Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


[SOLVED!] GMER bad_pool_header system crash BSOD

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk
View previous topic :: View next topic  
Author Message
Radiation
Grandmaster Cheater
Reputation: 14

Joined: 17 Jun 2009
Posts: 842
Location: Chernobyl

PostPosted: Sat Feb 05, 2011 5:00 pm    Post subject: [SOLVED!] GMER bad_pool_header system crash BSOD Reply with quote

Ok, I work with virus-infested computers and laptops a LOT. I would like to find a good tool that will reveal ALL folders/files. Some viruses use clever techniques in folder hiding. Like the program Ardamax - their keyloggers create a folder in system32 that if you don't know the name of it, you will not be able to find it through explorer (even if you go to folder options and uncheck "hide system files/folders".)

Any suggestions?

EDIT:

I posted a solution on this page below

_________________
Jesus loves you, Hitler! Smile

Playing/Embedding XM and MOD files in Visual Basic 6

.erutangis ruoy ni siht esu neht ,sdrawkcab siht daer ot hguone trams erew uoy fI
I can spell your name backwards: ‮Hitler


Last edited by Radiation on Thu Feb 17, 2011 11:27 pm; edited 1 time in total
Back to top
View user's profile Send private message
ipivb
Master Cheater
Reputation: 5

Joined: 29 May 2010
Posts: 256

PostPosted: Sat Feb 05, 2011 7:34 pm    Post subject: Reply with quote

Whenever I get a virus that bad, I pretty much resort to reinstalling windows.

Note I said reinstall, not reformat. If you have at least a few GB of hard drive space left, you can split the partition of your hard drive and reinstall windows on the new partition. Boot from that partition, and if you wish, copy all of your needed files over to the new partition and then delete it so you have one partition again. This way, you can keep all of your files without using an external hard drive or using tons of DVDs.

However, there are a few viruses which are so nasty, they will literally infect every single .exe on your computer (often causing them to not work anymore). This is rare, however, but in this case, you will have to ditch all of your .exe programs and redownload/reinstall them on a clean installation of windows.

A good program I'd recommend is WinPatrol. Instead of being the typical antivirus which scans programs and determines their danger based off of constantly updated signature (and more often than not, being unable to take any action against them), WinPatrol simply warns you whenever it detects a new startup program, registry entry, etc. It's nothing like UAC where it pops up all the fking time and doesn't give you any information. Instead it gives you the exact file name, and asks you whether to allow it or not.

Viruses are more commonly infecting through a somewhat fatal flaw of Java. Sometimes you will visit a website where it makes a Java popup asking if you want to run this application... the problem being that the popup doesn't look that suspicious, and sometimes it will keep asking until you click yes (sometimes accidentally). Which you are then infected.
Back to top
View user's profile Send private message
atom0s
Moderator
Reputation: 205

Joined: 25 Jan 2006
Posts: 8587
Location: 127.0.0.1

PostPosted: Sat Feb 05, 2011 8:48 pm    Post subject: Reply with quote

Helpful rootkit detection tool:
http://www.gmer.net/

_________________
- Retired.
Back to top
View user's profile Send private message Visit poster's website
Radiation
Grandmaster Cheater
Reputation: 14

Joined: 17 Jun 2009
Posts: 842
Location: Chernobyl

PostPosted: Sun Feb 06, 2011 3:21 pm    Post subject: Reply with quote

Wiccaan wrote:
Helpful rootkit detection tool:
http://www.gmer.net/


when I opened it, immediately, my computer crashed and auto-restarted.

_________________
Jesus loves you, Hitler! Smile

Playing/Embedding XM and MOD files in Visual Basic 6

.erutangis ruoy ni siht esu neht ,sdrawkcab siht daer ot hguone trams erew uoy fI
I can spell your name backwards: ‮Hitler
Back to top
View user's profile Send private message
atom0s
Moderator
Reputation: 205

Joined: 25 Jan 2006
Posts: 8587
Location: 127.0.0.1

PostPosted: Sun Feb 06, 2011 3:41 pm    Post subject: This post has 1 review(s) Reply with quote

If your system is currently infected it could be the virus itself attempting to prevent you from opening it. It's a fairly well known tool so it tends to land up on blacklists inside of viri frequently. I use it frequently for the hook detection and have no issues with it at all.

Perhaps you have something else conflicting with it too, what was the bluescreen message / stop code you got when you ran it?

