Should this have removed this infection successfully? Where might I have picked it up, attempt to use Frostwire to download Matlab and PaintShop PRO?
Malwarebytes’ Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6711
Windows 6.1.7600
Internet Explorer 9.0.8112.16421
29/05/2011 13:11:02
mbam-log-2011-05-29 (13-11-02).txt
Scan type: Full scan (C:|D:|Q:|)
Objects scanned: 331077
Time elapsed: 55 minute(s), 10 second(s)
Memory Processes Infected: 4
Memory Modules Infected: 1
Registry Keys Infected: 5
Registry Values Infected: 3
Registry Data Items Infected: 1
Folders Infected: 1
Files Infected: 11
Memory Processes Infected:
c:\Windows\SysWOW64\KBDCZ232.exe (Trojan.Tracur.SGen) → 2276 → Unloaded process successfully.
c:\programdata\icsigd32.exe (Trojan.Tracur.SGen) → 3268 → Unloaded process successfully.
c:\Users\MCGA\AppData\Roaming\SysWin\lsass.exe (Trojan.Tracur.SGen) → 3468 → Unloaded process successfully.
c:\Windows\sqlserverspatialwow.exe (Trojan.Tracur.SGen) → 1224 → Unloaded process successfully.
Memory Modules Infected:
c:\programdata\api-ms-win-core-misc-l1-1-032.dll (Trojan.Tracur.S) → Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID{0ED4C89D-152A-4D16-AD41-0B5B94571439} (Trojan.Tracur.S) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{0ED4C89D-152A-4D16-AD41-0B5B94571439} (Trojan.Tracur.S) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings{0ED4C89D-152A-4D16-AD41-0B5B94571439} (Trojan.Tracur.S) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{0ED4C89D-152A-4D16-AD41-0B5B94571439} (Trojan.Tracur.S) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT.fsharproj (Trojan.BHO) → Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\RTHDBPL (Trojan.Tracur.SGen) → Value: RTHDBPL → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sqlserverspatialwow.exe (Trojan.Tracur.SGen) → Value: sqlserverspatialwow.exe → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dsdmowow.exe (Trojan.TracurW.Gen) → Value: dsdmowow.exe → Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur.S) → Bad: (C:\ProgramData\api-ms-win-core-misc-l1-1-032.dll) Good: () → Quarantined and deleted successfully.
Folders Infected:
c:\Users\MCGA\AppData\Roaming\SysWin (Trojan.Agent) → Quarantined and deleted successfully.
Files Infected:
c:\Windows\SysWOW64\KBDCZ232.exe (Trojan.Tracur.SGen) → Quarantined and deleted successfully.
c:\programdata\api-ms-win-core-misc-l1-1-032.dll (Trojan.Tracur.S) → Quarantined and deleted successfully.
c:\programdata\icsigd32.exe (Trojan.Tracur.SGen) → Quarantined and deleted successfully.
c:\Users\MCGA\AppData\Roaming\SysWin\lsass.exe (Trojan.Tracur.SGen) → Quarantined and deleted successfully.
c:\Windows\sqlserverspatialwow.exe (Trojan.Tracur.SGen) → Quarantined and deleted successfully.
c:\Windows\System32\KBDCZ232.exe (Trojan.Tracur.SGen) → Quarantined and deleted successfully.
c:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-032.dll (Trojan.Tracur.S) → Quarantined and deleted successfully.
c:\Users\MCGA\downloads\retrogamer.exe (Adware.FunWeb) → Quarantined and deleted successfully.
c:\Windows\System32\api-ms-win-core-misc-l1-1-032.dll (Trojan.Tracur.S) → Quarantined and deleted successfully.
c:\Windows\System32\icsigd32.exe (Trojan.Tracur.SGen) → Quarantined and deleted successfully.
c:\Windows\SysWOW64\icsigd32.exe (Trojan.Tracur.SGen) → Quarantined and deleted successfully.