my BF did a scan yesterday and this Threat:Win32:Downloader-FBI[Trj] appeared in 2 C:\System Volume Information\restore entries.
when he tried to fix the threat with AVAST he had the error The System cannot find the file specified!
he used CCleaner to look at the restore entries and there were 2 not specified entries both ended with .exe and he couldn’t delete them either.
he did what Windows recommended switch off system restore restart pc and then switch system restore back on which should empty system restore.
well, CCleaner didn’t show those 2 entries anymore but they keep coming up with AVAST scan.
we tried Superantispyware, Malwarebytes, Panda Cloud Antivirus nothing and it shouldn’t be there anyway as system restore is clean.
a search online only showed references to the AVAST Virus Update History. Nothing to find at Kaspersky, McAfee or Norton.
Avast was so far the best antivirus i’ve ever used and i have recommended it to many of my friends but when things like this happens you start to doubt.
this is driving us mad because we don’t know is it still there or not and if it is still there how the hell do we get rid off it. please help!!
started the pc in save mode. out of curiosity and because it’s the only way to get into system volume information.
it’s in system restore the folder RP304 and the file is called A0055208.exe still i cannot delete it though but whilst trying to delete it you can see what it actually is. it the installer from Microsoft Sdpblb File Version 5.2.3790.0 which refers to the sdpblb.dll
Probably you can’t delete because it is running,you can check it in taskmanager.Anyway.
Try MalwareBytes Anti Malware
Download from here www.malwarebytes.org
Download
Install
Update
I repeat update,Don’t forget it.
Scan
Post the log
Happy new year
as i mentioned it is in system restore.
we’ve been through the whole registry and didn’t find anything related to this downloader-fbi
there is nothing unusual running in the startup etc
and as i mentioned first we did run a fully updated malwarebytes and it didn’t find anything, nor did superantispyware or panda cloud antivirus.
and we’ll be trying some more just to make sure.
but still i find it very odd that just AVAST comes up with a new trojan threat and nobody else seemed to have heard of it ???
thanks Tenko for your suggestion but i would like NEW ideas and solutions.
please read my first post correctly so nobody will suggest programs we’ve already tried
Download Hijackthis http://majorgeeks.com/download3155.html
Install
Choose RUN AND SAVE A LOG FILE!Don’t hesitate scan won’t take more than 1 minute
Post the log.
I will take a look at your log tomorrow morning.