Avast full system scans have been reporting a lot of password protected files that could not be scanned (example) so I ran a boot-time scan. These were the results, and I opted to delete all the files which Avast reported success in doing. I ran Avast Antirootkit and these were my results:
avast! Antirootkit, version 0.9.6File C:## aswSnx private storage HIDDEN
File C:## aswSnx private storage\snx_rhive HIDDEN
File C:## aswSnx private storage\snx_rhive.LOG HIDDEN
File C:## aswSnx private storage\webStorage HIDDEN
File C:## aswSnx private storage\webStorage\attrib HIDDEN
File C:## aswSnx private storage\webStorage\image HIDDEN
File C:## aswSnx private storage\webStorage\snx_fs.dat HIDDENHidden files found: 7
Hidden registry items found: 0
Hidden processes found: 0
Hidden services found: 0
Hidden boot sectors found: 0
Another one, after disabling System Restore:
avast! Antirootkit, version 0.9.6File C:## aswSnx private storage HIDDEN
File C:## aswSnx private storage\webStorage HIDDENHidden files found: 2
Hidden registry items found: 0
Hidden processes found: 0
Hidden services found: 0
Hidden boot sectors found: 0
Another one, I think after I connected my external hard drive to scan for viruses, and then running another boot-time scan which came up clean:
avast! Antirootkit, version 0.9.6Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4018\Shell] MinPos1024x768(1).x=-1 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4018\Shell] MinPos1024x768(1).y=-1 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4038\Shell] FolderType=“Music” HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4038\Shell] MinPos1024x768(1).x=-1 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4038\Shell] MinPos1024x768(1).y=-1 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4038\Shell] WinPos1024x768(1).left=139 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4038\Shell] WinPos1024x768(1).top=46 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4038\Shell] WinPos1024x768(1).right=939 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4038\Shell] WinPos1024x768(1).bottom=646 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4038\Shell] Vid=“{65F125E5-7BE1-4810-BA9D-D271C8432CE3}” HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4038\Shell] Mode=6 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4038\Shell] Col=0 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4097\Shell] MinPos1024x768(1).x=-1 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4097\Shell] MinPos1024x768(1).y=-1 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4519\Shell] FolderType=“MusicArtist” HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4519\Shell] MinPos1024x768(1).x=-1 HIDDEN
Registry item [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\4519\Shell] MinPos1024x768(1).y=-1 HIDDEN
avast! Antirootkit, version 0.9.6Hidden files found: 0
Hidden registry items found: 0
Hidden processes found: 0
Hidden services found: 0
Hidden boot sectors found: 0
So I’m wondering, is my computer still infected? Another computer using the same router had the same infected Combofix files as well.