This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

oyodomo.com redirect [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi and Welcome!!

My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
  • Please be sure to subscribe to the topic if you have not already done so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.


Having said that…. [external image: Posted Image] Let's get going!!
β€”β€”β€”-

[external image: Posted Image] Please double click the aswMBR icon to run it.
Vista and Windows 7 users right click the icon and choose "Run as administrator".

  • Click the Scan button to start scan.
  • When scan finishes, press the Fix Button. Once the Fix is done, press the Save Log button and save the log to your desktop. You need to reboot your computer when its done before you do anything else, then post the log that will be on your desktop.

[external image: Posted Image]
Click the image to enlarge it

[external image: Posted Image] AdwCleaner
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
β€”β€”β€”-
The first thing you tell me is to right click on the icon and run as administator. I right click but there is no option to run as administrator?????
Ok go ahead and boot to Safe Mode and see if you are able to run either of the tools from there. If so, please post the logs…if not, let me know what happens.
Oh my gosh….I am so sorry. I am not sure what happened but the link for aswMBR did not post. :wacko:

Try this…

[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
β€”β€”β€”-

Be sure to post both the aswMBR log and the AdwCleaner log when you get them. :)
Great job! AdwCleaner removed a bunch of garbage that was showing up in your OTL log. Please run a new Quick Scan with OTL and post the log when you get it and we will go from there. :)
[external image: Posted Image] Tweaking.com Registry Backup
  • Download the tool found here to your Desktop so it is easy to find.
  • Double click on the file you just downloaded to install it to your system.
  • Once the tool is installed, double-click on the Tweaking.com Registry Backup icon
    **Note** The tool should automatically open to the Backup Registry tab.

    [external image: Posted Image]
  • Press Backup Now
  • When the back up is complete, the tool will tell you that Successful */* Files Backed Up
  • You have now successfully backed up your Registry.


