These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life

At 12:24 today, I downloaded a file without knowing it was a Trojan horse.
Now Avast keeps reminding me every few minutes that a threat has been detected and SUCCESSFULLY BEEN DEALT WITH when it has not.
[I have attached the pics, I hope they are showing(]

Yet despite the fact that I have gone to the file location, scanned it with Avast and deleted the threats SEVERAL TIMES, they are not going anywhere. Avast says they have been deleted but few minutes later the same message about threats being detected pops up.
I have tried to download malwarebytes from Cnet.com to remove them but since they have infected my laptop, I CANT DOWNLOAD ANYTHING NOT EVEN A PICTURE OFF THE INTERNET and my laptop has been slowing down. I am extremely upset and feel upset right now and fear for my laptop, my files :cry:

Please help me

Hi,

We need to check that first.

[*] I will be working on your Malware issues this may or may not solve other issues you have with your machine.
[*] The fixes are specific to your problem and should only be used for this issue on this machine.
[*] If you don’t know or understand something, please don’t hesitate to ask.
[*]Please refrain from making any further changes to your computer (Install/Uninstall programs, delete files, edit the registry, etc…)
[*] Please DO NOT run any other tools or scans whilst I am helping you.
[*] It is important that you reply to this thread. Do not start a new topic.
[*] Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
[*] Absence of symptoms does not mean that everything is clear.


Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.

[*]Double-click to run it. When the tool opens click Yes to disclaimer.
[*]Under Optional Scan ensure “List BCD” and “Driver MD5” are ticked.
[*]Press Scan button.
[*]It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
[*]The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Perform a bootscan with avast then do as Magna suggested.

Hi Eddy, :slight_smile:
This type of malware uses embedded nulls and permissions are broken on malware related keys (malware’s loading point), malware also has two loading point (one as backup launcher) therefore AV can not target ZA loading points.
As ZA uses uses embedded to hide full path of loading files, you can’t aim these file like that. Avast boot time scan is a good thing for post cleaning or in case of some other lightware infections, but in ZA cases, it is waste of time. :wink:

Thanks for your swift replies (^_^) I have Avast full system scan running right now, should I stopped it or pausing it is enough?
Also to Eddy, I have no idea what a bootscan is

If you have been start boot time scan, don’t stop it. Finish it first.
avast shall warn you to preform boot time scan, just press Yes and follow the prompts.

But i dont know what boot time scan is. I am only using Avast full system scan and it has been running for about an hour and 45 and scanned 25% of my system.
So I fear that if the scan takes too long, the Trojan Horse will have destroyed my laptop by the time the scan is finished and also, I have important documents to download off my email account :confused:

But i dont know what boot time scan is. I am only using Avast full system scan and it has been running for about an hour and 45 and scanned 25% of my system. So I fear that if the scan takes too long, the Trojan Horse will have destroyed my laptop by the time the scan is finished and also, I have important documents to download off my email account :/
Boot time scan is preforming virus scanning by avast before windows files load in. All in sistem is shutdown and avast can target and kill all malware. Malware is inactiv and it can't defend itself. But this malware uses some technique to hide the full path from AV and other security tools. You may preform virus scanning some other time. Stop scan and preform FRST.

ZA will not brake your system. His misions is to steal information from you, not to brake computer. ;D

I am soooo relieved!! At first I thought I was about to lose everything on my laptop since I have been too lazy to back up. GREAT !! ;D
“Stop scan and preform FRST”
Sorry for my ignorance but i am not really good with IT :-[.
So you want me to STOP Avast full scan right??
What is FRST?
Also since I have checked my email account several times since I got infected, are people in my contact list at risk of getting infected too?

So you want me to STOP Avast full scan right??
yes
What is FRST?
follow instructions magna86 gave you in first post

Thanks for the head up.
I have tried downloading the Farbar scan several times ( I am on firefox right now) but I cant. I cant find it in its location folder. I said in my OP that I couldnt download anything off the internet since my laptop got infected, that is my main problem.

Hey, I have tried Real player browser and so far it is working , I am downloading it right now! I think the issue was with my browsers, I will get back to you soon.

:cry:
NOPE it is not downloading. i cant see them anywhere even in the Downloads folder ;;
OMG I am terrified, is there any other way out of this if I cant download off the internet? I am really desperate now ;
;

Often when you can not download through a web-browser, ftp is still working.

You can also create a Bart-pe bootcd with the utils on it and run them from there.

what is ftp?

http://en.wikipedia.org/wiki/File_Transfer_Protocol

FileZilla is an ftp program, and there are many others.

Almost all browsers support the ftp protocol.

Can anyone then tell me how i can use the ftp protocol to download off the internet or any other alternative?? Also I dont understand IT jargon and at this point I feel totally helpless because I have no clue what to do

@ frankocean89

NOPE it is not downloading. i cant see them anywhere even in the Downloads folder ;_; OMG I am terrified, is there any other way out of this if I cant download off the internet? I am really desperate now ;_;

We shall run FRST in RE.

On a clean machine, please download Farbar Recovery Scan Tool and save it to a flash drive.

Note: You need to run the version compatible with your system.

Plug the flashdrive into the infected PC.

[*]If you are using Windows 8 consult How to use the Windows 8 System Recovery Environment Command Prompt to enter System Recovery Command prompt.
[*]If you are using Vista or Windows 7 enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:

[*]Restart the computer.
[*]As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
[*]Use the arrow keys to select the Repair your computer menu item.
[*]Select US as the keyboard language settings, and then click Next.
[*]Select the operating system you want to repair, and then click Next.
[*]Select your user account an click Next.

Note: In case you can not enter System Recovery Options by using F8 method, you can use Windows installation disc, or make a repair disc. Any Windows installation disc or a repair disc made on another computer can be used.
To make a repair disk on Windows 7 consult: http://www.sevenforums.com/tutorials/2083-system-repair-disc-create.html

To enter System Recovery Options by using Windows installation disc:

[*]Insert the installation disc.
[*]Restart your computer.
[*]If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.[/]
[*]Click Repair your computer.[/
]
[*]Select US as the keyboard language settings, and then click Next.
[*]Select the operating system you want to repair, and then click Next.
[*]Select your user account and click Next.

On the System Recovery Options menu you will get the following options:

Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

http://i1090.photobucket.com/albums/i366/garyr56/W7InstallDisk2.png

Select Command Prompt

Once in the Command Prompt:

[*]In the command window type in notepad and press Enter.
[*]The notepad opens. Under File menu select Open.
[*]Select “Computer” and find your flash drive letter and close the notepad.
[*]In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.
[*]When the tool opens click Yes to disclaimer.
[*]Press Scan button.
[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Sorry for the delay, I had to run to an Internet cafe to download it. Since I am here, is there any other document I would need later that I should download now before going back home?? It is 4:35 and the cafe closes at 5.
I need to go home to start the scan since i cant connect my laptop using the internet cafe connect.