
OP
G
Joined
Sep 2, 2014
Messages
4
Reaction score
0
Points
1
Thank you all for you very helpful thoughts and directions.

I'm sorry if I offended any one on the virus thing

Anyhow lots and lots of work has been going on since I last posted [both in my real job, hence why I haven't been on here in a while] and with what folks here and other places suggested.

Okay so found good info via another good program called: fseventer
http://fernlightning.com/doku.php?id=software:fseventer:start[fernLightning

Gives you a nice live breakdown of what is going on in your processes.

Anyhow this has shown that is related to my online back-up program.

I didn't think it was this originally as I've been running it for 3 months with out any issue and I haven't upgraded it or installed any new programs on this computer since Mid-July. So why should it suddenly go wrong?

So by going back to GrandPerspective I was able to get to these zip files easily - they are in the hidden library in my user account.

Here’s all those zip files
https://www.dropbox.com/s/g6k4s2f0oewr89m/hiddengmail.jpg?dl=0

What I found interesting is that this folder was first made back on 10-August and until 30-August (ie late Saturday night) the zip files being made were smallish (nothing over 150 megs) but then something happened Saturday night and they started getting made in the Gb range. Also added to this, until yesterday, they were made only 2 times a day. Now they are made every time I'm on the internet and fill up any and all space on the hard drive.


So I know what it is, I sorta know what is doing...but I can't figure out WHY it is doing it (as I've never asked for my email to be backed up as I only access it via the web, never anything like 'Mail' or 'Thunderbird') or more importantly how to stop it without deleting the program all together.

I've contacted SOS Online Backup and was waiting on a response. The first I've gotten has ticked me off to no end as it is a cut and paste response (no literally cut and past from some online document/wiki)- and the short version is they want me to delete everything and reinstall.

I was pissed with that response let them know and waiting for a better one, which has yet to arrive.

So if anyone is thinking about SOS for online back-up I would not recommend them and I'm most likely going to try and get all my money back.

Oh and to answer the previous question of who- that would be SOS, but I no longer believe they can perform the simple reversion as they are not a very streamlined, organized back-up. I would on the other hand suggest looking at CrashPlan. But I had reservations against them too. Not sure anymore.

Anyhow I'll let everyone know how this gets resolved. But yes, it looks like not a virus/malware issue after all, just bad programming for Macs.
 

chscag

Well-known member
Staff member
Admin
Joined
Jan 23, 2008
Messages
65,248
Reaction score
1,833
Points
113
Location
Keller, Texas
Your Mac's Specs
2017 27" iMac, 10.5" iPad Pro, iPhone 8, iPhone 11, iPhone 12 Mini, Numerous iPods, Monterey
Anyhow I'll let everyone know how this gets resolved. But yes, it looks like not a virus/malware issue after all, just bad programming for Macs.

Thanks for the update. I probably should have looked into your problem a bit further... I noticed the on line backup activity and what seemed like a redundancy in the data transfer when you posted your Activity Monitor screen shots. Got busy and had to run off for awhile.
Yes, please let us know when you get it all resolved.
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top