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKU\S-1-5-21-3997484045-3527156826-3630032937-1000\..\SearchScopes\{CA7D3339-947D-4BE9-AF41-26818BE311BD}: "URL" = http://us.yhs4.search.yahoo.com/yhs/search?hspart=w3i&hsimp;=yhs-geneiotransfer&type;=W3i_IA,206,0_0,StartPage,20120102,18482,0,0,6434&p;={searchTerms}
    IE - HKU\S-1-5-21-3997484045-3527156826-3630032937-1000\..\SearchScopes\{E417A81B-31D7-4E87-98C7-0DC30A792EFB}: "URL" = http://www.mysearchresults.com/search?&c;=2643&t;=03&q;={searchTerms}
    FF - prefs.js..browser.search.defaulturl: ""
    FF - prefs.js..browser.search.selectedEngine: "Search Here"
    FF - prefs.js..extensions.enabledAddons: plugin%40yontoo.com:1.20.02
    FF - prefs.js..extensions.netassistant.keyword.url: "http://click.w3i.com/?Programid=132&Elementname;=Keyword&Applicationid;={3CE0F335-37D3-4719-9FE7-68BA55A59E7B}&Version;=3.6.5&Vintage;=20121044&Defaultbrowserid;=62&Productid;=2138&Vendorid;=3662&Offerid;=6894&searchterm;="
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\EXTENSIONS\\{6013E7AC-CCA6-4207-90E0-97EDA12F2359}: C:\Users\Frank\AppData\Local\FizzPlatinum\platinum.xpi [2012/10/06 16:36:19 | 000,012,302 | β€”- | M] ()
    [2011/04/30 14:41:41 | 000,000,000 | β€”D | M] (Veehd Plugin) – C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\5lpfp3he.default\extensions\{3DB5ABE1-407D-458F-AD5D-8D89BD625CCC}
    [2012/11/21 06:12:58 | 000,000,000 | β€”D | M] (ShopToWin15) – C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\5lpfp3he.default\extensions\{4ac80c6c-0a1b-4b3a-ad7e-8a6d8f5e6928}
    [2011/11/13 11:30:27 | 000,000,000 | β€”D | M] (EpicPlay Games) – C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\5lpfp3he.default\extensions\[removed]
    [2013/04/28 14:54:26 | 000,000,000 | β€”D | M] ("ICQ Toolbar") – C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
    [2012/10/06 16:36:19 | 000,012,302 | β€”- | M] () (No name found) – C:\USERS\FRANK\APPDATA\LOCAL\FIZZPLATINUM\PLATINUM.XPI
    File not found (No name found) – C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5LPFP3HE.DEFAULT\EXTENSIONS\[removed]
    File not found (No name found) – C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5LPFP3HE.DEFAULT\EXTENSIONS\[removed]
    O2 - BHO: (PinPhotoZoom) - {4a0c8953-9d4e-4790-b732-2b9fc9ebce05} - C:\Users\Frank\AppData\Roaming\PinPhotoZoom\AutocompletePro.dll (SimplyGen)
    O2 - BHO: (EpicPlay Games) - {56E4076B-A42B-4745-BA35-34DA8AC4C2F2} - C:\Program Files\EpicPlay\epicPlayGames.dll File not found
    O2 - BHO: (PlayFizz Platinum Content Add-on) - {757FAD76-20D9-4973-BD64-9208ED0A0624} - C:\Users\Frank\AppData\Local\FizzPlatinum\FizzPlatinumBHO.dll (PlayFizz)
    O15 - HKU\S-1-5-21-3997484045-3527156826-3630032937-1000\..Trusted Domains: celebritycruises.com ([www] https in Trusted sites)
    O15 - HKU\S-1-5-21-3997484045-3527156826-3630032937-1000\..Trusted Domains: intuit.com ([accounts] https in Trusted sites)
    O15 - HKU\S-1-5-21-3997484045-3527156826-3630032937-1000\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
    O15 - HKU\S-1-5-21-3997484045-3527156826-3630032937-1000\..Trusted Domains: myqwest.com ([www] https in Trusted sites)
    O15 - HKU\S-1-5-21-3997484045-3527156826-3630032937-1000\..Trusted Domains: tracfone.com ([www] https in Trusted sites)
    O15 - HKU\S-1-5-21-3997484045-3527156826-3630032937-1000\..Trusted Domains: turbotax.com ([]https in Trusted sites)
    O33 - MountPoints2\{8b7213fa-abda-11dc-83f5-00188b5b03a3}\Shell - "" = AutoRun
    O33 - MountPoints2\{8b7213fa-abda-11dc-83f5-00188b5b03a3}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
    [1 C:\*.tmp files -> C:\*.tmp -> ]
    [2013/05/18 03:54:04 | 000,000,262 | β€”- | M] () – C:\Windows\tasks\PlayFizz.job
    [2007/02/13 16:12:27 | 000,047,616 | β€”- | C] () – C:\Users\Frank\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    @Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:5A4B6413
    @Alternate Data Stream - 97 bytes -> C:\ProgramData\TEMP:1C94526F
    @Alternate Data Stream - 97 bytes -> C:\ProgramData\TEMP:182786D9
    @Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:1A4138A0
    @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:88B0DDFD
    @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:7D3DC77E
    @Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:E0F561FE
    @Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:398D29B6
    @Alternate Data Stream - 76 bytes -> C:\Users\Frank\Documents\CineMagic.dmsm:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Users\Frank\Documents\CineMagic.dat:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Users\Frank\Documents\2007_12_13_07H41M_PM Extra 1.c2d:Roxio EMC Stream
    @Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:99352C4C
    @Alternate Data Stream - 156 bytes -> C:\ProgramData\TEMP:5C68FD2C
    @Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:38760F1C
    @Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:6AF6F459
    @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:AD6127BD
    @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:4F30F326
    @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:D582AB62
    @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:47E1EAB1
    @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:EBD8123D
    @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:E5294695
    @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:4A6D00A6
    @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:225CD7D5
    @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:C6D0EC31
    @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:1E0D6460
    @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:908019AD
    @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:67C9F690
    @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:60B38AF3
    @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:178D4338
    @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:814692DF
    @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:FEAEBBCA
    @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:BEACDB69
    @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:0CE0AE44
    @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:AFA6E827
    @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:F65733F1
    @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:C67AEEBF
    @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:574ACBBF
    @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:0E1EFC7C
    @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:78E0DF72
    @Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:E1AB2E7C
    @Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:4AC9B4B7
    @Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:1AAFA9FD
    @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:FFFBC48F
    @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:B2AAF611
    @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:337FC984
    @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:D7E875F8
    @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:6AA4326A
    @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:3F3AC9D6
    @Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:038F475A
    @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:F369DF24
    @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:8807C278
    @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:43301D1D
    @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:0AC32449
    @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:CC32D59B
    @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:9D59097E
    @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:43982D5E
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [emptytemp]
    [resethosts]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Let me know if you have any problems with any of this and post the new OTL log when finished. Also let me know how your system is running. :)
When I ran the RUN FIX with the custom program as you said. It was running fine and then after about 20 mins is stopped and i received a box that said OTL had stopped running. I had to restart the computer. I am sending the file that was generated after the restart and the OTL file after the new scan. Do you want me to run the custom program again? The computer seems to be running alot faster and I tried Mozilla Firefox and I did not get the redirect this time.

Attachments:

[external image: Posted Image] Java

Please go to Start > Control Panel > Programs and Features > uninstall all the Java Programs you see, now download the latest Java from the following link and install it:

http://java.com/en/download/index.jsp
β€”β€”β€”-

[external image: Posted Image]
See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Installed Applications and Applets
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
β€”β€”β€”-

[external image: Posted Image] Please download Malwarebytes Anti-Malware to your desktop.

  • Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:

Windows 2000 & Windows XP:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs

Windows Vista & Win7:
C:\Users\\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs
β€”β€”β€”-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
β€”β€”β€”-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI