What is accessing my hard drive?

airduct

Senior member
Jan 27, 2000
321
0
0
how do I find out what software is accessing my hard drive? i am on a inspiron 8200 w/ home WinXP and there is something that is constantly accessing my hard drive. how do i find out what it is? thanks
 

Mavrick007

Diamond Member
Dec 19, 2001
3,198
0
0
It could be something that is updating it self or if you're connected to the internet and don't have a firewall then it could be outside connections trying to hack your machine or steal info.

You could always check to see which processes are active in your task manager. It will let you know how much resources are being used as well as what programs are running.
 

slycat

Diamond Member
Jul 18, 2001
5,656
0
0
before u panic..

actually, here's what u do.
disconnect from internet...if still no change, that means ur not being hacked.
Look at your taskbar, it can be a virus scanner scanning, a scheduled task like Defragmenter working,
or another program.

on the other hand, if u think someone is accessing your system, go to Start, Run, and type in "compmgmt.msc" and Enter.
Under SystemTools, SharedFolders, you should see Shares, Sessions, OpenFiles...click on these to make sure things look alright.
if someone is accessing your files, it will also show up there. Sessions and OpenFiles should 'usually' be empty, unless someone IS
looking at your files. You can also do a few other things like turn on full logging under your Profiles, to audit access events etc...
then you will be able to see any activity in your EventViewer(Start, Run, "eventvwr" and Enter).

a personal firewall with IDS is also recommended...
 

ForUmuse

Member
Jan 22, 2002
26
0
0
I do not know if this is applicable or not to the Home Edition, but check and see if Indexing Services is running. Also, if you are running any Norton AV software, see if the Live File System protection is enabled is it is available.
 

Miramonti

Lifer
Aug 26, 2000
28,653
100
106
Originally posted by: tkdkid
Step aside all you inferior geeks, here comes the good info: Go to sysinternals.com and download diskmon. It'll tell you every single disk operation that happens and what program caused it. http://www.sysinternals.com/ntw2k/freeware/diskmon.shtml
Diskmon works on NT 4.0 and Windows 2000.

He's got XP, tkdkid.
rolleye.gif
:p
 

kduncan5

Golden Member
Apr 22, 2000
1,794
0
0
After you've discovered you have no legitimate programs updating in the background, you can go to Housecall and check for virus', and download AdAware and check for spyware. -kd5-
 

airduct

Senior member
Jan 27, 2000
321
0
0
Originally posted by: jjsole
Sorry to bog your system down. I got what I needed and am through now. ;)

that's so not funny :)... thanks for all the replies, i'll see if it works.

I removed alot of the stuff that came w/ the inspiron 8200 system: Norton AV (it only had 90 days registration and is so bloated and slow), all the symantec auto update stuff, MSN explorer (I sign up using it, but then deleted it and currently using DUN)... i am trying to figure out how to remove Windows Media Player 8.0 and a couple of other useless, bloated programs. thanks again for all the replies.



 

JellyBaby

Diamond Member
Apr 21, 2000
9,159
1
81
It's probably XP's defragger making a "brief" rearrangement pass. This is never listed in "scheduled tasks" and I don't know how to stop it from doing its unholy work.
 

airduct

Senior member
Jan 27, 2000
321
0
0
tkdkid,

i used the disk monitor and this is what it read EVERY 2 SECS!!!


1000 IRP_MJ_WRITE \Harddisk\Partition 0 Success Sector6431721 length 8
.
.
.
.
1398 IRP_MJ_WRITE \Harddisk\Partition 0 Success Sector6431721 length 8

it keeps saying irp_mj_read or irp_mj_flush etc...

what is going on? anyone know? should I / Can I stop it? thanks



 

tkdkid

Senior member
Oct 13, 2000
956
0
0
That may just be the OS writing to or reading from the swap file. I also noticed on my system that when I stopped the System Event Notification service that it stopped doing it when the system is idle.
 

tkdkid

Senior member
Oct 13, 2000
956
0
0
Hey you know what I just realized? Diskmon isn't going to help you at all. What you want to download is Filemon. Hehe..sorry about that.
 

airduct

Senior member
Jan 27, 2000
321
0
0
kid,

how do you stop the system event notification? where is it located? thanks for the help.
 

airduct

Senior member
Jan 27, 2000
321
0
0
tkdkid,

sorry i didn't get back to you sooner... i downloaded the filemo, but didn't know how to stop the files that were accessing the hard drive. so i checked w/ tweakxp.com and they said to turn off indexing under c drive and that helped a lot. thanks for all the help.