My computer wont finish the root Repeal scan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tonymiggs, Oct 14, 2011.

  1. tonymiggs

    tonymiggs Private E-2

    My computer is acting strange...It freezes up and will not respond, when I use Opera or Mozilla. I try to end the process of the non responding program in task manager, it doesnt respond I have to reboot my system...in order to end the process of the not responding programs..I have followed all your steps, however the root repeal freezes on the last drive...and never completes the scan or give a scan report . I thank you in advance for any help that may give.
     

    Attached Files:

  2. tonymiggs

    tonymiggs Private E-2

    I almost forgot the Mbam log...thanks again
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may not be having malware problems, but let's run a couple of additional scans.

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller

    Now [lease also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  4. tonymiggs

    tonymiggs Private E-2

    Here are the results
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One item of possible concern in your MBRcheck log is he below:
    Code:
     
        279 GB  [URL="file://\\.\PhysicalDrive0"]\\.\PhysicalDrive0[/URL]   Unknown MBR code
    
    This does not necessarily mean you MBR is infected. It could just be due to a special MBR that your PC manufacturer installed to allow for a factory recovery partition. However normally MBRcheck recognizes HP MBRs.

    Since you are have problems with your PC, it may be a good idea to repair your MBR to see if it is the problem. So we need to ask a few of questions.

    1. Do you have all of your important data backed? You need to do this before continuing. While fixing the MBR typical works without a problem, it still could potentially render a PC unbootable if something goes wrong.... especially if malware is the problem.
    2. Do you have your Windows XP boot CD so that we can use it to boot into the Recovery Console to fix the MBR?
    3. Do the freeze up problems only occur with Opera and Firefox? Does Internet Explorer work without a problem? Does it ever freeze while using other programs if you don't open any browsers?
     
  6. tonymiggs

    tonymiggs Private E-2

    Yes I have my important data backed up, I also have the boot cd...internet explorer works fine...it only freezes up when using opera and mozilla...
     
  7. thisisu

    thisisu Malware Consultant

    Hi,

    chaslang has asked me to help you while he is busy with other projects at the moment.

    Do you have your Windows XP CD? We need it to restore a clean MBR.
    If you do not have your Windows XP CD, you can create one with the Recovery Console (which is really all we need), here: Download Windows XP Recovery Console

    Then see if you can boot from this CD and get into the Recovery Console. See the second section in the below link where it says "How to use the Recovery Console"

    http://support.microsoft.com/kb/307654

    If you can get to the command prompt of the Recovery Console, type fixmbr and hit enter. After it finishes type exit to reboot and remove the CD to allow Windows to boot normally.

    If you were able to run fixmbr, rerun MBRCheck and attach a new log. Also tell me how things are working.
     
  8. tonymiggs

    tonymiggs Private E-2

    Hi thisisu and chaslang...I tried to repair the mbr...but it failed and give me this error cooo0218 Registry File failure...next I tried to update IObit...unsuccessful... it would always go the IE and stall ...blank screen... so I decided to uninstall IObit since I dont recall installing on my puter..then I tried to uninstall opera...and Panda AV give this message...Blocked...Dangerous operation detected..Rule 5002...I google Rule 5002...and found this...

    Rule 5002: During normal behaviour, Web browsers shouldn’t need to execute administration, network or command shell tools. If you receive an alert, some kind of vulnerability is being exploited.

    and it goes on to say how PCAV blocks adobe 0-day

    the video link below
    http://vimeo.com/12449415

    I found the problem...Now I'm dependin on your expertise for the solution...thanks in advance for your help!!
     
  9. thisisu

    thisisu Malware Consultant

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not if he got a STOP: c0000218 {Registry File Failure} error. He was running Windows and did not boot to the Recovery Console. ;)
     
  11. tonymiggs

    tonymiggs Private E-2

    Any suggestions would be helpful...Thanks again
     
  12. thisisu

    thisisu Malware Consultant

    Make sure you have your Windows XP cd in the Cd/DVD-Rom drive.
    Now reboot your system.
    At the HP splash screen (screenshot below)
    [​IMG]
    Press the Esc key on your keyboard.
    This takes you to the Boot Menu
    Select your Cd-DVD rom device and press ENTER
    Be ready to press ANY KEY ON THE KEYBOARD (multiple times if you'd like) when you see the following:
    [​IMG]
    You should start hearing the CD in your CD-rom drive tray spinning up, be patient while the Recovery Console loads.
    From there:
    1. When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
    2. If you have a dual-boot or multiple-boot computer, select the installation that you must access from the Recovery Console.
    3. When you are prompted, type the Administrator password. If the administrator password is blank, just press ENTER.

