| View previous topic :: View next topic |
| Author |
Message |
Radiation Grandmaster Cheater
Reputation: 14
Joined: 17 Jun 2009 Posts: 842 Location: Chernobyl
|
Posted: Sat Feb 05, 2011 5:00 pm Post subject: [SOLVED!] GMER bad_pool_header system crash BSOD |
|
|
Ok, I work with virus-infested computers and laptops a LOT. I would like to find a good tool that will reveal ALL folders/files. Some viruses use clever techniques in folder hiding. Like the program Ardamax - their keyloggers create a folder in system32 that if you don't know the name of it, you will not be able to find it through explorer (even if you go to folder options and uncheck "hide system files/folders".)
Any suggestions?
EDIT:
I posted a solution on this page below
_________________
Last edited by Radiation on Thu Feb 17, 2011 11:27 pm; edited 1 time in total |
|
| Back to top |
|
 |
ipivb Master Cheater
Reputation: 5
Joined: 29 May 2010 Posts: 256
|
Posted: Sat Feb 05, 2011 7:34 pm Post subject: |
|
|
Whenever I get a virus that bad, I pretty much resort to reinstalling windows.
Note I said reinstall, not reformat. If you have at least a few GB of hard drive space left, you can split the partition of your hard drive and reinstall windows on the new partition. Boot from that partition, and if you wish, copy all of your needed files over to the new partition and then delete it so you have one partition again. This way, you can keep all of your files without using an external hard drive or using tons of DVDs.
However, there are a few viruses which are so nasty, they will literally infect every single .exe on your computer (often causing them to not work anymore). This is rare, however, but in this case, you will have to ditch all of your .exe programs and redownload/reinstall them on a clean installation of windows.
A good program I'd recommend is WinPatrol. Instead of being the typical antivirus which scans programs and determines their danger based off of constantly updated signature (and more often than not, being unable to take any action against them), WinPatrol simply warns you whenever it detects a new startup program, registry entry, etc. It's nothing like UAC where it pops up all the fking time and doesn't give you any information. Instead it gives you the exact file name, and asks you whether to allow it or not.
Viruses are more commonly infecting through a somewhat fatal flaw of Java. Sometimes you will visit a website where it makes a Java popup asking if you want to run this application... the problem being that the popup doesn't look that suspicious, and sometimes it will keep asking until you click yes (sometimes accidentally). Which you are then infected.
|
|
| Back to top |
|
 |
atom0s Moderator
Reputation: 205
Joined: 25 Jan 2006 Posts: 8587 Location: 127.0.0.1
|
Posted: Sat Feb 05, 2011 8:48 pm Post subject: |
|
|
Helpful rootkit detection tool:
http://www.gmer.net/
_________________
- Retired. |
|
| Back to top |
|
 |
Radiation Grandmaster Cheater
Reputation: 14
Joined: 17 Jun 2009 Posts: 842 Location: Chernobyl
|
Posted: Sun Feb 06, 2011 3:21 pm Post subject: |
|
|
when I opened it, immediately, my computer crashed and auto-restarted.
_________________
|
|
| Back to top |
|
 |
atom0s Moderator
Reputation: 205
Joined: 25 Jan 2006 Posts: 8587 Location: 127.0.0.1
|
|
| Back to top |
|
 |
Radiation Grandmaster Cheater
Reputation: 14
Joined: 17 Jun 2009 Posts: 842 Location: Chernobyl
|
Posted: Sun Feb 06, 2011 4:48 pm Post subject: |
|
|
| Wiccaan wrote: | If your system is currently infected it could be the virus itself attempting to prevent you from opening it. It's a fairly well known tool so it tends to land up on blacklists inside of viri frequently. I use it frequently for the hook detection and have no issues with it at all.
Perhaps you have something else conflicting with it too, what was the bluescreen message / stop code you got when you ran it? |
hmm... no bsod, just an instant restart. i will enable the showing of bsod and tell you what message i get.
i have ESS 4 and Mbam running on my windows xp sp3 home edition. It crashes regarding if i turn the antivirus on or off. i also have sandboxie, i tried to open it, and to my surprise, it opened it...
yesterday my cousin brought an external hdd and i double-clicked some weird file. I think i'm infected...
EDIT:
Just enabled the BSOD, ran GMER and...
nothing. A regular crash without a BSOD. I think something IS blocking it...
_________________
Last edited by Radiation on Wed Feb 09, 2011 11:35 pm; edited 2 times in total |
|
| Back to top |
|
 |
atom0s Moderator
Reputation: 205
Joined: 25 Jan 2006 Posts: 8587 Location: 127.0.0.1
|
Posted: Sun Feb 06, 2011 7:49 pm Post subject: |
|
|
Try renaming gmer's executable, or run the generated download on their page to see if you can get it to run under a different name.
_________________
- Retired. |
|
| Back to top |
|
 |
Radiation Grandmaster Cheater
Reputation: 14
Joined: 17 Jun 2009 Posts: 842 Location: Chernobyl
|
Posted: Mon Feb 07, 2011 6:01 pm Post subject: |
|
|
| Wiccaan wrote: | | Try renaming gmer's executable, or run the generated download on their page to see if you can get it to run under a different name. |
hmm... no success... although, i was able to open it on another os. I have two harddrives in my computer, each one of them has an independent operating system. I opened GMER on the other harddrive's os (which is also win xp) and it worked!
Now, is there a way to scan for active rootkits on my FIRST harddrive while operating on the second harddrive?
EDIT:
I re-enabled the BSOD and it showed me:
"bad_pool_header"
EDIT2:
Just in case someone has the same problem, I have disabled the service named FsUsbExService by Samsung New PC Studio located in
| Code: | | C:\WINDOWS\system32\FsUsbExService.Exe |
This solved all issues with GMER crashing or not loading. No more BSODs... Happy Me!!!
Thanks for all your help Wiccaan!
_________________
|
|
| Back to top |
|
 |
satanrules666 Advanced Cheater
Reputation: 0
Joined: 31 Oct 2010 Posts: 70 Location: New Zealand
|
Posted: Tue Mar 08, 2011 10:31 am Post subject: |
|
|
you can use event manager to see bsod messages instead of waiting to see a bluescreen that may disapear when ya pc restarts
o see you can spell my name backwards
somehow on here im hated just for having a name such as satanrules666 who would have thaught ae
as for viruses and all i always have my blackbox my 1 terabyte external sata 2 seagate drive which was a old hard drive of mine i had siting around and that contains everything to date not connected to the net and i scan everything i use theres always a false positive with a trainer though
i can normally tell if i have a virus just from decrease in proformance
anyway i use windows live essentials why you ask this is the only anti virus i dont get a bsod from seems my sapphire hd5850 hates old games and it hates antivir
much in the same way i am hated lol
_________________
|
|
| Back to top |
|
 |
|