I am not computer saavy and have been doing my best by reading the topics and taking what steps I can understand. My computer is using Windows XP, my updates are set on “automatic” and update every day. I am currently using Avast4 Home Edition, Spybot Search and Destroy, Spyware Blaster, and I just downloaded Malwarebytes Anti-Malware.
For two weeks now, Avast has been giving warnings to the effect of “Suspicious file has been found using the heuristic method”. The recommended action is always “ignore” and I have done just that.
Avast has also found many files infected with the Win32:trojan, Win32:trojan-gen, and Win32:rootkit-gen. The recommended action has been “move to chest” so I have done that. However, I was unaware until this evening that those files should not be deleted. I deleted all of the files that have been moved to the chest. I have no idea how many files have been moved and deleted thus far.
When I have schedule boot-time scans, I have set “move all infected files to chest” under “Advanced Settings” and have set “ignore or take no action with system files”. On two occasions, I have turned off system restore and re-started in safe mode while completing a boot time scan.
Here is a copy of the scan results that I got from “program files - alwil - Avast4”:
06/17/2009 17:37
Scan of all local drives
Number of searched folders: 6589
Number of tested files: 70430
Number of infected files: 0
06/17/2009 18:28
Scan of all local drives
Number of searched folders: 6589
Number of tested files: 70308
Number of infected files: 0
06/18/2009 17:54
Scan of all local drives
File C:\66y01b.cmd is infected by Win32:Kavos [Trj], Moved to chest
File C:\kyl0q3xg.bat is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP331\A0027070.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP331\A0027071.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP331\A0027073.cmd is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP331\A0028066.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP331\A0028068.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP331\A0028071.cmd is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP331\A0028101.exe is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP331\A0028105.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028114.cmd is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028128.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028130.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028132.cmd is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028136.exe is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028164.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028166.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028174.bat is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028191.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028193.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028199.bat is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028224.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028226.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028229.bat is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028232.exe is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028249.cmd is infected by Win32:Kavos [Trj], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP332\A0028250.bat is infected by Win32:Kavos [Trj], Moved to chest
File C:\WINDOWS\system32\ahnfgss1.dll is infected by Win32:Kavos [Trj], Moved to chest
File C:\WINDOWS\system32\trz5.tmp is infected by Win32:Kavos [Trj], Moved to chest
Number of searched folders: 6558
Number of tested files: 69660
Number of infected files: 29
06/29/2009 21:22
Scan of all local drives
Number of searched folders: 6418
Number of tested files: 62378
Number of infected files: 0
06/29/2009 22:40
Scan of all local drives
Number of searched folders: 6418
Number of tested files: 62423
Number of infected files: 0
06/30/2009 05:36
Scan of all local drives
Number of searched folders: 6418
Number of tested files: 62460
Number of infected files: 0
07/02/2009 19:13
Scan of all local drives
Number of searched folders: 6472
Number of tested files: 62582
Number of infected files: 0
07/02/2009 21:42
Scan of all local drives
Number of searched folders: 6477
Number of tested files: 62665
Number of infected files: 0
07/07/2009 19:21
Scan of all local drives
File C:\gyaa.exe is infected by Win32:Rootkit-gen [Rtk], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000013.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000040.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000074.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP3\A0000118.exe is infected by Win32:Rootkit-gen [Rtk], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP3\A0000136.exe is infected by Win32:Rootkit-gen [Rtk], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP3\A0000140.exe is infected by Win32:Rootkit-gen [Rtk], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP3\A0000141.dll is infected by Win32:Rootkit-gen [Rtk], Moved to chest
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP3\A0000157.exe is infected by Win32:Rootkit-gen [Rtk], Moved to chest
Number of searched folders: 6492
Number of tested files: 62889
Number of infected files: 9
I would like to know how to completely clean my computer as well as to figure out if I have done any damage by deleting the infected files. Sorry for my ignorance and thanks so much for your help!!