    If you can get to the command prompt of the Recovery Console, type fixmbr and hit enter. After it finishes type exit to reboot and remove the CD to allow Windows to boot normally.

    If you were able to run fixmbr, rerun MBRCheck and attach a new log. Also tell me how things are working.
     
  13. tonymiggs

    tonymiggs Private E-2

    As I previously said before....

    .I tried to repair the MBR...but it Failed and give me this error cooo0218 Registry File failure...next I tried to update IObit...unsuccessful... it would always go the IE and stall ...blank screen... so I decided to uninstall IObit since I dont recall installing on my puter..then I tried to uninstall opera...and Panda AV give this message...Blocked...Dangerous operation detected..Rule 5002...I google Rule 5002...and found this...

    Rule 5002: During normal behaviour, Web browsers shouldn’t need to execute administration, network or command shell tools. If you receive an alert, some kind of vulnerability is being exploited.

    and it goes on to say how PCAV blocks adobe 0-day

    the video link below
    http://vimeo.com/12449415

    I found the problem...Now I'm dependin on your expertise for the solution...thanks in advance for your help!!
     
  14. thisisu

    thisisu Malware Consultant

    Please explain what you tried to do in order to repair the MBR.
     
  15. tonymiggs

    tonymiggs Private E-2

    I placed the factory Windows XP CD...in the drive...and followed your instructions...rebooted the computer and when the black windows came up...I pressed esc...switch the primary booting to CD-dvd Rom...Welcome to Setup screen appears with three options...I choose "R" for recovery....then a blue screen appears...sayin "Error Cooo0218 Registry File failure"...I tried repeat the process 4 times...

    10-29-11, 00:43
    chaslang MajorGeeks Admin - Master Malware Expert Join Date: Feb 2004
    Location: Northern New Jersey USA
    Posts: 71,604
    Thanks: 45
    Thanked 5,059 Times in 2,469 Posts

    Re: My computer wont finish the root Repeal scan

    --------------------------------------------------------------------------------

    Quote:
    Originally Posted by thisisu
    Were you able to boot off the Windows XP CD enter the Recovery Console?

    Not if he got a STOP: c0000218 {Registry File Failure} error. He was running Windows and did not boot to the Recovery Console.
     
  16. thisisu

    thisisu Malware Consultant

    I think either I am misinterpreting what chaslang said or you are. I am taking it as you are getting a BSOD because you are still running in Windows (on the hard drive), and NOT on the recovery console (CD-rom drive).

    I have never seen anyone get a Registry error BSOD while using a CD.

    I am just hoping you are not still using the built in Recovery Console (the one on the HDD)

    However, since you are apparently not able to use the above methods, give this one a try:

    [​IMG] Please download aswMBR by Avast! to your desktop.
    • Double-click aswMBR.exe to run it (Vista and Win7 right-click and select Run as Administrator)
    • Select No when asked Would you like to download latest Avast! virus definitions?
    • Click the [FixMBR] button.
    • Follow the prompts and reboot as requested.

    Once you are back into Windows, rerun MBRCheck and attach its latest log.
     
    Last edited: Nov 3, 2011
  17. tonymiggs

    tonymiggs Private E-2

    I download the AswMBR...applied the MBRfix..and It wouldnt even load up windows...It would automatically go the BSOD and give the same REGISTRY failure code as before...so I had no choice but to reformat my drive...or "F" (sigh)...I downloaded malwarebytes , panda free av and superantispyware...it superantispyware caught what looked like the same viruses and quarantined them...Now I want make sure the computer is totally clean from any infection
     
  18. thisisu

    thisisu Malware Consultant

    Ok, thanks for the heads up.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds