This thread's last reply is from April 9, 2011, 5:45 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Looks like the TDL Rootkit is still present.
Download
OTL by OldTimer to your Desktop.
Alternative Download
If you already have a copy of OTL delete it and use this version.
- Double click OTL.exe to launch the programme.
- Copy/Paste the contents of the code box below into the Custom Scans/Fixes box.
:Files
C:\Users\Alex\AppData\Local\cspiena.dll
C:\Users\Alex\AppData\Local\temp\rnewaomsxc.exe
C:\Users\Alex\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\42cc9baf-6632dd0d
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\TfsStore\Tfs_DAV\hxn0.jar
:Commands
[emptytemp]
[emptyflash]
[resethosts]
- Click the Run Fix button.
- OTL will now process the instructions.
- When finished a box will open asking you to open the fix log, click OK.
- The fix log will open.
- Copy/Paste the log in your next reply please.
Note: If necessary, OTL may re-boot your computer, or request that you do so, if it does, re-boot your computer. A log will be produced upon re-boot.
Next
- Download aswMBR.exe to your desktop.
- Double click aswMBR.exe to run it
- Click the SCAN button to start the scan.
- On completion of the scan click SAVE LOG and save it to your desktop.
- Post the log contents in your next reply please.
Do not attempt to fix anything with aswMBR.exe yet
Summary of the logs I need from you in your next post:
Please post each log separately to prevent it being cut off by the forum post size limiter. Check each after you've posted it to make sure it's all present, if any log is cut off you'll have to post it in sections.
Well the aswMBR scan is saying you don't have a TDL infection, so ..... How is your computer behaving now ?
It seems to be running well. I hadn't tried anything video or processor intensive before yesterday night so I loaded up a game and ran it. Performance seems good. Redirection is no longer happening on my search results, my browsers and other programs launch quickly, and my windows look alright again.
Would it be prudent to run aswMBR again (maybe in safemode) just to verify its results? Also, a question about the bottom section of the ESET log:
C:\Qoobox\Quarantine\C\Users\Alex\AppData\Roaming\0AA35AA340E408D76C950D7A0C838F79\enemies-names.txt.vir Win32/Adware.AntimalwareDoctor.AE.Gen application (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\Users\Alex\AppData\Roaming\0AA35AA340E408D76C950D7A0C838F79\local.ini.vir Win32/Adware.AntimalwareDoctor.AE.Gen application (unable to clean) 00000000000000000000000000000000 I
C:\Users\Alex\AppData\Local\cspiena.dll a variant of Win32/Cimag.GG trojan (unable to clean) 00000000000000000000000000000000 I
C:\Users\Alex\AppData\Local\temp\rnewaomsxc.exe a variant of Win32/Cimag.GG trojan (unable to clean) 00000000000000000000000000000000 I
C:\Users\Alex\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\42cc9baf-6632dd0d probably a variant of Java/Agent.AF trojan (unable to clean) 00000000000000000000000000000000 I
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\TfsStore\Tfs_DAV\hxn0.jar a variant of Java/TrojanDownloader.Agent.NAL trojan (unable to clean) 00000000000000000000000000000000 I
C:\_OTL\MovedFiles\02092011_074510\C_Users\Alex\AppData\Roaming\BC3FC61EBD2390BE003660698B68EBA6\enemies-names.txt Win32/Adware.AntimalwareDoctor.AE.Gen application (unable to clean) 00000000000000000000000000000000 I
C:\_OTL\MovedFiles\02092011_074510\C_Users\Alex\AppData\Roaming\BC3FC61EBD2390BE003660698B68EBA6\local.ini Win32/Adware.AntimalwareDoctor.AE.Gen application (unable to clean) 00000000000000000000000000000000 I
I see the scanner is still finding traces of AntiMalwareDoctor... Is that something to worry about or are these not a concern because they have already been found and quarantined?
Have you run a new E-Set scan since the last one, or is the log section you've just posted the one you posted earlier? ...... PLEASE LET ME KNOW
We did not remove the Qoobox and _OTL\Moved file objects found by E-set because they are encrypted quarantine files created by Combofix and OTL, they cannot re-infect you and we will remove them when we remove Combofix and OTL.
The other files we removed with OTL and your last OTL log says they were moved successfully.
aswMBR was not designed to run in Safe Mode, it was designed to run in Normal Mode.
No, I have not run E-Set again; I don't do anything unless you tell me to

. I was just quoting the earlier log a second time because I saw the name of the program that started this whole mess in the log... so I didn't understand how ESET could see it but aswMBR said I was free and clear. Thanks, that makes more sense now. Sorry I wasn't clear.
How do you suggest we proceed, or are we finished?
Since your latest logs appear clear, and your computer appears to be operating normally again, I think we must assume you're now clean of infection.
Time for a little tidying up, then I'll make a few suggestions about security.
First
Let's clear out OTL and the files and folders it created. This will also remove TDSSKiller.
- Double click OTL.exe to launch the programme.
- Click on the CleanUp! button.
- OTL will download a list from the Internet, if your firewall or other defensive programmes alerts you, allow it access.
- You will be prompted to allow the clean up procedure, click Yes
- When finished exit out of OTL
- Now delete OTL.exe (if still present).
Next
Please delete the following files ....
CKScanner.exe ... and any log files it created.
aswMBR.exe ... and any log files it created.
DDS.scr ... and any log files it created.
Next
Earlier on you disabled Win Patrol
To Re-enable WinPatrol.
- Click Start, Programs > All Programs > WinPatrol > WinPatrol
- Right Click the Scotty icon in your task bar and select Options.
- Check Automatically run Win Patrol when computer starts
- Close the Win Patrol window.
As far as I can see, your computer looks clear of infection now.
Are you still noticing any problems ?
- If you are let me know about them.
- If not it's time to make your computer more secure.
Please read the article below which will give you a few suggestions for how to minimise your chances of getting another infection.
If your computer is running slowly after your clean up, please read.
As your problems appear to have been resolved,