I'm Infected! Please Help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TROUBLEtime, Nov 8, 2017.

  1. TROUBLEtime

    TROUBLEtime Private E-2

    You guys have totally been my saviours in the past. I REALLY appreciate your help and what you guys do for people in this virus and funk filled world we live in.

    So I've attached all the logs requested in the "do this first" thread except for hitman pro. I can tell you it found 5 threats and like 49 items. Basically when I hit "save" to save the log file it kinda lags for a minute and then says "hitmanpro has stopped working." I ran it like 4 times, same thing every time. I should also mention that currently my computer will only let me into windows in safe mode. If i try to start it up normal i get a blue screen right after logging into windows. Very scary. So for now, here are the logs I'm working with and I appreciate any help you can provide.

    THANK YOU SO MUCH!!!
    Jeremy
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First clean everything ADW found. Next remove these items in RogueKiller:

    ¤¤¤ Processes : 5 ¤¤¤
    [Suspicious.Path] siceagr.exe(2084) -- C:\Users\Jeremy R\AppData\Local\siceagr\siceagr.exe[-] -> Found
    [Suspicious.Path] usienbp.exe(2600) -- C:\Users\Jeremy R\AppData\Local\siceagr\usienbp.exe[-] -> Found
    [Suspicious.Path] usienbp.exe(2388) -- C:\Users\Jeremy R\AppData\Local\siceagr\usienbp.exe[-] -> Found
    [Suspicious.Path] usienbp.exe(3680) -- C:\Users\Jeremy R\AppData\Local\siceagr\usienbp.exe[-] -> Found
    [Suspicious.Path] usienbp.exe(2224) -- C:\Users\Jeremy R\AppData\Local\siceagr\usienbp.exe[-] -> Found

    ¤¤¤ Files : 1 ¤¤¤
    [PUP.OnlineIO|PUP.Gen1][Folder] C:\Users\Jeremy R\AppData\Roaming\AGData -> Found


    Next, let's get rid of your temp files. Right click start / run/ and type in %temp% and delete everything in there. Then empty your Recycle Bin.

    Now use file explorer to find and delete: C:\Windows\system32\tasks\ivdHB0GgucDC

    Reboot and try to get into normal mode. If you can, rerun RogueKiller, ADW and see if you can get me a log from Hitman. If you have to, try to copy and paste the results into notepad.
     
  3. TROUBLEtime

    TROUBLEtime Private E-2

    thanks for your speedy reply. i did everything you said, but there was one file in the temp folder that i couldn't delete. its called FXSAPIDebugLogFile.txt. Also I couldn't get the computer to restart in normal mode. it bluescreened again. and when i just now opened the temp folder there was 2 things in there, the file i mentioned above and an empty folder called WPDNSE. When i log into windows in normal mode it shows me my desktop for about 3-5 seconds before this text file pops up in notepad, then it quickly bluescreens. shouldnt i delete all those things that hitman found? it found more bad files than any other program i ran and the instructions said to just mark them all "ignore." hopefully you can get back to me soon....again. i;m at home on my email right now so i can try whatever you shoot my way.

    thanks again,
    jeremy
     
  4. TROUBLEtime

    TROUBLEtime Private E-2

    I also just noticed that there are 2 "desktop.ini files now on my desktop that were not there before and that I didn't put there. I've attached 4 screen shots of my hitman pro log since the program keeps crashing everytime I go to save the log. thanks!

    Sorry, I'm not sure why the pics got turned sideways and I cant even open my photoviewer in safe mode in order to spin them around. hopefully you can.
     

    Attached Files:

  5. TROUBLEtime

    TROUBLEtime Private E-2

    Ok, so I did 2 things and managed to get my computer to start in normal mode. First I ran "msconfig" and went to the startup tab, where every single box was checked to startup with my computer including a few things I definitely didn't recognize. I unchecked everything and applied it and did a reboot. Second, when I rebooted I used my windows cd to boot and selected "repair windows." It immediately told me it found a problem with my bootloader file, so I selected repair and restart. Voila! I'm in normal mode, so far so good. I'm gonna try to run the hitman pro scan and see if it will let me save the log file and i'll post it here if it does.

    Thanks!
     
  6. TROUBLEtime

    TROUBLEtime Private E-2

    Awesome! it worked! hitman pro log is attached. ty!
     

    Attached Files:

  7. TROUBLEtime

    TROUBLEtime Private E-2

    here's my new rogue killer log as well
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know you managed to get into normal mode. Now remove everything found in Hitman and remove this one item in RogueKiller:

    ¤¤¤ Files : 1 ¤¤¤
    [PUP.OnlineIO|PUP.Gen1][Folder] C:\Users\Jeremy R\AppData\Roaming\AGData -> Found

    Reboot and rescan with Hitman and RogueKiller and also run ADW and attach the new logs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds