Hi all.
Managed to infect my pc with some malware, constantly trying to link through to a dodgy URL. Avast keeps popping up to warn me every few minutes.
Have gone through the steps recommended at: http://forum.avast.com/index.php?topic=53253.0 and logs files are attached (MBAM.log pasted below. OTL, Extras, and aswMBR attached).
Could someone please have a look through and tell me if I have to do anything else, or am I in the clear?
Many thanks in advance!
MBAM log:
Malwarebytes’ Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8105
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
07/11/2011 10:16:09
mbam-log-2011-11-07 (10-16-09).txt
Scan type: Quick scan
Objects scanned: 218195
Time elapsed: 19 minute(s), 0 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 5
Memory Processes Infected:
c:\documents and settings\administrator\start menu\Programs\Startup\winlogon.exe (Trojan.Agent) → 456 → Unloaded process successfully.
c:\documents and settings\administrator\start menu\Programs\Startup\winlogon.exe (Trojan.Agent) → 536 → Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Uyomog (Trojan.Agent) → Value: Uyomog → Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4Y3Y0C3AXF7W1HXVFBLJNVO (Trojan.SpyEyes) → Value: 4Y3Y0C3AXF7W1HXVFBLJNVO → Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Recycle.Bin (Trojan.Spyeyes) → Quarantined and deleted successfully.
Files Infected:
c:\documents and settings\administrator\start menu\Programs\Startup\winlogon.exe (Trojan.Agent) → Quarantined and deleted successfully.
c:\documents and settings\administrator\application data\uyomog.exe (Trojan.Agent) → Quarantined and deleted successfully.
c:\documents and settings\administrator\application data\3EBE.tmp (Trojan.Agent) → Quarantined and deleted successfully.
c:\documents and settings\administrator\application data\7.exe (Trojan.Downloader) → Quarantined and deleted successfully.
c:\Recycle.Bin\51fce571337df17 (Trojan.Spyeyes) → Quarantined and deleted successfully.