also @ TechSpot: Asus' new lineup of Z87 Haswell motherboards revealed

Search engine redirect malware

Discussion in 'Virus and Malware Removal' started by yeahisgood, Sep 9, 2012.

Post New Reply
  1. yeahisgood Newcomer, in training Posts: 73

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Owner
    ->Temp folder emptied: 52122 bytes
    ->Temporary Internet Files folder emptied: 6234603 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 0 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 492 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 52138 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 3080326 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 9.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Owner
    ->Flash cache emptied: 0 bytes

    User: Public

    User: UpdatusUser

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Default

    User: Default User

    User: Owner
    ->Java cache emptied: 0 bytes

    User: Public

    User: UpdatusUser

    Total Java Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.61.3 log created on 09132012_003714
    Files\Folders moved on Reboot...
    C:\Users\Owner\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\83ZIETVF\bizo_multi[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\83ZIETVF\default[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\83ZIETVF\page-2[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\83ZIETVF\partner[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\83ZIETVF\partner[2].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4VZP37UI\RteFrame_16.4.9822.0821[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4VZP37UI\xmlProxy[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\39DT50AT\AjaxHistoryFrame[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\39DT50AT\flextag[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\39DT50AT\LocalStorage[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\39DT50AT\Messenger[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\39DT50AT\resourcespreload[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\39DT50AT\xmlProxy[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\39DT50AT\xmlProxy[2].htm moved successfully.
    PendingFileRenameOperations files...
    Registry entries deleted on Reboot...
  2. yeahisgood Newcomer, in training Posts: 73

    Thanks. Will see how it runs this time and let you know in a couple days. Once again, you were a very big help and took care of the problem. I truly appreciate it.
  3. Broni Malware Annihilator Posts: 39,288   +175

    Way to go!! [IMG]
    Good luck and stay safe :)
  4. yeahisgood Newcomer, in training Posts: 73

    Broni,

    I noticed that I am getting a redirect when I recently started using Google Chrome again. I rarely if ever use Chrome and had it opened and used it for some searches (both BING and GOOGLE). Was getting a redirect often. On the other hand, I haven't noticed anything regarding my IE and have tried Firefox with no redirects since we did the last fix. I've been updating/running Malwarebytes and MSE regularly. I have run them both and no threats were detected.
  5. Broni Malware Annihilator Posts: 39,288   +175

    Uninstall Chrome...

    1. Go to Start > All Programs > Google Chrome > Uninstall Google Chrome.
    2. Delete your user profile information, like your browser preferences, bookmarks, and history, by selecting the "Also delete browser data" checkbox.
    3. Select the default browser you'd like to use.
    4. Click OK in the confirmation prompt.
    5. The uninstall process will begin.
    Install fresh copy.
  6. yeahisgood Newcomer, in training Posts: 73

    I just did the steps. Thank you. The redirect appears to be working fine.
     
  7. Broni Malware Annihilator Posts: 39,288   +175

    Very well :)