This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good Morning Mowman, That took a while, here's the data. C:\Users\vanbass\Downloads\SetupGamevance.exe a variant of Win32/Adware.Gamevance.AE application C:\Users\vanbass\Downloads\SetupPlaySushi.exe a variant of Win32/Adware.Gamevance.AK application C:\Users\vanbass\Downloads\SoftonicDownloader_for_directx.exe a variant of Win32/SoftonicDownloader.A application C:\Users\wsidejo\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000373 HTML/ScrInject.B.Gen virus
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :files
    C:\Users\vanbass\Downloads\SetupGamevance.exe 
    C:\Users\vanbass\Downloads\SetupPlaySushi.exe 
    C:\Users\vanbass\Downloads\SoftonicDownloader_for_directx.exe 
    C:\Users\wsidejo\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000373
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Thank you again Mowman for all that you do, I appreciate the help. :thumbup: All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Users\vanbass\Downloads\SetupGamevance.exe moved successfully. C:\Users\vanbass\Downloads\SetupPlaySushi.exe moved successfully. C:\Users\vanbass\Downloads\SoftonicDownloader_for_directx.exe moved successfully. C:\Users\wsidejo\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000373 moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: JOJO ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: vanbass ->Temp folder emptied: 473936 bytes ->Temporary Internet Files folder emptied: 36458 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 125834736 bytes ->Flash cache emptied: 3858 bytes User: wsidejo ->Temp folder emptied: 103665 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 245270278 bytes ->Flash cache emptied: 2232 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2432 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32768 bytes RecycleBin emptied: 77795 bytes Total Files Cleaned = 355.00 mb OTL by OldTimer - Version 3.2.46.1 log created on 06092012_195029 Files\Folders moved on Reboot… C:\Users\vanbass\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\wsidejo\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\wsidejo\AppData\Local\Temp\JETE031.tmp not found! C:\Users\wsidejo\AppData\Local\Temp\logger.log moved successfully. Registry entries deleted on Reboot…
You appear clean of infections,please do the following.

Right click on TDSSKiller and select delete,delete ESET using add/remove programs.




ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.









Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing
Good Morning Mowman, :thumbup: The clean up went well, I'll get to work on making the computer safer, thanks for all the info. I appreciate all the time and patience you have given me, I don't get to many problems usually, but this one was stubborn. As I had read in the posts from this site, you do a great service to people with unique problems, it's awesome to see there are people helping people. Thanks again, Dan :woot:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI