Author Topic: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2  (Read 22524 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #30 on: July 25, 2012, 09:08:59 PM »
Sorry yes run it from the OTLPE as the malware is blocking any programme run from normal windows

DreaMzzy

  • Guest
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #31 on: July 25, 2012, 09:50:03 PM »
Here comes tha log from Listpart..

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #32 on: July 25, 2012, 09:52:31 PM »
Could you now go to normal windows please

Then run TDSSKiller

DreaMzzy

  • Guest
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #33 on: July 25, 2012, 10:02:51 PM »
Here comes the report from TDSSkiller which i copied to notepad.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #34 on: July 26, 2012, 12:28:25 AM »
OK we beat it

How is the computer behaving now ?

DreaMzzy

  • Guest
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #35 on: July 26, 2012, 07:51:50 AM »
Great! Its much better now i think. Are there any virus/malware och virus-deseased files on my computer now?

The program maps on my start menu are there, but they are all empty.. Could I remove all the programs Installed and the files/maps created on my C-drive like C:\_OTL, C:\Qoobox, C:\TDSSKiller_Quarantine, C:\FRST, C:\Gotcha, C:\FRST.exe? and maybe some  more files..

Should I do anything more to get everything back to normal?

Thank you for all the help, a great THANKS to you!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #36 on: July 26, 2012, 01:30:08 PM »
Essexboy will give you advice on the removal of the tools and general advice for the future.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #37 on: July 26, 2012, 04:20:32 PM »
OK lets get the menus back where we can, I will remove all the programmes when you are happy 

But first lets check the bad partition has gone, if not you can delete it  ;D

Go Start > Run
Type in the following and press enter:

diskmgmt.msc

This will open the disc management console
Look at the partitions is there a second one of 10Mb size ?
If so then right click that partition and select delete

MENUS

Restore Accessories Program Files Menu 
 
Please download this tool [here
 
You will need to unzip the tool first. 
 
Once you've unzipped the tool, please double-click on it to run it. 
 
Ensure that the following check boxes are checked (as seen in this image below): 
 


 
Once they are, click on the Restore button.
 
 
 
Restore Admin Tools Program Files Menu 
 
Please download this tool here[/color]
 
You will need to unzip the tool first. 
 
Once you've unzipped the tool, please double-click on it to run it. 
 
Click on the Restore Administrative Tools Items button. 
 
As seen in this image below: 
 


 
This next one will produce the necessary shortcut links which you can cut and paste into the start menu folder
Download the repair.vbs file to your destop
Run the repair.vbs
It will ask for a folder name call it recovery
The tool will let you know when it is finished
On the desktop will be a recovery folder 
Open the folder
Cut and Paste the links that you want to C:\documents and settings\your name\start menu






DreaMzzy

  • Guest
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #38 on: August 19, 2012, 09:31:15 AM »
Hi,

I have been away on holiday for the last three weeks but now Im back.

I only have one partition left, which looks okay. The restore accessories program ran without any problem. When I ran restore admin tools I got an error message, and same happened with repair.vbs (see attachment). Can you help me out?

DreaMzzy

  • Guest
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #39 on: August 23, 2012, 09:14:28 PM »
Are there anyone that can help me to finish this?

DreaMzzy

  • Guest
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #40 on: August 26, 2012, 10:16:37 AM »
Why I didnt tell you that I was going away for three weeks was of security reasons and not of being impolite.

I saw that the language in the picture I attached was in Swedish and here comes the translation for the Rapair.vbs message:

Script: C:\Documents and Settings\Jonas\desktop\Rapair.vbs
Line: 36
Letter: 4
Fault: Could not find the given path
Code: 800A004C
Source: Run error in Microsoft VBScript


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #41 on: August 27, 2012, 01:40:31 PM »
I will need to talk to the Author on that one

What are the current problems ?

DreaMzzy

  • Guest
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #42 on: August 27, 2012, 07:27:10 PM »
I just want to remove all the files and programs that are not necessary anymore and want the missing shortcuts in the start meny to be there again.

I also want to know if I can do a check to know that everything on my computer is all right. It is much slower than i think it was before and its not because I have so many demanding programs and a full drive (only used 90GB of 500GB). Can I check that?

A little thing more is that I got a "black picture" when Im starting the computer asking if I want to start windows XP and one other option, but its just there fo 2 seconds. I this thing is because of the installation of Listpart or some of the other programs.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #43 on: August 27, 2012, 07:45:35 PM »
OK lets remove my programmes first.  I have just run repair.vbs on my system and it worked perfectly.  Could you try it once more please   

Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :Commands
    [resethosts]
    [emptytemp]
    [CLEARALLRESTOREPOINTS]
     [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
Remove ComboFix
  • Hold down the Windows key + R on your keyboard. This will display the Run dialogue box
  • In the Run box, type in ComboFix /Uninstall
     (Notice the space between the "x" and "/")
    then click OK



  • Follow the prompts on the screen
  • A message should appear confirming that ComboFix was uninstalled
Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself. 

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.
   Your Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

 Upgrading Java:
  • Go to this site  and click Do I have Java
  • It will check your current version and then offer to update to the latest version
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

Malwarebytes.

Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ?Keep safe  :wave:

DreaMzzy

  • Guest
Re: Virus: Please help me to remove MBR:\\.\PHYSICALDRIVE0\Partition2
« Reply #44 on: August 27, 2012, 09:13:11 PM »
I still dont get repair.vbs to work, same message that the picture shows that I attached in an earlier message.

The black screen with white text in the startup with a question to start from windows XP is still there, do you know how to get it away?

The shortcuts in the start meny are still missing. I guess i can try to add them manually from the explorer.

What about the picture you attached from you program map?