i got a rootkit problem (win32 bubak [rtk]) ive used my avast to scan and remove but it keeps comming back so i downloaded mbam followedtheinstruction and completed the scan and removal/disinfect then it came back again, ill attach the latest of my 3 scans today, i think ive resolved all the issues that it was causing but i keep getting a pop up telling me i got a rootkit and progs that prev worked now no longer work with this version of windows :-/. latest log and many thanks :-
Database version: 4735
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943
[*]Download TDSSKiller and save it to your Desktop.
[*]Extract its contents to your desktop.
[*]Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
[*]If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
[*]If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of “TDSSKiller.[Version][Date][Time]_log.txt”. Please copy and paste the contents of that file here.
soz about the delay the missus is in hospital :(, ive followed your instructions and after the scan it said no infection but the warning box keeps returning, the problem files is called smezr.sys and possibly sptd.sys in the system32\drivers folder. i have a report but its rather large should i post it on here ive downloaded the other program but havent used it yet many thanks for your help :-*
im not sure what just happened but i got a warning about other websites sum loud beeps and then a blue box and an error message then the computer restarted and combo fix started and another error message kernel debugger maybe sorry for being dense and again many thanks for your efforts
[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]Click on Minimal Output at the top
[*]Select All Users[*]Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select “Save”
[*]Double click inside the Custom Scan box at the bottom
[*]A window will appear saying “Click Ok to load a custom scan from a file or Cancel to cancel”
[*]Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
[*]Select scan.txt and click Open. Writing will now appear under the Custom Scan box
[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Please attach these files, one at a time and post them in your topic
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
OTL by OldTimer - Version 3.2.14.1 log created on 10082010_110128
Files\Folders moved on Reboot…
File\Folder C:\Users\Daddy\AppData\Local\Temp~DFF451.tmp not found!
File\Folder C:\Users\Daddy\AppData\Local\Temp~DFF46B.tmp not found!
File\Folder C:\Users\Daddy\AppData\Local\Temp~DFF4D2.tmp not found!
File\Folder C:\Users\Daddy\AppData\Local\Temp~DFF4DF.tmp not found!
File\Folder C:\Users\Daddy\AppData\Local\Temp~DFF528.tmp not found!
File\Folder C:\Users\Daddy\AppData\Local\Temp~DFF534.tmp not found!
C:\Users\Daddy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\68PC6W7W\index[1].htm moved successfully.
File\Folder C:\Windows\temp_avast4_\unp104529900.tmp not found!
File\Folder C:\Windows\temp_avast4_\unp131018488.tmp not found!
File\Folder C:\Windows\temp_avast4_\unp226551445.tmp not found!
File\Folder C:\Windows\temp_avast4_\unp24613228.tmp not found!
File\Folder C:\Windows\temp_avast4_\unp97027036.tmp not found!
File move failed. C:\Windows\temp_avast4_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be moved on reboot.
[]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
[]Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
my combofix is the one you told me to dl lastweek when i start it it DL`S a newer version 4me then runs that one, Combofix will run until 5-7 secs after the blue admin box appears then the message “The name cfscript appears tobe spelt incorrectly” comes up and combofix stops working, thanks again guys, ps ive tried sophos as surgested it gos through fine clears it all then the bloody grey box of rootkit doom comes back ???