_________________
- Retired.
Back to top
View user's profile Send private message Visit poster's website
Radiation
Grandmaster Cheater
Reputation: 14

Joined: 17 Jun 2009
Posts: 842
Location: Chernobyl

PostPosted: Sun Feb 06, 2011 4:48 pm    Post subject: Reply with quote

Wiccaan wrote:
If your system is currently infected it could be the virus itself attempting to prevent you from opening it. It's a fairly well known tool so it tends to land up on blacklists inside of viri frequently. I use it frequently for the hook detection and have no issues with it at all.

Perhaps you have something else conflicting with it too, what was the bluescreen message / stop code you got when you ran it?


hmm... no bsod, just an instant restart. i will enable the showing of bsod and tell you what message i get.

i have ESS 4 and Mbam running on my windows xp sp3 home edition. It crashes regarding if i turn the antivirus on or off. i also have sandboxie, i tried to open it, and to my surprise, it opened it...

yesterday my cousin brought an external hdd and i double-clicked some weird file. I think i'm infected... Sad

EDIT:

Just enabled the BSOD, ran GMER and...

nothing. A regular crash without a BSOD. I think something IS blocking it...

_________________
Jesus loves you, Hitler! Smile

Playing/Embedding XM and MOD files in Visual Basic 6

.erutangis ruoy ni siht esu neht ,sdrawkcab siht daer ot hguone trams erew uoy fI
I can spell your name backwards: ‮Hitler


Last edited by Radiation on Wed Feb 09, 2011 11:35 pm; edited 2 times in total
Back to top
View user's profile Send private message
atom0s
Moderator
Reputation: 205

Joined: 25 Jan 2006
Posts: 8587
Location: 127.0.0.1

PostPosted: Sun Feb 06, 2011 7:49 pm    Post subject: Reply with quote

Try renaming gmer's executable, or run the generated download on their page to see if you can get it to run under a different name.
_________________
- Retired.
Back to top
View user's profile Send private message Visit poster's website
Radiation
Grandmaster Cheater
Reputation: 14

Joined: 17 Jun 2009
Posts: 842
Location: Chernobyl

PostPosted: Mon Feb 07, 2011 6:01 pm    Post subject: Reply with quote

Wiccaan wrote:
Try renaming gmer's executable, or run the generated download on their page to see if you can get it to run under a different name.


hmm... no success... although, i was able to open it on another os. I have two harddrives in my computer, each one of them has an independent operating system. I opened GMER on the other harddrive's os (which is also win xp) and it worked!

Now, is there a way to scan for active rootkits on my FIRST harddrive while operating on the second harddrive?

EDIT:


I re-enabled the BSOD and it showed me:

"bad_pool_header"

EDIT2:

Just in case someone has the same problem, I have disabled the service named FsUsbExService by Samsung New PC Studio located in

Code:
C:\WINDOWS\system32\FsUsbExService.Exe


This solved all issues with GMER crashing or not loading. No more BSODs... Happy Me!!! Very Happy Very Happy

Thanks for all your help Wiccaan!

_________________
Jesus loves you, Hitler! Smile

Playing/Embedding XM and MOD files in Visual Basic 6

.erutangis ruoy ni siht esu neht ,sdrawkcab siht daer ot hguone trams erew uoy fI
I can spell your name backwards: ‮Hitler
Back to top
View user's profile Send private message
satanrules666
Advanced Cheater
Reputation: 0

Joined: 31 Oct 2010
Posts: 70
Location: New Zealand

PostPosted: Tue Mar 08, 2011 10:31 am    Post subject: Reply with quote

you can use event manager to see bsod messages instead of waiting to see a bluescreen that may disapear when ya pc restarts

o see you can spell my name backwards

somehow on here im hated just for having a name such as satanrules666 who would have thaught ae

as for viruses and all i always have my blackbox my 1 terabyte external sata 2 seagate drive which was a old hard drive of mine i had siting around and that contains everything to date not connected to the net and i scan everything i use theres always a false positive with a trainer though

i can normally tell if i have a virus just from decrease in proformance

anyway i use windows live essentials why you ask this is the only anti virus i dont get a bsod from seems my sapphire hd5850 hates old games and it hates antivir

much in the same way i am hated lol

_________________
I know you're reading this, Jiehfeng. Smile


http://forum.cheatengine.org/viewtopic.php?t=533625
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites