Possibly infected - how can I tell and how can I fix?
Tonight around 10:30 I visited a web site that started installing something on my computer. (It was a totally innocent site - a wind ensemble that some friends play in - and I will let them know that their site was apparently hacked.)
I closed everything and started running a McAfee scan, which detected several programs and cookies right away. I deleted them, but another virus scanner appeared in my system tray and kept popping up, prompting me to purchase the full version. I did not, of course, but couldn't close or uninstall it. (After doing some research, I'm certain this was part of the malware.)
I used System Restore to return to a restore point from two days ago. The computer rebooted and I went to run McAfee again, but this time it would not run a scan and kept telling me I wasn't fully protected, but couldn't fix this "due to an error." On my own, I searched my C drive for suspicious looking files with a modification date and time after 10:30 tonight. I found one right in C:\ with a jumble of letters and numbers for a filename (sorry, don't know exactly what it was, I deleted and emptied the trash). Deleting this file seemed to repair McAfee, and the warnings I wasn't fully protected went away. I was also able to start up a full scan again. The fake antivirus software has also not appeared.
There is one file, wiadebug.lnk, that is located in my C:\WINDOWS and I can't delete because it says something is using it. Here is the content of the file:
====================Start 'wiaservc.dll' Debug - Time: 2009/07/06 22:47:59:609====================
*> StiServiceMain entered, Time: 2009/07/06 22:47:59:609
CWiaDevMgr::CreateDevice Failed to find device:
CDrvWrap::WIA_drvInitializeWia, exception in drvInitializeWia: 0xC0000005
CreateLocalDevice drvInitializeWia failed. lDevErrVal: 0x00000000 hr: 0x8021000E
CWiaDevMgr::CreateDevice Failed to find device:
CDrvWrap::WIA_drvInitializeWia, exception in drvInitializeWia: 0xC0000005
CreateLocalDevice drvInitializeWia failed. lDevErrVal: 0x00000000 hr: 0x8021000E
I ran another McAfee scan, which didn't find anything, but in reading about this type of virus it seems that it can somehow hide itself from McAfee at some point. I'm currently installing Kaspersky to do an online scan. I never get viruses or anything, and am always diligent about running regular scans and stuff, so I'm very worried. Is it possible I took care of it myself? If not, what else should I be doing to check and correct the problem?
Thanks for your help!
Sorry, forgot relevant info:
Running Windows XP Home Edition (I believe SP3)
Use Firefox 2.0
Sorry, one more, here is the HJT log file:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:11:14 AM, on 7/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Results of Kaspersky scan - found 2 infected files:
C:\Documents and Settings\Linnea\Local Settings\Temp\1087565664mxx.dll Infected: Trojan-GameThief.Win32.WOW.ijw 1
C:\Documents and Settings\Linnea\Local Settings\Temp\install.48349.exe Infected: Trojan-Downloader.Win32.FraudLoad.exe 1
...I did a search of my computer and can't find either the files or the Local Settings folder it says they're in (is it a hidden folder?). So I can't check whether these are new as of tonight, or if they're something that was already affecting my computer.