Si MalwareByte's a détecté des infections, clique sur Afficher les résultats ensuite sur Supprimer la sélection Enregistre le rapport sur ton Bureau comme cela il sera plus facile à retrouver, Antivirus)SRV:64bit: - [2008/07/22 08:12:08 | 000,902,656 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\Ati2evxx.exe -- (Ati External Event Utility)SRV:64bit: - [2008/06/11 13:18:30 | 000,024,576 | ---- | M] () physicaldriveo Customer Question have a virus or trojan called mbr;\\.\physicaldriveo Submitted: 5 years ago.

I think this could have been much worse if it had not done so. Mrken làm cẩn thận. Đụng đến sector thì dễ banh ổ đĩa lắm . ... I do so and have let it run boottime scans multiple times. TDL4 rootkit infection detected !

I was steelimg myself to the reality I would have to buy a new computer before I met you and TSF!! N. I've run the OTL and aswMBR.exe as mentioned in the suggestions here. Double-clique sur l'icône AD-Remover située sur ton Bureau. (Vista/Seven - Faire un clique droit sur l'icône AD-Remover située sur ton Bureau et choisir exécuter en tant qu'administrateur.) Au menu principal, choisis

Reporte de TDSSKiller 14 3644 TDSS rootkit removing tool Mar 10 2011 12:26:28 2011/04/15 21:37:48.0291 3644 ================================================================================ 2011/04/15 21:37:48.0291 3644 SystemInfo: 2011/04/15 21:37:48.0291 3644 2011/04/15 21:37:48.0291 3644 OS Version: 6.0.6000 Note : Si MalwareByte's a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok Tutoriel pour MalwareByte's ici : http://www.malekal.com/tutoria [...] alware.php @++

This type of virus makes modifications to the master boot record (MBR) of the compromised PC. http://www.justanswer.com/computer/4wqyk-virus-trojan-called-mbr-physicaldriveo.html SBRE;SBRE S? Attached Files Combofix 4 6 2011 log.txt (22.7 KB, 47 views) mbam-log-2011-04-06 (15-51-15).txt (897 Bytes, 28 views) 04-06-2011, 07:34 PM #8 RPMcMurphy Security Team Analyst Join Date: get out and enjoy some of this spring weather.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: Click on Yes, to continue scanning for malware. It will open a black window, please do not fix anything (if it gives you an option).3. My system is running Vista Home Edition. Did you try a scan with malwarebytes in safe mode?

Registrado jun 2007 Ubicacin Argentina Mensajes 58.517 Re: Physicaldriveo [emailprotected],ROOTKYT Hola Hac con Total confianza el trabao con ComboFix, Tal cual est explicado en Mi 1er respuesta y luego volves con When activated, it alters the particular registry entry to your computer so that you may get constant popup once Windows is launched. Désactive provisoirement et seulement le temps de l'utilisation de AD-Remover, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de nettoyage de Please do this next: Your Java is out of date.

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal or read our Welcome Guide to learn how to use this site. Saludos Conoce Malwarebytes Sguenos en Twitter y hazte nuestro amigo en Facebook.

Internet Security *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} AV: Sunbelt VIPRE *Enabled/Updated* {964FCE60-0B18-4D30-ADD6-EB178909041C} FW: avast!

c:\program files\ClickPotatoLite c:\program files\ClickPotatoLite\bin\10.0​.530.0\ClickPotatoLiteSAAX.dll​ c:\program files\ClickPotatoLite\bin\10.0​.530.0\ClickPotatoLiteSAHook.d​ll c:\program files\ClickPotatoLite\bin\10.0​.530.0\firefox\extensions\chro​me.manifest c:\program files\ClickPotatoLite\bin\10.0​.530.0\firefox\extensions\inst​all.rdf c:\program files\ClickPotatoLite\bin\10.0​.530.0\firefox\extensions\plug​ins\npclntax_ClickPotatoLiteSA​.dll c:\program files\ClickPotatoLite\bin\10.0​.530.0\LaunchHelp.dll c:\program files\ClickPotatoLite\bin\10.0​.624.0\ClickPotatoLiteSAHook.d​ll c:\program files\ClickPotatoLite\bin\10.0​.624.0\firefox\extensions\inst​all.rdf c:\program files\ClickPotatoLite\bin\10.0​.624.0\firefox\extensions\plug​ins\npclntax_ClickPotatoLiteSA​.dll c:\program files\ClickPotatoLite\bin\10.0​.624.0\LaunchHelp.dll c:\program files\Mozilla Firefox\plugins\npclntax_Click​PotatoLiteSA.dll c:\program files\OfferBox c:\program files\OfferBox\extensions-4.0.​4376.15\offerbox_air_iexplorer​.dll c:\programdata\2ACA5CC3-0F83-4​53D-A079-1076FE1A8B65 c:\programdata\ClickPotatoLite​SA Show hidden files and folders. Thanks you for your help. - Show quoted text - -- 李文思(斯) (Bob) Attached Files Spybot - Search & Destroy scan report.pdf (8.8 KB, 19 views) 04-10-2011, 08:37 PM and Vipre running.

Utilise cjoint.com pour poster en lien tes rapports : http://cjoint.com/ - Clique sur Parcourir pour aller chercher le rapport OTL.txt sur le bureau - Clique sur Ouvrir ensuite sur Créer le Please include the following in your next post:ComboFix log MBAM log __________________ ASAP & UNITE Member 04-06-2011, 01:55 PM #7 awaterguy Registered Member Join Date: Apr 2011 Location: Télécharge sur ton bureau TdssKiller de kaspersky , décompresse le et exécute le , un rapport sera crée ici: C:\TDSSKillerVersion_Date_Time​_log.txt.<< copie_colle son contenu (Vista/Seven --> Faire un clique droit sur tdsskiller.exe IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service S?

Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr)