MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 05-04-09, 20:36
sithspawn sithspawn is offline
Private E-2
 
Join Date: Apr 2009
Location: Seattle, WA
Posts: 1
Thanks: 1
Thanked 0 Times in 0 Posts
Default Virus Scan blocks bo:heap

Hi,

McAfee's Virus Scan Enterprise 8.0 started giving me a buffer overrun error block bo:heap (the error occurs with Internet Exploder and Outlook). I tried running the scan, but it seems that the database is out of date, and attempting to update the software doesn't seem to work...it says it does, but when I check the database date, it still says February 2009??? WTF. Anyway, I ran SAS to see if that helped, it found a bunch of trojans and some virtual dns stuff. I cleared that out, but the problem didn't go away. I tried running SpyBot, and it found a couple trojans, but the problem persisted. I decided to run through your Read and Run Me First, so without further ado, here are the logs.

BTW, everything seems to be OK at the moment, but I'd like to have the logs looked over to make sure everything is good to go. Thank you!
Attached Files
File Type: txt ComboFix 5-4-09.txt (12.5 KB, 4 views)
File Type: txt mbam log 5-4-09.txt (973 Bytes, 4 views)
File Type: zip MGlogs.zip (88.2 KB, 3 views)
File Type: log SASLog 5-4-09.log (584 Bytes, 4 views)
Reply With Quote
Sponsored links
  #2  
Old 05-08-09, 02:01
dr.moriarty's Avatar
dr.moriarty dr.moriarty is offline
Malware Super Sleuth
 
Join Date: Nov 2007
Location: Spying on 221b Baker St.
Posts: 4,765
Thanks: 143
Thanked 518 Times in 501 Posts
Default Re: Virus Scan blocks bo:heap

Welcome to MajorGeeks!

I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

Thanks for your patience.
dr.m
__________________
"Education never ends, Watson.... It is a series of lessons, with the greatest for the last."
Free malware removal from MajorGeeks
Support MajorGeeks!
Reply With Quote
The Following User Says Thank You to dr.moriarty For This Useful Post:
sithspawn (05-08-09)
  #3  
Old 05-12-09, 08:12
dr.moriarty's Avatar
dr.moriarty dr.moriarty is offline
Malware Super Sleuth
 
Join Date: Nov 2007
Location: Spying on 221b Baker St.
Posts: 4,765
Thanks: 143
Thanked 518 Times in 501 Posts
Default Re: Virus Scan blocks bo:heap

Hello, sithspawn

*Just some tidying up left to do.

I strongly recommend that you clean up your Desktop immediately leaving only links. Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least it can have an effect on your PCs performance.

*Comment: Giving all users of this pc "Adminstrator Accounts" is bound to lead to problems.

Step 1:
Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
Quote:
Java 2 Runtime Environment, SE v1.4.2_03
Java(TM) 6 Update 11
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Spybot - Search & Destroy 1.4
Viewpoint Media Player
Step 2:
Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


Step 3:
Open Ccleaner - select "Cleaner" > "Run Cleaner" <---use this ONLY

Step 4:
Now install the latest Sun Java Runtime Environment

--------------------------------------------------------

After taking care of that - it is time to do our final steps:
Quote:
  1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
  2. If we had you use ComboFix, uninstall ComboFix (=This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    • "%userprofile%\Desktop\combofix" /u
      • Notes: The space between the combofix" and the /u, it must be there.
      • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    • Delete the C:\combofix folder from combofix (if it exists)
  3. If we had you run Avenger, you can delete all files related to Avenger now.
  4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
  5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
  6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
  7. Go to add/remove programs and uninstall HijackThis.
  8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
  9. If you are running Vista, Windows XP or Windows ME, do the below:
    • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    • Then reboot and Enable System Restore to create a new clean Restore Point.
  10. After doing the above, you should work thru the below link:
Safe surfing!
__________________
"Education never ends, Watson.... It is a series of lessons, with the greatest for the last."
Free malware removal from MajorGeeks
Support MajorGeeks!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Virus blocks ComboFix. Please Help zildjian03 Malware Removal 10 01-27-09 18:07
bo:heap? wamniomniye Software 3 06-06-08 09:50
Virus barrage blocks all Internet access... Nekojin Malware Removal 18 08-16-06 20:49
Colored blocks with ghosts,Virus???HJT LOG tubo Hardware 1 04-30-06 21:04
Virus blocks access to HJT, REGEDIT, TManager, Housecall and others. Need Help! undomiele Malware Removal 3 05-01-05 22:50


All times are GMT -5. The time now is 20:51.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger