Ok followed all the instructions,it seems to be working a lot better but i wanted to double check with you guys before making any conclusions.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 5001
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
10/30/2010 7:01:06 PM
mbam-log-2010-10-30 (19-01-06).txt
Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 313019
Time elapsed: 1 hour(s), 3 minute(s), 55 second(s)
Memory Processes Infected: 4
Memory Modules Infected: 3
Registry Keys Infected: 102
Registry Values Infected: 2
Registry Data Items Infected: 4
Folders Infected: 2
Files Infected: 39
Memory Processes Infected:
c:\programdata\ir50_qc32.exe (Trojan.Tracur) -> Unloaded process successfully.
c:\programdata\api-ms-win-core-memory-l1-1-032.exe (Trojan.Tracur) -> Unloaded process successfully.
C:\ProgramData\WsmRes32.exe (Trojan.Tracur) -> Unloaded process successfully.
C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-032.exe (Trojan.Tracur) -> Unloaded process successfully.
Memory Modules Infected:
C:\ProgramData\ir50_qc32.dll (Trojan.Tracur) -> Delete on reboot.
C:\Windows\System32\config\systemprofile\AppData\Roaming\D91F.tmp (Trojan.Tracur) -> Delete on reboot.
C:\Users\clehigh\AppData\Local\KBDLes.dll (Trojan.Hiloti) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vss32 (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1915590a-ead8-83b5-faa2-70e93fa820cd} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1915590a-ead8-83b5-faa2-70e93fa820cd} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a6e91e3c-6fc0-df9a-6f90-ec10acaa7051} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a6e91e3c-6fc0-df9a-6f90-ec10acaa7051} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b02f530b-5a61-653b-f6cd-967c79271e6a} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b02f530b-5a61-653b-f6cd-967c79271e6a} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f1cf1665-b497-b3a3-d7a1-100f19163d22} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f1cf1665-b497-b3a3-d7a1-100f19163d22} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{09794aad-bd6c-4e4b-b0f7-cc81335a2145} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{09794aad-bd6c-4e4b-b0f7-cc81335a2145} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{227276bb-4b9a-75da-3dca-66fb7219f22c} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{227276bb-4b9a-75da-3dca-66fb7219f22c} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2909414b-5416-b9b4-ef70-b405692858ec} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2909414b-5416-b9b4-ef70-b405692858ec} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3bac86e3-3df7-81ee-4147-55f42eed5f2d} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3bac86e3-3df7-81ee-4147-55f42eed5f2d} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3ecbb1e6-d40f-32ce-7cee-9daf87800363} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3ecbb1e6-d40f-32ce-7cee-9daf87800363} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4f704af0-bbf2-6cf7-c502-2131ec65acb1} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f704af0-bbf2-6cf7-c502-2131ec65acb1} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5ab42b4d-a790-80a9-5303-e90a1ac2b7bd} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5ab42b4d-a790-80a9-5303-e90a1ac2b7bd} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6e571a72-906e-d8f5-ae9e-a8683f651cf0} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6e571a72-906e-d8f5-ae9e-a8683f651cf0} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9aa43ddf-8321-cbe8-e190-23377f4d6546} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9aa43ddf-8321-cbe8-e190-23377f4d6546} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a0ab2b8f-a516-9e55-680e-3dbad3cc4329} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a0ab2b8f-a516-9e55-680e-3dbad3cc4329} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4b20b57-6288-c136-78ff-59afed22a8d4} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4b20b57-6288-c136-78ff-59afed22a8d4} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a5175f41-2409-89a9-cebf-620a8c054b5b} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a5175f41-2409-89a9-cebf-620a8c054b5b} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ab28655b-396d-92ce-6e4f-7cf925a74087} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ab28655b-396d-92ce-6e4f-7cf925a74087} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b4a6f399-ccc6-f735-6ccd-9dcb16a2e0f3} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b4a6f399-ccc6-f735-6ccd-9dcb16a2e0f3} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bb742680-e27d-ca62-0d40-60c86c5ab13e} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bb742680-e27d-ca62-0d40-60c86c5ab13e} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c7819f87-c1e1-4fc2-ad73-b3ad3b0e51be} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c7819f87-c1e1-4fc2-ad73-b3ad3b0e51be} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d1c7d556-ad83-d463-33b0-5e19078bffd7} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d1c7d556-ad83-d463-33b0-5e19078bffd7} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f4b7da12-3e74-d531-2479-e3d7140276ce} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f4b7da12-3e74-d531-2479-e3d7140276ce} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{fa9df4db-ca4c-15e1-81d8-f17ad0ad6b5f} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fa9df4db-ca4c-15e1-81d8-f17ad0ad6b5f} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2a257ecc-739c-a456-466f-b5d31916a2a3} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2a257ecc-739c-a456-466f-b5d31916a2a3} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2a257ecc-739c-a456-466f-b5d31916a2a3} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6528e954-e5f3-1ef0-d267-46bd4d2f838d} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6528e954-e5f3-1ef0-d267-46bd4d2f838d} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{671a19dd-6141-e723-2f8e-fb842c5e7690} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{671a19dd-6141-e723-2f8e-fb842c5e7690} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{671a19dd-6141-e723-2f8e-fb842c5e7690} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6be07ae5-1e0a-45fb-379f-a219a2ea5a66} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6be07ae5-1e0a-45fb-379f-a219a2ea5a66} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{75730417-a7b1-fc72-cd7e-ac54f4bf0b0f} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{75730417-a7b1-fc72-cd7e-ac54f4bf0b0f} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75730417-a7b1-fc72-cd7e-ac54f4bf0b0f} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{760261e9-c6c5-4627-d749-b3abcf2beaa4} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{760261e9-c6c5-4627-d749-b3abcf2beaa4} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8768e79f-2b38-c5ad-9af2-d3234bb93030} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8768e79f-2b38-c5ad-9af2-d3234bb93030} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8768e79f-2b38-c5ad-9af2-d3234bb93030} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{984db96d-4451-3a41-2ea9-6516013bcfbc} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{984db96d-4451-3a41-2ea9-6516013bcfbc} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9dc368e2-1a39-7cc8-1c36-6bf2d8e1097d} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dc368e2-1a39-7cc8-1c36-6bf2d8e1097d} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9e53a81d-6546-0daf-b527-809955bbac9f} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9e53a81d-6546-0daf-b527-809955bbac9f} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ae47905e-d085-43ae-a9f5-c4b47f3be4be} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ae47905e-d085-43ae-a9f5-c4b47f3be4be} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b8885e08-7791-0360-73cc-b83e3d3b4065} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8885e08-7791-0360-73cc-b83e3d3b4065} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bb8b1c4a-bd21-e672-41b9-aafb0c774dbc} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bb8b1c4a-bd21-e672-41b9-aafb0c774dbc} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d3a50f56-7ce9-f132-801e-51c7a9e18ebd} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d3a50f56-7ce9-f132-801e-51c7a9e18ebd} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{de4710dc-6b55-902c-5f2d-83ee5656210f} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{de4710dc-6b55-902c-5f2d-83ee5656210f} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e2289070-4be2-5d07-6b02-2b51af1880ca} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e2289070-4be2-5d07-6b02-2b51af1880ca} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e36b19ed-9563-9d9d-8588-ff08cd500617} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e36b19ed-9563-9d9d-8588-ff08cd500617} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e36b19ed-9563-9d9d-8588-ff08cd500617} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{eab687bc-04b6-b738-98cd-d2461418f512} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{eab687bc-04b6-b738-98cd-d2461418f512} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f1077ebc-c0d2-42f6-c66f-850378bea7ad} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f1077ebc-c0d2-42f6-c66f-850378bea7ad} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f4bcdab2-b9e4-cbc7-21ae-4dc7c43d7223} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f4bcdab2-b9e4-cbc7-21ae-4dc7c43d7223} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5ae2ef1-bb7e-4aad-c742-27e6114b9d18} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f5ae2ef1-bb7e-4aad-c742-27e6114b9d18} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f5ea6a42-d6e4-45ef-1131-752c31963c3a} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f5ea6a42-d6e4-45ef-1131-752c31963c3a} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wersvc32 (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{01d4a14f-1259-42dd-be2b-b0c27c7f7eb1} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{01d4a14f-1259-42dd-be2b-b0c27c7f7eb1} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{01d4a14f-1259-42dd-be2b-b0c27c7f7eb1} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01d4a14f-1259-42dd-be2b-b0c27c7f7eb1} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ewijoziyi (Trojan.Hiloti) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rthdbpl (Trojan.Tracur) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\programdata\ir50_qc32.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\programdata\api-ms-win-core-memory-l1-1-032.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\programdata\api-ms-win-core-misc-l1-1-032.dll -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.StartPage) -> Bad: (
http://dymasearch.com/) Good: (
http://www.google.com) -> Quarantined and deleted successfully.
Folders Infected:
C:\ProgramData\1985737549 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\clehigh\AppData\Roaming\SysWin (Trojan.Agent) -> Quarantined and deleted successfully.
Files Infected:
c:\programdata\ir50_qc32.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\ir50_qc32.dll (Trojan.Tracur) -> Delete on reboot.
C:\Windows\System32\config\systemprofile\AppData\Roaming\D91F.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
c:\programdata\api-ms-win-core-memory-l1-1-032.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\WsmRes32.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-032.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\clehigh\AppData\Local\KBDLes.dll (Trojan.Hiloti) -> Delete on reboot.
C:\Users\clehigh\AppData\Roaming\SysWin\lsass.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\1808284557c1 (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\1808284557c2 (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\1808284557c3 (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\1808284557c4 (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\api-ms-win-core-memory-l1-1-032.dll (Trojan.Tracur) -> Delete on reboot.
C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll (Trojan.Tracur) -> Delete on reboot.
C:\ProgramData\iscsidsc32.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\iTVData32.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\clehigh\Desktop\setup\QuickTime_Update_KB118012.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\System32\api-ms-win-core-localregistry-l1-1-032.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\System32\api-ms-win-core-memory-l1-1-032.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\System32\api-ms-win-core-misc-l1-1-032.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\System32\duwkr.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\Windows\System32\iscsium32.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\System32\iTVData32.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\System32\jffy.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\Windows\System32\pdqe.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\Windows\System32\config\systemprofile\AppData\Roaming\31AB.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\config\systemprofile\AppData\Roaming\F316.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-032.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-032.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\duwkr.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\iscsium32.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\iTVData32.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\jffy.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\pdqe.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\31AB.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\D91F.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\F316.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\System32\winset.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\Windows\System32\GnuHashes.ini (Trojan.Tracur) -> Quarantined and deleted successfully.
--------------------------------------------------------------------------------------------------------
GMER 1.0.15.15477 -
http://www.gmer.net
Rootkit scan 2010-10-30 19:30:26
Windows 6.1.7600
Running: q3f2233u.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x31 0x69 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA7 0x9E 0x3C 0xCF ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x5A 0x8D 0xC0 0x4E ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xC9 0xF8 0x63 0x3A ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x31 0x69 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA7 0x9E 0x3C 0xCF ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x5A 0x8D 0xC0 0x4E ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xC9 0xF8 0x63 0x3A ...
---- EOF - GMER 1.0.15 ----