She was looking for some sort of Reebok sneakers that they don't sell in the stores. "Princess" style or something like that. Anyway, the google search warned her the combo she was searching for had some bad websites, but it got through here AVG anyway.

Here is her Malwarebytes file. Running GMER now per stickied instructions.

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4404

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

8/8/2010 10:27:01 AM
mbam-log-2010-08-08 (10-27-01).txt

Scan type: Quick scan
Objects scanned: 143034
Time elapsed: 20 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Margaret\Local Settings\Temp\svchost.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.