RootRepeal stuck on "Initializing, please wait..."?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by amym, Jan 17, 2010.

  1. amym

    amym Private E-2

    Hi, I just want to make sure that while I'm waiting for this scan to run that it is actually running and not just hung up somewhere!

    I've got a window w/in the RootRepeal window that says "File Path" - this is blank. Under that it says "Initializing, please wait..."

    At the very bottom of the RootRepeal screen it says "Scanning for hidden/locked files..."

    The computer is making no noise (all the other scans so far have made noise indicating they are doing something).

    *I am patient and have no problem waiting, I just want to make sure something is actually going on!

    Thanks so much, Amy
     
  2. amym

    amym Private E-2

    Awwww...my first virus....win32.netsky worm

    I committed the cardinal sin of clicking on a link in an email from someone I don't know. I didn't think I was doing anything wrong - it was a reply to an item I put up for sale on Craigslist, I thought they were trying to tell me the item was recalled or something....anyway, that's what I get for thinking. So, it was either this or something I picked up on Facebook - went there for the first time to check out some pictures a friend wanted me to see, got lost, started clicking on all kinds of things, people I know but hadn't heard from in forever.

    So, all these warnings about not being protected, being infected started popping up, including a window that kept starting to scan everything - Internet Security 2010. Then my desktop went neon green with a black box saying I had (have) a virus. I kind of panicked and I'm not sure what all I clicked because I couldn't tell what was legit and what was not.

    I followed the FAQ, cleaned what I was told to, downloaded what I was told to, ran what I was told to. I only had problems with RootRepeal, it kept getting hung up on initializing and then everything froze - I had to push the button to turn off the computer. I tried unzipping again and ran it again - same thing.

    So, now I will try to attach my logs.....

    I need to go find the SuperAntiSpyware and MalWareBytes logs and I'll be back to post them. What should I do about RootRepeal?

    Thanks so much in advance for any help anyone can give, Amy
     

    Attached Files:

  3. amym

    amym Private E-2

    Re: Awwww...my first virus....win32.netsky worm

    OK, here are my other 2 logs.....

    Thanks again:)
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Amy :)

    RootRepeal seems to only have a 50/50 chance of running on machines... so simply attach what logs you do have from running the rest of the tools.
     
  5. amym

    amym Private E-2

    Thanks Kestrel13. I started a new post explaining my problem with all logs (minus RootRepeal:)) attached.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Merged now to keep things tidy.

    I'll review your logs and give a set of instructions in my next post :)
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    2. Please go to add/remove programs and uninstall he following out of date version of java:

    Java(TM) 6 Update 15

    3. Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    4. Were you once using symantec as anti-virus but are now using avast? If so then there has been an incomplete uninstallation of the software and a removal tool needs to be run in order to clear all traces of it:

    Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    5. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6


    6. Now tell me how your computer is behaving since running the scans and since completing the above.

    Thanks
    Kes13!
     
    Last edited: Jan 18, 2010
  8. amym

    amym Private E-2

    Wow - thank you so much for taking the time to not only help me but to be so detailed and to provide links. Really awesome :)

    I did everything you outlined. No idea about Messenger, I've never used it, but it's gone now. Bad Java switched out for good Java. Got a success message for #3. I did use Norton a very long time ago, switched to AVG but then I think that started giving me grief last year so switched to AVAST. I did use the Norton removal tool originally, but it must've missed something the first time around. Did it 2x like you instructed.

    Everything seems to be back to normal :) I won't have much of a chance to really use my computer much till tomorrow so I'll know more then.

    Thank you so much Kestrel13!, I really appreciate the help! Amy
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Just let me know as soon as possible and then I can give you final steps to follow :)
     
  10. amym

    amym Private E-2

    Everything seems to be running normally except that each time the computer has been idle for awhile the cursor freezes and it takes about 20-30 seconds before I can use the mouse or keyboard. Not really a huge deal, just a change and a bit annoying.

    Thanks again Kestrel13!

    Amy
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not a malware problem and also not caused by any of the tools we ran here. You can take this up in the software forum :)

    Glad things are running okay apart from this. Now you can follow the final steps.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds