This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Think Im Infected [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:welcome:

 

Sorry for the delay, most of our helpers are away for the holidays.  All the reports that we ask for will open in Notepad and I prefer if you would copy and paste them in in lieu or attaching them. I would like you to run these three programs, post the log for each please.  Malwarebytes just came out with a new version so follow my instruction as best you can, I will update the info as soon as I can

 

All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder, so download and run these tools right from the DESKTOP
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
     
     
    [external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
    • Download the one from Bleeping Computer
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
      •  
        [external image: MBAM221%201043_zpsdtasp5xe.jpg]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • # AdwCleaner v6.041 - Logfile created 25/12/2016 at 15:21:51
          # Updated on 16/12/2016 by Malwarebytes
          # Database : 2016-12-23.1 [Server]
          # Operating System : Windows 10 Home  (X64)
          # Username : \//////////
          # Running from : C:\Users\//////////\AdwCleaner.exe
          # Mode: Clean
          # Support : https://www.malwarebytes.com/support
           
          ***** [ Services ] *****
           
          ***** [ Folders ] *****
           
          ***** [ Files ] *****
           
          ***** [ DLL ] *****
           
          ***** [ WMI ] *****
           
          ***** [ Shortcuts ] *****
           
          ***** [ Scheduled Tasks ] *****
           
          ***** [ Registry ] *****
          [-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\dotomi.com
          [-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\iad-usadmm.dotomi.com
          [-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\metrolyrics.com
          [-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\sjc-usadmm.dotomi.com
          [-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.metrolyrics.com
          [-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\dotomi.com
          [-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\iad-usadmm.dotomi.com
          [-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\metrolyrics.com
          [-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\sjc-usadmm.dotomi.com
          [-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.metrolyrics.com
          [#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\dotomi.com
          [#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\iad-usadmm.dotomi.com
          [#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\metrolyrics.com
          [#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\sjc-usadmm.dotomi.com
          [#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.metrolyrics.com
          [#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\dotomi.com
          [#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\iad-usadmm.dotomi.com
          [#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\metrolyrics.com
          [#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\sjc-usadmm.dotomi.com
          [#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.metrolyrics.com

          ***** [ Web browsers ] *****
          [-] [C:\Users\\//////////\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
          [-] [C:\Users\\//////////\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com

          *************************
          :: "Tracing" keys deleted
          :: Winsock settings cleared
          *************************
          C:\AdwCleaner\AdwCleaner[C0].txt - [5459 Bytes] - [25/12/2016 15:21:51]
          C:\AdwCleaner\AdwCleaner[S0].txt - [5550 Bytes] - [25/12/2016 15:21:32]
          ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [5605 Bytes] ##########
           
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Malwarebytes
          Version: 8.1.0 (12.05.2016)
          Operating System: Windows 10 Home x64
          Ran by (Administrator) on Sun 12/25/2016 at 15:29:14.89
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           

          File System: 0
           

          Registry: 0
           
           
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on Sun 12/25/2016 at 15:30:26.11
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           
           
          Malwarebytes
          www.malwarebytes.com
          -Log Details-
          Scan Date: 12/25/16
          Scan Time: 3:36 PM
          Logfile:
          Administrator: Yes
          -Software Information-
          Version: 3.0.5.1299
          Components Version: 1.0.43
          Update Package Version: 1.0.860
          License: Trial
          -System Information-
          OS: Windows 10
          CPU: x64
          File System: NTFS
          User: \\//////////
          -Scan Summary-
          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 378084
          Time Elapsed: 2 min, 20 sec
          -Scan Options-
          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Disabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled
          -Scan Details-
          Process: 0
          (No malicious items detected)
          Module: 0
          (No malicious items detected)
          Registry Key: 0
          (No malicious items detected)
          Registry Value: 0
          (No malicious items detected)
          Data Stream: 0
          (No malicious items detected)
          Folder: 0
          (No malicious items detected)
          File: 0
          (No malicious items detected)
          Physical Sector: 0
          (No malicious items detected)

          (end)

          Thanks for the logs.  What are you experiencing to make you think your infected ?  Are you getting any browser redirects or unwanted pop up windows ?

           

          As far as your router, dotomi is a bad site but if you where infected with it malwarebytes would have picked it up. All AdwCleaner found was registry entries but no files.  Usually a business or a corporations website  is the target of a Dos attack, not a home user.  The object of a Dos attack is to flood the site with so much traffic that the site cant be accessed  basically shutting it down.    Looking at the router log can you access the internet in those time frames ? You may want to think about resetting it, most routers have a reset button that you press with a ball point pen or paper clip and hold it in for about 10 seconds and it resets your router back to manufacturers default. Then you will have to use the set up CD and set it up again. If your router is pretty old maybe a new one would be in order.

          This has been going on for over a year. I get disconnected around 12am-2am for short burst at a time. I check the logs and see the attacks. I thought the storm attack was a virus trying to dial out.

          Ask AI

          AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

          Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI