Problems with Root Repeal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by M_Logan, Aug 5, 2009.

  1. M_Logan

    M_Logan Private E-2

    I've run through the procedures a number of times on different computers, and this is the first time I've had this particular problem.

    On the computer in question - a Compaq laptop, precise specs unknown, running Vista 32bit - after running Root Repeal, I now have a 'Windows Explorer has stopped working' error popping up -constantly-. Nothing can be done with the computer, and I have tried running system restore to before I started working. I've also tried safe mode - still no dice.

    What I need to know is, just how badly am I screwed, and is there any way to fix this without doing a full factory reset? The computer in question is not mine, and contains a fair number of pictures and other data that will be difficult if not impossible to replace. I hate being the local tech guru sometimes...
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you open task manager and start a new process....type in explorer and what do you get?

    What exactly can you do? Does it boot to a user account? You need to explain exactly what is happening.
     
  3. M_Logan

    M_Logan Private E-2

    Okay, here goes.

    Yes, I can boot to a user account, and yes, I can launch task manager by doubling ctrl/alt/del to bring up the corresponding menu. The user account has admin-level perms. As for what I can do - not a lot. I can't use the touchpad to click things, keyboard shortcuts don't seem to work (aside from the aforementioned CAD), and context menus do not appear on right click or using the keyboard button.

    Starting the Explorer task as you suggested works; it brought up Documents and seems to have stabilized things. I'm in the process of checking to see if this has fixed the problem... Taking a little while because the computer apparently downloaded an update. (I usually turn off auto update because a large proportion of Microsoft's updates for Vista seem to break things.) I'm not entirely sure, but this is taking far too long and on the heels of everything else, I don't trust it. Going to rerun scans when this is done. If it doesn't somehow manage to destroy the hard drive.

    At any rate, this at least means that I can save the documents and other files if I do need to make it a full wipe. Not that I'm fond of the idea of using my own comp to store potentially infected files, but needs must. I'm somewhat unconvinced that a wipe will help, though, since system restore does not seem to have done anything for it.

    Sorry it took me so long to reply.
     
  4. M_Logan

    M_Logan Private E-2

    Update: I killed the Windows Update that was running by shutting down; I figured if it had been trying to install the same one for thirty minutes, it probably wasn't going to work.

    Before shutting down the computer, I deleted a settings.dat file from the desktop which (I assume) was part of RootRepeal; this was the only change I made. Either that or restarting the Explorer process last time must have done the trick, everything is working now. I'm in the process of re-running scans, and will post logs when finished.
     
  5. M_Logan

    M_Logan Private E-2

    Okay, that didn't turn out so well. svchost is taking up half of the processor (it's a dual core), and I can't run any of the installers. I sense something rotten in the general vicinity of Denmark, here. I've tried killing the process, but it pops right back up. I used process explorer to do -something- else to it (stopping it without killing it, I can't remember what the option was called), and that freed up the processor, but I still couldn't install anything. Can't install in safe mode, either. I'm wondering if I can get system restore to run me back to -after- I had everything installed. Hmm... I'll try that in the morning, I guess.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Neither ComboFix or MGTool require an installation. I can't help you without being able to see what is happening in your system.
     
  7. M_Logan

    M_Logan Private E-2

    Apologies for taking so long, but the computer was out of my possession.

    Attached are the logs I was able to obtain. Some of them may be incomplete - MGTools, in particular, was having issues with running completely through.

    The biggest issue at present is an svchost.exe process which is taking up fully half of the processor time, and when mgtools tries to run, it seems to kick off - just long enough for mgtools to start running.

    One of the 'programs' installed was PC Confidential, which I'm guessing is viral based on just how hard it is to get rid of.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are running Vista with only 1 gig of memory. Not enough! You need at least 2 gigs to run properly:
    Total Physical Memory 958.00 MB
    Available Physical Memory 173.64 MB ---> what is left over to use!

    Second, you are missing a lot of system files:
    You may be able to fix this by installing SP1. Or you may just have to save your personal data and files and do a repair installation. If that doesn't work, then a full re-installation.

    We can clean up a few mon malware related items. But your main issues are the above.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    c:\program files\iMesh Applications

    Let me know what you want to do.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds