Ran MBAM to remove viruses. Computer still not operating properly.
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.orgDatabase version: v2012.06.17.05
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Denise :: AARONS-PC [administrator]
6/17/2012 9:27:40 AM
mbam-log-2012-06-17 (09-27-40).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 245490
Time elapsed: 30 minute(s), 56 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 1
C:\Windows\System32\hh52516.dll (Trojan.BHO) -> Delete on reboot.
Registry Keys Detected: 14
HKCR\CLSID\{C27AE7F1-2719-3F0C-B71B-18EE9CEF0D8C} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\D.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\D (Trojan.BHO) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C27AE7F1-2719-3F0C-B71B-18EE9CEF0D8C} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\{C27AE7F1-2719-3F0C-B71B-18EE9CEF0D8C} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{C27AE7F1-2719-3F0C-B71B-18EE9CEF0D8C} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C27AE7F1-2719-3F0C-B71B-18EE9CEF0D8C} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\TypeLib\{10F70095-3F7D-3B69-80D6-5C47FC260BC4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\Interface\{6CC06D02-0679-3FC2-A701-7D8E60624874} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\CLSID\{5123CCA0-B3E7-3449-B275-F72C904C7A4D} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{5123CCA0-B3E7-3449-B275-F72C904C7A4D} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5123CCA0-B3E7-3449-B275-F72C904C7A4D} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\TypeLib\{9CBF6174-6634-3079-8049-CDAA9ECC3316} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\Interface\{A89658CF-AE75-340E-90EA-7A4B66FA9C01} (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 3
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKCR\scrfile\shell\open\command| (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and repaired successfully.
HKCR\regfile\shell\open\command| (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 46
C:\Windows\System32\hh52516.dll (Trojan.BHO) -> Delete on reboot.
C:\Windows\System32\config\systemprofile\AppData\Roaming\dwm.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\conhost.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
C:\Windows\System32\pu61003.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\msimg32.dll (Spyware.Password) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache4276.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache46530.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache47643.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache47819.tmp (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache48324.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache49883.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache5416.tmp (Spyware.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache55435.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache25465.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache25944.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache27211.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache2852.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache29085.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache31086.tmp (Spyware.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache10927.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache14538.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache14953.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache56965.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache60493.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache36865.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache40330.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache41460.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache42334.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache17702.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache1813.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache2169.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache21701.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache23400.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache42564.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache55966.tmp (Trojan.FakeMS.Gen) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\B085.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\B90E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\C327.tmp (Backdoor.IRCBot) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\DE46.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\E02A.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\err.log871889 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Aaron's\AppData\Local\Temp\Low\jar_cache8268.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> Delete on reboot.
C:\Windows\Installer\{b0a70ab8-d63a-da0c-e59c-d2793a72d63e}\n (Spyware.Password) -> Delete on reboot.
C:\Windows\Installer\{b0a70ab8-d63a-da0c-e59c-d2793a72d63e}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.
C:\Windows\Installer\{b0a70ab8-d63a-da0c-e59c-d2793a72d63e}\U\80000000.@ (Trojan.Sirefef) -> Quarantined and deleted successfully.
(end)