It looks like that did the trick! OTS rebooted the computer to “finish removing files”. Notepad popped up after the reboot (log is attached). I’ve rebooted again since then and the redirect has not returned.

Does this virus try to steal passwords or banking information? I made one online purchase while infected and can report that credit card stolen if necessary.

Thanks a million, essexboy. You’re the man!

UPDATE: Attached file looks Chinese to me. Here’s the fix log on MediaFire:
http://www.mediafire.com/?nicy9kz3c3kbwlq