HELP PLEASE!! Threat:Win32:Downloader-FBI[Trj] - SOLVED!!

my BF did a scan yesterday and this Threat:Win32:Downloader-FBI[Trj] appeared in 2 C:\System Volume Information\restore entries.
when he tried to fix the threat with AVAST he had the error The System cannot find the file specified!

he used CCleaner to look at the restore entries and there were 2 not specified entries both ended with .exe and he couldn’t delete them either.

he did what Windows recommended switch off system restore restart pc and then switch system restore back on which should empty system restore.
well, CCleaner didn’t show those 2 entries anymore but they keep coming up with AVAST scan.

we tried Superantispyware, Malwarebytes, Panda Cloud Antivirus nothing and it shouldn’t be there anyway as system restore is clean.

a search online only showed references to the AVAST Virus Update History. Nothing to find at Kaspersky, McAfee or Norton.

Avast was so far the best antivirus i’ve ever used and i have recommended it to many of my friends but when things like this happens you start to doubt.

this is driving us mad because we don’t know is it still there or not and if it is still there how the hell do we get rid off it. please help!!

started the pc in save mode. out of curiosity and because it’s the only way to get into system volume information.
it’s in system restore the folder RP304 and the file is called A0055208.exe still i cannot delete it though but whilst trying to delete it you can see what it actually is. it the installer from Microsoft Sdpblb File Version 5.2.3790.0 which refers to the sdpblb.dll

i hope this helps a little more.

Probably you can’t delete because it is running,you can check it in taskmanager.Anyway.
Try MalwareBytes Anti Malware
Download from here www.malwarebytes.org
Download
Install
Update
I repeat update,Don’t forget it.
Scan
Post the log
Happy new year

you cloud also try to do a fullsystem scan with superantispyware.

Regards,
Tenko

as i mentioned it is in system restore.
we’ve been through the whole registry and didn’t find anything related to this downloader-fbi
there is nothing unusual running in the startup etc

and as i mentioned first we did run a fully updated malwarebytes and it didn’t find anything, nor did superantispyware or panda cloud antivirus.
and we’ll be trying some more just to make sure.
but still i find it very odd that just AVAST comes up with a new trojan threat and nobody else seemed to have heard of it ???

thanks Tenko for your suggestion but i would like NEW ideas and solutions.
please read my first post correctly so nobody will suggest programs we’ve already tried

Downloade program DDS http://download.bleepingcomputer.com/sUBs/dds.scr
Double-click Run DDS

Wait a bit, it will dispose two logs
Copy me log DDS.txt

Have you tried hitman pro?

just tried hitman pro and it came up clean like everything else before.

please avast tell me it’s a hiccup at your end and there’s nothing wrong with our pc

have you made a boot scan?

unfortunately avast still doesn’t support boot scans with Windows 7 64bit. a bit disappointing if i’m honest

any suggestions for a program that does support windows 7 64 boot scans are appreciated.

won’t do anything tonight though as it’s getting late

Download Hijackthis
http://majorgeeks.com/download3155.html
Install
Choose RUN AND SAVE A LOG FILE!Don’t hesitate scan won’t take more than 1 minute
Post the log.
I will take a look at your log tomorrow morning.

thanks everyone for your kind help :slight_smile:

Avast only just updated which now includes 64 boot scan. done one this morning and the problem has been solved :smiley:

thanks again :-*