Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.orgDatabase version: v2012.04.05.07
Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Joe :: JOE-PC [administrator]
4/5/2012 12:49:41 PM
mbam-log-2012-04-05 (12-49-41).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 197190
Time elapsed: 3 minute(s), 27 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 1
C:\Users\Joe\AppData\Roaming\Creative\Creative\buhjtfc.dll (Trojan.Tracur) -> Delete on reboot.
Registry Keys Detected: 3
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{258C9770-1713-4021-8D7E-1F184A2BD754} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BDEA95CF-F0E6-41E0-BD3D-B00F39A4E939} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully.
Registry Values Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Update (Trojan.Tracur) -> Data: rundll32.exe "C:\Users\Joe\AppData\Roaming\Creative\Creative\buhjtfc.dll",DllRegisterServer -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 6
C:\Users\Joe\AppData\Roaming\Creative\Creative\buhjtfc.dll (Trojan.Tracur) -> Delete on reboot.
C:\Users\Joe\AppData\Roaming\Creative\Creative\ivzucplz.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Joe\AppData\Local\Temp\arg268359.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Joe\AppData\Local\Temp\nsj4453.tmp\buhjtfc.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\Joe\AppData\Local\Temp\nsj4453.tmp\ivzucplz.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
(end)