Paid Help, Please?? Brand New Virus/malware- Mbam Team Struggling-need Help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BethyK, Mar 8, 2016.

  1. BethyK

    BethyK Private E-2

    Anyone looking for a BRAND NEW challenge??

    Hi, I'm Bethy. I'm new but I know just enough about this stuff to probably be dangerous... I literally took my brand new Alienware desktop out of the box four days ago. I have no idea how, but in the process of installing antivirus software I managed to find a first run virus- Virustotal first identified it on March 7th at 8pm.
    Have been working with the Mbam team since Sat. to try to remove it but despite writing code scripts for me, we still haven't fixed it. The nasty files appear to be:
    C:\WINDOWS\wine.exe
    and
    C:\Program Files(x86)\standing\minor.exe

    Basically, it starts a proxy server that doesn't show up in the regedit and loops back despite all attempts to remove it. I've got 6 FRST logs from various attempts Mbam'ers have tried and innumerable scans with various programs but at this point we know it's a completely new creature and we know mbam, Avira, Hitman Pro, Kaspersky TDSS, MBAR, and Zemana do NOT remove it and only Zemana even detects the proxy server- however deleting and repairing does nothing - it just re-installs within 10 seconds. The net result of this is that I only have internet access for approximately 20-30 seconds at a time and that ALL of my USB ports, optical drive etc- anything to transfer files (EG like to download Respawn and factory reset-if that would even work) is not an option... for some reason, about every 10th attempt I CAN get it to recognize a thumb drive on one port, so please, whatever software programs anyone thinks might help, give them to me all at once... I've got a clean laptop I can install the programs to the thumbdrive from, but the only way to launch anything that requires internet - like mbam- is to run the infected desktop in safe mode... once it's installed, it still has to be run in safe mode or the virus terminates it within 10 seconds. Desktop icons also display an error that the program the shortcut refers to has been corrupted- so there's no install in SM and run in normal boot either...
    I know this is long- please bear with me... Let me know all logs you might need to help-I'll reply immediately- my thumb drive is detected now but new downloads will take a while to install from the thumb drive since I have to install it from the clean laptop & can't rely on having the infected desktop recognize the usb... sometimes it requires 10 to 12 restarts or logouts to get lucky...
    Is anyone up for a challenge? I know this is a totally volunteer site, but I truly respect the skills everyone here has developed and the time you put into helping others. I would like to offer payment for your help... Especially because working with me- I'm a couple of years behind the tech (although 5 years ago I could have been on the other side of this post- isn't easy and I know it.
    My email is (snip)- you can post here and communicate with me via email or whatever the correct protocol is... I hope no one is offended by offering money, that is definitely not my intention... it is only out of respect and a huge desire to get my new rig functioning. Thank you all!!
    Bethy
     
    Last edited by a moderator: Mar 9, 2016
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

     
  3. BethyK

    BethyK Private E-2

    This is the only forum I meant to posted to... If I somehow managed to post to any additional forums I apologize... It was not my intention. Apologies to all. Bethy
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please stick with MBAM Forums until you get an answer. If no one can fix it, post back and follow these instructions:

    READ & RUN ME FIRST. Malware Removal Guide

    You might just consider a reinstall.
     
  5. BethyK

    BethyK Private E-2

    Sorry, I wasn't clear... I'm not posting to mbam forums. I've actually been working with them via email but they have no known solution and believe it may be a week or more before they have a solution... Was hoping someone here might have a different approach or have heard of this in the past couple of days. Sorry to confuse.
    Beth
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, considering how new the machine is, I again suggest you just reinstall. Otherwise, you need to go through the Read and Run First instructions and attach the requested logs.
     
  7. BethyK

    BethyK Private E-2

    At this point, I don't think I can factory reset... The Alienware Respawn software does not recognize the presence of a thumb drive-even when I can see it in the "this PC" index... and the optical drive will not even load a disk. I agree that IF resetting would work that is no doubt the easiest way to go, but I don't know another way to obtain the factory reset files... If you have ANY ideas, believe me, I would be thrilled to try it! In the mean time, I am going to start with the READ & RUN ME FIRST MALWARE REMOVAL GUIDE... If you can walk me through a reset, I'll try whatever you suggest.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you first boot up and get the splash screen, click on the icon in the lower right which should start a reinstall.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Last edited: Mar 9, 2016

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds