There are possibly some residual files that are still corrupted because MalwareBytes said it wasn't able to fix everything. I used this removal guide:
http://www.bleepingcomputer.com/virus-remo...-antivirus-softMalwarebytes' Anti-Malware 1.44
Database version: 3765
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
2/20/2010 1:17:19 AM
mbam-log-2010-02-20 (01-17-19).txt
Scan type: Full Scan (C:\|H:\|)
Objects scanned: 650780
Time elapsed: 1 hour(s), 52 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 13
Registry Values Infected: 10
Registry Data Items Infected: 6
Folders Infected: 0
Files Infected: 46
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\oe07ekk.dll (Trojan.Downloader) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{a3ba40a2-74f0-42bd-f434-00b15a2c8953} (Trojan.Downloader) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a3ba40a2-74f0-42bd-f434-00b15a2c8953} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a3ba40a2-74f0-42bd-f434-00b15a2c8953} (Trojan.Downloader) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\_VOID (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOIDd.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ROUA3O12PW (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\TOY5KNQ8OC (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\zodejuhaj (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{a3ba40a2-74f0-42bd-f434-00b15a2c8953} (Trojan.Downloader) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\remote system protection (Trojan.Downloader) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lihacbhp (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lihacbhp (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\asg984jgkfmgasi8ug98jgkfgfb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\uishf9wuifwuh387fh3wufinhjfdwefe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\toy5knq8oc (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.164.230,93.188.166.78 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{80ef2465-3208-4041-aee8-2ce1f2b24d62}\DhcpNameServer (Trojan.DNSChanger) -> Data: 93.188.164.230,93.188.166.78 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{80ef2465-3208-4041-aee8-2ce1f2b24d62}\NameServer (Trojan.DNSChanger) -> Data: 83.149.115.157,4.2.2.1,93.188.164.230,93.188.166.78 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{f22214f4-d0b2-40fa-baf9-171321e0f57d}\NameServer (Trojan.DNSChanger) -> Data: 83.149.115.157,4.2.2.1,192.168.1.1 -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\oe07ekk.dll (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\Jeff\Local Settings\temp\nexdmia9.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\Ylx.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\install.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\000050e0 (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\1565779764.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\1607629330.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\1763548666.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\1885598080.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\234a6c0c.tmp (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\2768494152.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\3014457108.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\492654764.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\avp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\cmd.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\debug.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\drweb.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\eventcreatexp.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\gv5uthsk.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\msinits.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\oxhyanxq.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\qikaoi.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\services.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\setup.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\smss.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\spoolsv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\user.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\vjwmmsku.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\vwwixjz.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\win.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\Ylw.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\07HJT9T5\mqlselg[1].htm (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\07HJT9T5\msdostr[1].exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\07HJT9T5\vzgomuf[1].htm (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\70I0G4PT\hyxrmxs[1].htm (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\70I0G4PT\mdyfelge[1].htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\BJ642SOU\bfzhfdywe[1].htm (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\BJ642SOU\ycpxe[1].htm (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\P7O9C2J9\ysautnmg[1].htm (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\12052008_000318\windows\system32\drivers\zonc.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
H:\Asus Backup Clone\_OTMoveIt\MovedFiles\12052008_000318\windows\system32\drivers\zonc.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\mswintmp.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\_VOIDkrl32mainweq.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Documents and Settings\All Users.WINDOWS\Application Data\_VOIDmainqt.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Documents and Settings\Jeff\Local Settings\Application Data\av.exe (ROGUE.Win7Antispyware2010) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Local Settings\temp\jisfije9fjoiee.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.