You were correct, all desktop icons were hidden, as were all Programs. The background color was changed to red as well.
I may have jumped ahead in my haste, and I apologize...but I ran a full MBAM scan again overnight and "fixed" some more things.
Here's that report:
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.orgDatabase version: 6705
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
6/2/2011 4:51:37 AM
mbam-log-2011-06-02 (04-51-37).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 318088
Time elapsed: 2 hour(s), 3 minute(s), 28 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\system volume information\_restore{a2578cba-012a-4ee9-9e3d-27d3f494a2b6}\RP13\A0016998.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a2578cba-012a-4ee9-9e3d-27d3f494a2b6}\RP13\A0017000.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a2578cba-012a-4ee9-9e3d-27d3f494a2b6}\RP13\A0017001.DLL (Adware.AskSBAR) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a2578cba-012a-4ee9-9e3d-27d3f494a2b6}\RP13\A0017002.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a2578cba-012a-4ee9-9e3d-27d3f494a2b6}\RP14\A0017272.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a2578cba-012a-4ee9-9e3d-27d3f494a2b6}\rp30\a0033316.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
I just now ran the OTS fix you provided, and here is the resulting report:
[Registry - Safe List]
Registry value HKEY_USERS\S-1-5-21-2554975061-1779180781-1490098313-1009\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_USERS\S-1-5-21-2554975061-1779180781-1490098313-1009\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_USERS\S-1-5-21-2554975061-1779180781-1490098313-1009\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\UtYUtxpPbB not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\ not found.
Registry value HKEY_USERS\S-1-5-21-2554975061-1779180781-1490098313-1009\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\ not found.
[Files/Folders - Modified Within 30 Days]
File C:\Documents and Settings\All Users\Application Data\16965412 not found!
File C:\Documents and Settings\All Users\Application Data\~18341668r not found!
File C:\Documents and Settings\All Users\Application Data\~18341668 not found!
File C:\Documents and Settings\Compaq_Owner.PHYLLIS\Desktop\Windows XP Recovery.lnk not found!
File C:\Documents and Settings\All Users\Application Data\18341668 not found!
[Files - No Company Name]
File C:\Documents and Settings\All Users\Application Data\16965412 not found!
File C:\Documents and Settings\All Users\Application Data\~18341668r not found!
File C:\Documents and Settings\All Users\Application Data\~18341668 not found!
File C:\Documents and Settings\Compaq_Owner.PHYLLIS\Desktop\Windows XP Recovery.lnk not found!
File C:\Documents and Settings\All Users\Application Data\18341668 not found!
Restore point Set: OTS Restore Point (0)
< End of fix log >
OTS by OldTimer - Version 3.1.43.0 fix logfile created on 06022011_051255
I will hold off doing anything else until you give the go-ahead.
And again...thanks so much for your help with this!
- John