So, my computer got infected yesterday. I’m not sure how, but it did. Every few minutes avast would warn me that a threat was detected (with the process in svchost), and whenever I would do a google search it would tell me a threat was detected (with the process in firefox.exe). This worried me, and I like to take extreme actions when I’m worried, so I ran a boot time scan. 3 threats were found (Win32:Alureon-JE (which I can not find anything about, though I can find information on Win32:Alureon-EJ which would explain my google warnings), Java:Agent-P, and Java:Djewers-S). I moved all of these to the chest and figured I was good. But as I browsed the internet, I realized the same warnings were popping up. I decided to run a full system scan, and 15 minutes into it started a quick scan. The quick scan ended first, obviously, and found 4 threats (Win32:Rootkit-gen, Win32:Oficla-AH, Win32:Oficla-AH (yes, twice, apparently), and JS:Downloader-AGK). I tried to delete all of them, but only the first three were successfully deleted. I then tried to move the last on to the chest, but it failed, with the message “Error: The system cannot find the file specified (2)”. That scan took 37:58, if that means anything at all.
Not long after, the full scan ended. It took 1:21:53. It found the same 4 files, three of which I had already deleted and thus when I tried to take action with them, they couldn’t be found. This is no surprise. The fourth did the same thing as before, i.e, nothing, which bothers me.
Curious, I did a google search, and sure enough, Avast warned me that a threat was detected. So I ran one more quick scan. This one was much much faster (only 5:48!), and it found only one infection–the same one that it can’t seem to find when I want to fix it. So…being not very computer savvy myself, I figured I’d ask for help here. How can I kill this guy?
If you need more information, just ask. According to my scan logs, the file name where the infection is located is as follows:
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KI9LY1L5\kwfsazksymcuazdv[1].htm
(Also, both firefox and internet explorer look aesthetically different than they did before. I just upgraded firefox to 3.5.13 (I’ll get 3.6 once this is dealt with), but I don’t think that should change the appearance, and I haven’t upgraded IE at all recently (I have version 7.0.6001.18000, apparently), so I don’t know if the virus is screwing with things or if it’s entirely unrelated.)