Author Topic: Help needed  (Read 4312 times)

0 Members and 3 Guests are viewing this topic.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Help needed
« on: December 12, 2013, 09:11:47 PM »
Hello,

So I literally just got home from school to find my computer in a horrible mess. It wasn't booting up at first, seems to work now. Windows Startup Repair saved the OS and my files. However, I would like to know why my computer crashed like that. I haven't had it crash in nearly a year since I owned it.

Is their any kind of file kept or anything that I can post for someone to look at?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Help needed
« Reply #1 on: December 12, 2013, 09:58:43 PM »
There could be something wrong with system files or some updates broke the system.

Best is that you make backups at least of your personal data or better an ISO-Image of the whole system.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Help needed
« Reply #2 on: December 12, 2013, 10:16:31 PM »
Yeah, I scanned with OTL. There are tons of .sys and other files within system32...
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Help needed
« Reply #3 on: December 12, 2013, 10:17:31 PM »
Please attach that log here and wait for an expert.

He knows how to deal with this.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Help needed
« Reply #4 on: December 12, 2013, 11:28:59 PM »
That log was produced with a Quick Scan. Not the usually one
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help needed
« Reply #5 on: December 12, 2013, 11:30:01 PM »


Please download aswMBR and save it to your desktop.

Double click aswMBR.exe to start the tool.
  • Select Yes if prompted to download the Avast database.
     
  • Click Scan
     
  • Upon completion of the scan ( Scan finished successfully ) click Save log and save it to your desktop, and post that log in your next reply for review.
    Note: do NOT attempt any Fix yet.


Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help needed
« Reply #6 on: December 12, 2013, 11:34:05 PM »
OTL log does not tell me anything that would cause the error in the system. When you deliver me the aswMBR log then we shall see what to deploy next.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Help needed
« Reply #7 on: December 12, 2013, 11:35:15 PM »
Log attached. I can format IF needed. I do have a MAK key plus a win 7 HP SP 1 64
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help needed
« Reply #8 on: December 12, 2013, 11:38:07 PM »
This is Windows 8.1 system?


Edit:
I'll need to look at deeper then aswMBR can go ...


Please download GMER, the RootKit Detector tool from the link below and save it to your Desktop:

Gmer download link
Note: file will be random named

Double-clicking to run GMER.
  • Wait for initial scan to finish - if there is any query, click No;
  • Click [ Scan ] button and wait until the full scan is complete;
  • Click [ Save ... ]- save the report to the Desktop (named ARK );

  • Then click the >>> button and select Autostart card;
  • Click [ Scan ] button;
  • After quick scan, click Copy button;
  • Open notepad and Paste text. Save report to the Desktop (named autostart )
> Attach here both Gmer logreports. (ARK.txt and autostart.txt)

« Last Edit: December 12, 2013, 11:39:55 PM by magna86 »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Help needed
« Reply #9 on: December 12, 2013, 11:40:17 PM »
incorrect. It's windows 7 Home Premium Service Pack 1 64 bit. However, the original OS was Windows 8.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help needed
« Reply #10 on: December 12, 2013, 11:42:06 PM »
Ok. As I was sow the GPT partition and Windows 7 in logs so I wanna to confirm.

Please run GMER if you will for additional ARK scan.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Help needed
« Reply #11 on: December 12, 2013, 11:44:48 PM »
Hey,

I got some unknown MBR code. I'll attach a ScreenShot of another error I got
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help needed
« Reply #12 on: December 12, 2013, 11:49:34 PM »
Is that from initial scan? If so, just press Scan button ...

If this is final results, just press Save button and save notepad as ARK.txt on Desktop and attach or paste the log here.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Help needed
« Reply #13 on: December 12, 2013, 11:55:33 PM »
Initial Scan.

However, I just tried to scan and it hit something and I blue Screened. Should I try Safe Mode? Or do you have something else?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help needed
« Reply #14 on: December 13, 2013, 12:06:39 AM »
Initial Scan.

However, I just tried to scan and it hit something and I blue Screened. Should I try Safe Mode? Or do you have something else?

That's Ok. You're get BSOD as GMER trying to load it's driver into kernel. Probably the driver has hooked something ..
GMER and aswMBR shows "unknown MBR" flag as you do not even have MBR partition type on your system. You have GPT type that is came with origin Win8.

OTL doesn't show malware or somting like, therefore you may remove OTL and it's files by clicking CleanUp! button.