Author Topic: MBR : \.\\PHYSICALDRIVE0\PARTITION2  (Read 15890 times)

0 Members and 1 Guest are viewing this topic.

willo.c

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #30 on: April 03, 2012, 10:34:41 PM »
Jeff,

Remember the process services.exe is still running and it takes almost all my cpu, at least in Normal mode.
In safe mode i cannot disable completly my antivirus.. And it is always difficult to run something..

I try to do the steps you kindly suggest me..
I keep you informed..

willo.c

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #31 on: April 03, 2012, 11:57:42 PM »
Jeff..

Here the log of the last scan..
I have not finished the ESET Online Scan (50%), i will rescan my computer tomorrow..

Anyway i attached the results..

jeffce

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #32 on: April 04, 2012, 03:10:17 AM »
Quote
i will rescan my computer tomorrow..
Ok let me know.  :)

willo.c

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #33 on: April 04, 2012, 10:00:45 PM »
Jeff,

finally we have a Eset log... It is attached..
In the previous post you can find the Malwarebytes log..

Are we close to the solution??  :P :P

Thanks

jeffce

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #34 on: April 04, 2012, 10:04:08 PM »
Hi,
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
Code: [Select]
File::
C:\Documents and Settings\Willy\My Documents\Download\SoftonicDownloader76569.exe
C:\Documents and Settings\Willy\My Documents\Download\Windows-Media-Player-Firefox-Plugin-1-0-0-8-Italian.exe
C:\Documents and Settings\Willy\My Documents\Programmi LEP\Nero.v.8.1.1.0 .exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.



  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
----------

In your next reply please attach the new ComboFix log and let me know how things are running now?  :)

willo.c

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #35 on: April 04, 2012, 10:33:47 PM »
Here the new Combofix log..

There still is the process Services.exe that take the 90% of my CPU.. This is the only problem, i think...

willo.c

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #36 on: April 05, 2012, 11:28:58 AM »
Jeff,

Any other suggestions to stop this process?

jeffce

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #37 on: April 05, 2012, 01:31:44 PM »
Hi,

Let's get a fresh scan and try to see what is using all that...

Run a new scan with OTL
In Custom Scans/Fixes put the following:

netsvcs

Press the Run Scan button and attach the logs created. 

willo.c

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #38 on: April 05, 2012, 02:29:05 PM »
Here the OTL log done in Safe Mode, because i can-t go to an end in Normal mode..

Consider that services.exe take 50-60 % of CPU in Safe Mode, and 85-95% in Normal mode..

In your opinion, do I have to format C?
« Last Edit: April 05, 2012, 02:38:26 PM by willo.c »

jeffce

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #39 on: April 05, 2012, 06:10:41 PM »
I am not sure about formatting yet.  :)

You never mentioned whether or not you are still using ZoneAlarm.  In my experience that can be quite a resource hog.

willo.c

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #40 on: April 05, 2012, 06:14:57 PM »
Jeff,

I think this is not Zonealarm.. If I stop it nothing happens..
Could it be avast? And is there a problem to formatting?

jeffce

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #41 on: April 05, 2012, 07:32:30 PM »
Quote
is there a problem to formatting?
No there is not a problem at all.  As a matter of fact I recommend it every so often just to have a clean start and make sure everything is fresh and running right.  With the infection that you had, if it were my computer, I would format...but that is just me. 

willo.c

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #42 on: April 05, 2012, 08:12:25 PM »
Ok, i'm going to do it..

Thanks for all your support.. I will keep you informed if everything is going well..

jeffce

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #43 on: April 05, 2012, 08:31:07 PM »
Ok thanks for letting me know.  :)

willo.c

  • Guest
Re: MBR : \.\\PHYSICALDRIVE0\PARTITION2
« Reply #44 on: April 06, 2012, 02:39:11 PM »
Jeff,

everything is done, my pc is well formatted.. No problems now..

Thank you again for supporting me..

Byee