Author Topic: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life  (Read 14322 times)

0 Members and 1 Guest are viewing this topic.

frankocean89

  • Guest
At 12:24 today, I downloaded a file without knowing it was a Trojan horse.
 Now Avast keeps reminding me every few minutes that a threat has been detected and SUCCESSFULLY BEEN DEALT WITH when it has not.
[I have attached the pics, I hope they are showing(]

Yet despite the fact that I have gone to the file location, scanned it with Avast and deleted the threats SEVERAL TIMES, they are not going anywhere. Avast says they have been deleted but few minutes later the same message about threats being detected pops up.
I have tried to download malwarebytes from Cnet.com to remove them but since they have infected my laptop, I CANT DOWNLOAD ANYTHING NOT EVEN A PICTURE OFF THE INTERNET and my laptop has been slowing down. I am extremely upset and feel upset right now and fear for my laptop, my files  :'(

Please help me

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Hi,

We need to check that first.
  • I will be working on your Malware issues this may or may not solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • If you don't know or understand something, please don't hesitate to ask.
  • Please refrain from making any further changes to your computer (Install/Uninstall programs, delete files, edit the registry, etc...)
  • Please DO NOT run any other tools or scans whilst I am helping you.
  • It is important that you reply to this thread. Do not start a new topic.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
  • Absence of symptoms does not mean that everything is clear.
---------------------------------------------------------------------------------------------

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Under Optional Scan ensure "List BCD" and "Driver MD5" are ticked.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Perform a bootscan with avast then do as Magna suggested.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Perform a bootscan with avast then do as Magna suggested.
Hi Eddy,  :)
This type of malware uses embedded nulls and permissions are broken on malware related keys (malware's loading point), malware also has two loading point (one as backup launcher)  therefore AV can not target ZA loading points.
As ZA uses uses embedded to hide full path of loading files, you can't aim these file like that. Avast boot time scan is a good thing for post cleaning or in case of some other lightware infections, but in ZA cases, it is waste of time.  ;)

frankocean89

  • Guest
Thanks for your swift replies (^_^) I have Avast full system scan running right now, should I stopped it or pausing it is enough?
Also to Eddy, I have no idea what a bootscan is

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Thanks for your swift replies (^_^) I have Avast full system scan running right now, should I stopped it or pausing it is enough?
Also to Eddy, I have no idea what a bootscan is

If you have been start boot time scan, don't stop it. Finish it first.
avast shall warn you to preform boot time scan, just press Yes and follow the prompts.

frankocean89

  • Guest
Thanks for your swift replies (^_^) I have Avast full system scan running right now, should I stopped it or pausing it is enough?
Also to Eddy, I have no idea what a bootscan is

If you have been start boot time scan, don't stop it. Finish it first.
avast shall warn you to preform boot time scan, just press Yes and follow the prompts.

But i dont know what boot time scan is. I am only using Avast full system scan and it has been running for about an hour and 45 and scanned 25% of my system.
So I fear that if the scan takes too long, the Trojan Horse will have destroyed my laptop by the time the scan is finished and also, I have important documents to download off my email account :/

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Quote
But i dont know what boot time scan is. I am only using Avast full system scan and it has been running for about an hour and 45 and scanned 25% of my system.
So I fear that if the scan takes too long, the Trojan Horse will have destroyed my laptop by the time the scan is finished and also, I have important documents to download off my email account :/
Boot time scan is preforming virus scanning by avast before windows files load in. All in sistem is shutdown and avast can target and kill all malware. Malware is inactiv and it can't defend itself.
But this malware uses some technique to hide the full path from AV and other security tools.
You may preform virus scanning some other time. Stop scan and preform FRST.

ZA will not brake your system. His misions is to steal information from you, not to brake computer.  ;D

frankocean89

  • Guest
Quote
But i dont know what boot time scan is. I am only using Avast full system scan and it has been running for about an hour and 45 and scanned 25% of my system.
So I fear that if the scan takes too long, the Trojan Horse will have destroyed my laptop by the time the scan is finished and also, I have important documents to download off my email account :/
Boot time scan is preforming virus scanning by avast before windows files load in. All in sistem is shutdown and avast can target and kill all malware. Malware is inactiv and it can't defend itself.
But this malware uses some technique to hide the full path from AV and other security tools.
You may preform virus scanning some other time. Stop scan and preform FRST.

ZA will not brake your system. His misions is to steal information from you, not to brake computer.  ;D

I am soooo relieved!! At first I thought I was about to lose everything on my laptop since I have been too lazy to back up. GREAT !! ;D
"Stop scan and preform FRST"
Sorry for my ignorance but i am not really good with IT  :-[.
So you want me to STOP Avast full scan right??
What is FRST?
Also since I have checked my email account several times since I got infected, are people in my contact list at risk of getting infected too?

« Last Edit: October 08, 2013, 04:09:04 PM by frankocean89 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37544
  • Not a avast user
Quote
So you want me to STOP Avast full scan right??
yes


Quote
What is FRST?
follow instructions magna86 gave you in first post



frankocean89

  • Guest
Quote
So you want me to STOP Avast full scan right??
yes


Quote
What is FRST?
follow instructions magna86 gave you in first post

Thanks for the head up.
I have tried downloading the Farbar scan several times ( I am on firefox right now) but I cant. I cant find it in its location folder. I said in my OP that I couldnt download anything off the internet since my laptop got infected, that is my main problem.

frankocean89

  • Guest
Hey, I have tried Real player browser and so far it is working , I am downloading it right now! I think the issue was with my browsers, I  will get back to you soon.

frankocean89

  • Guest
 :'(
NOPE it is not downloading. i cant see them anywhere even in the Downloads folder ;_;
OMG I am terrified, is there any other way out of this if I cant download off the internet? I am really desperate now ;_;

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Often when you can not download through a web-browser, ftp is still working.

You can also create a Bart-pe bootcd with the utils on it and run them from there.
« Last Edit: October 08, 2013, 04:42:21 PM by Eddy »

frankocean89

  • Guest
Often when you can not download through a web-browser, ftp is still working.
what is ftp?