BleepingComputer.com: gmer error when scanning

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

gmer error when scanning followed prep guide

#1 User is offline   kurtunes 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 18
  • Joined: 09-January 12

Posted 10 January 2012 - 01:34 PM

I just posted and forgot to preface with my original concern before contacting bleeping computer. here is original concern:

When I start xp before desktop loads completely a small black box pops up quickly then dissapears. Seems to say windows\system32\cmd.exe Happens so quickly hard to read everything. I've tried print screen but to fast for me to catch. When desktop loaded I haven't noticed any problems with PC but am concerned as fear a virus. Have run different virus programs and disc check,etc. It does not happen when booting in safe mode. I forgot to mention that I already tried that and actually unchecked all startup boxes as there was no cmd.exe and it still happened when starting? I did go to run regedit and there are several cmd.exe but didn't alter as afraid it might screw up PC. Not sure if it is a virus as really haven't had any problems with PC running
prgrams,etc..


I followed instruction from Prep guide and attained logs requested dds & attach. Then ran into error after scanning gmer which is where I'm at a standstill. I'll attach dds and attach files.

Have been following instructions and succesfully saved DDS and attach file. I was then to run gmer scan after file. Did disable CD emulation as suggested. Heres what happened with gmer.



(after running gmer scan for 3 hours I could see that it had scanned tons of stuff but then this message came up.)

Windows was unable to save all the data for the file\$Directory.The data has been lost.This error may be caused by a failure of your computer hardware or network connection. Please try to save this file elsewhere.

Then this message came up.

The instruction at "0x7c9501b6" referenced memory at "0x6807f864". The required data was not placed in memory because of an i/o error status of "0xc000009a" click on ok to terminate program or cancel to debug.


(I wasn't sure what to do but was scared to terminate so I clicked debug and computer rebooted and the scan program was not up and running. Now what?)

Attached File(s)

  • Attached File  dds.txt (12.81K)
    Number of downloads: 1
  • Attached File  attach.txt (14.56K)
    Number of downloads: 0


#2 User is offline   kurtunes 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 18
  • Joined: 09-January 12

Posted 10 January 2012 - 08:26 PM

I tried disabling internet, antivirus, and windows firewall then running gmer scan again. Had similar results. Seems to work great and scans for

hours - then message came up. the error box had a heading of "lxeecoms.exe-application error" I clicked O.K. and another error "windows delayed write failed" more similar error boxes and after clicking o.k my PC rebooted. I was never able to save what had scanned as wouldn't let me because error boxes.


The errors below are ones I posted from previous scan and same similar content came up even after disabling antivrus,etc.

Windows was unable to save all the data for the file\$Directory.The data has been lost.This error may be caused by a failure of your computer hardware or network connection. Please try to save this file elsewhere.

Then this message came up.

The instruction at "0x7c9501b6" referenced memory at "0x6807f864". The required data was not placed in memory because of an i/o error status of "0xc000009a" click on ok to terminate program or cancel to debug.

#3 User is offline   kurtunes 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 18
  • Joined: 09-January 12

Posted 11 January 2012 - 08:11 AM

The problem I originally contacted bleeping computer about was a suspicious black box coming up for a split second on desktop when PC almost booted up. I original was getting help from the "am I infected forum" about my problem of a black box with c:\Windows\system32\cmd.exe flashing open for a second on bootup. I was never able to catch it with print screen but finally did. Not sure if it will help but I attached the saved printscreen of what is popping up.Attached File  Windows system32cmd.exe black box.zip (120.24K)
Number of downloads: 1 Also when in the "am I infected forum" I was instructed to run several troubleshooting programs which led them to suggest going to this forum. One question I have is that in the autoruns results which I saved after running program, on the 6th line down the following was:
+ "cmd.exe" "" "" "File not found: cmd.exe" ( you will see this on the 6th line down on the autoruns file I attached.Attached File  AutoRuns.txt (104.14K)
Number of downloads: 1Being as the black box popping up has cmd.exe included in it could this be part of the problem. Anyways, hope this helps in some way. I really have had no issues so far other that the black box flashing up on bootup but it has never done that and am a little nervous it could turn into something undesirable. Thanks in advance for all your help!

#4 User is online   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,061
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 16 January 2012 - 11:10 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
===

This may be the culprit.

uRun: [Bomgar_Cleanup_ZD82226874038] cmd.exe /C rd /S /Q "c:\documents and settings\all users\application data\bomgar-scc-4e83292b" & reg delete hkcu\software\microsoft\windows\currentversion\Run /v Bomgar_Cleanup_ZD82226874038 /f

Open your task manager and disable this startup Bomgar_Cleanup_ZD82226874038

Restart the computer normally.

How is it now?

#5 User is online   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,061
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 22 January 2012 - 10:09 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users