This thread's last reply is from July 21, 2012, 2:49 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
All processes killed
========== OTL ==========
HKEY_USERS\S-1-5-21-1486715935-242868176-2598389495-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1486715935-242868176-2598389495-1000\Software\Microsoft\Internet Explorer\SearchScopes\{C34F1341-62B9-49C1-A40F-39887D0CB88B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C34F1341-62B9-49C1-A40F-39887D0CB88B}\ not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Leslie\Downloads\cmd.bat deleted successfully.
C:\Users\Leslie\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Leslie
->Temp folder emptied: 2297835 bytes
->Temporary Internet Files folder emptied: 686206 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 75727307 bytes
->Flash cache emptied: 1841 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10684 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 75.00 mb
[EMPTYFLASH]
User: All Users
User: Default
->Flash cache emptied: 0 bytes
User: Default User
->Flash cache emptied: 0 bytes
User: Leslie
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0.00 mb
[EMPTYJAVA]
User: All Users
User: Default
User: Default User
User: Leslie
->Java cache emptied: 0 bytes
User: Public
Total Java Files Cleaned = 0.00 mb
Restore point Set: OTL Restore Point
OTL by OldTimer - Version 3.2.54.0 log created on 07192012_080759
Files\Folders moved on Reboot...
File move failed. C:\Users\Leslie\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.
PendingFileRenameOperations files...
[2012/07/16 08:18:31 | 000,000,000 | ---- | M] () C:\Users\Leslie\AppData\Local\Temp\FXSAPIDebugLogFile.txt : Unable to obtain MD5
Registry entries deleted on Reboot...
C:\Users\Leslie\Documents\Homework\Research\SoftonicDownloader_for_spss.exe a variant of Win32/SoftonicDownloader.A application
C:\_OTL\MovedFiles\07112012_232343\C_Users\Leslie\AppData\Local\Temp\SetupDataMngr_Searchqu.exe a variant of Win32/Toolbar.SearchSuite application
After we got the anti-virus disabled there were no problems completing your instructions, thank you for the additional instructions on disabling it.
I had two threats from the ESET online scanner shown above.
Hello
kizzer1102,
Your latest set of logs appear to be clean!
This is my general post for when your logs show no more signs of malware.
Before I give you instructions how to keep your computer clean and secure, you need to make a few additional steps
Step 1.
Remove Program(s)
- Click on Start, then click the Start Search box on the Start Menu.
- Copy and paste the value below without the word Code: into the open text entry box:
appwiz.cpl
and press Enter - the Unistall or change a program list will be opened. - Click each entry, as follows, one by one, if it exists, choose Uninstall, and give permission to Continue:
Java Auto Updater
Java(TM) 6 Update 33
- Take extra care in answering questions posed by any Uninstaller.
- When the program(s) have been uninstalled, please close Control Panel.
- Reboot you computer.
Step 2.
Latest Java Installation Needed!
Attention: Print these instructions or copy them. You will be closing your browser!!
DOWNLOAD LATEST VERSION
- Get the latest version (7u5) of Java Runtime Environment (JRE)... © Sun Microsystems, Inc.
- Click the "Download JRE" button to the right.
- Check "Accept License Agreement "
- Locate the entry for Windows x64, click on the associated file name, then save the file to your Desktop.
INSTALL Java
- Close all open applications (standard), especially your browser.
- From Desktop please right-click on jre-7u5-windows-x64.exe select "Run As Administrator..." to install the newest version.
- Follow the on-screen directions. When installation is completed successfully, please reboot your computer normally.
- Once the computer has been restarted, you can delete the "downloaded" installation file from your desktop.
OPTIONAL:
To prevent some unnecessary JAVA components from running when you boot your computer each time...
- Go to Control Panel and click on the JAVA icon.
- Press the Advanced tab and press the [+] to expand the JRE Auto-Download.
- CHECK "Never Auto-Download". (You can check for updates manually.)
- Press Apply and OK, then close the Java Control Panel and exit Control Panel.
Step 3.
Disable Symantec Endpoint Protection
- Open Symantec Endpoint Protection and then click Change settings from the left menu bar.
- Click Configure Settings next to Antivirus and Antispyware Protection.
- Click the File System Auto-Protect tab and uncheck the box labeled Enable File System Auto-Protect. Click OK.
- Click Configure Settings next to Proactive Threat Protection. Uncheck the boxes labeled Scan for trojans and worms and Scan for keyloggers.
- Click OK.
Step 4.
OTL - Run Fix Script
You should still have
OTL on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your
Desktop.
- Right click on OTL.exe select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
- Copy and Paste the following code into the
text box. Do not include the word Code
:Files
C:\Users\Leslie\Documents\Homework\Research\SoftonicDownloader_for_spss.exe
:Commands
[EMPTYTEMP]
[CLEARALLRESTOREPOINTS]
- Click under the Custom Scan/Fixes box and paste the copied text.
- Click the Run Fix button. If prompted... click OK.
- OTL may ask to reboot the machine. Please do so if asked.
Step 5.
OTL - Cleanup
- Right click on OTL.exe select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
- Press the CleanUp button.
- When done, you will be prompted to reboot your system to finish file removal, please select OK to reboot your computer.
Then:
Please don't forget to enable all your defense software!
Finally,
please click HERE to find a short guide to staying safer online.
Please don't hesitate to ask any additional questions.
Stay Safe!

pgmigg
Failure to post replies within 72 hours will result in this thread being closed
Finished the instructions from the last post. But I still have the "searchnu" tab come up when I open Google Chrome. I tried to change my search engine settings but the only search engine I have on the list is google.com, which is set as my default. How can I get rid of this second tab that pops up when I open chrome?
Hello
kizzer1102,
But I still have the "searchnu" tab come up when I open Google Chrome.
If
Chrome is still redirecting you then first use the instructions
here to change your home page to something like
google.com or some other clean site. Then reboot your system and see if
Chrome is still being redirected.
If it's still being redirected after changing your home page then please uninstall Chrome then download and install a clean copy.
Please let me know if this resolves your issues.
Thanks,
pgmigg
Failure to post replies within 72 hours will result in this thread being closed
Yep, the "Open a specific page or set of pages" was selected under the google chrome settings. When I edited the settings "searchnu" was on the list. I deleted it and now I do not see it come up when I open up the browser.
Thank you very much for your help! :-)
As your problems appear to have been resolved,