Well, life is getting better. I'm not sure if I followed instructions to a T, but I can at least have my own homepage now. When I ran the Panda scan, I couldn't figure out where the "autoclean" box was so perhaps I have to do it again? I appreciate your wisdom and knowledge. Let me know what I should do next.
Logfile of HijackThis v1.99.1
Scan saved at 2:45:37 PM, on 7/10/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\Program Files\ViRobotXP\vrmonsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\ViRobotXP\vrmonnt.exe
C:\Program Files\ViRobotXP\Vrres.exe
C:\Program Files\PCSecurityShield\The Shield Firewall\FireWall.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe
C:\Program Files\iWare\iWare Mouse\3.2\lwbwheel.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://jfadbbdrsklvq...jeC8GdZYzZ.htmlR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll (file missing)
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Vrmon] C:\Program Files\ViRobotXP\vrmonnt.exe Main
O4 - HKLM\..\Run: [VrSchedule] C:\Program Files\ViRobotXP\Vrres.exe
O4 - HKLM\..\Run: [dwStart] C:\Program Files\PCSecurityShield\The Shield Firewall\FireWall.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\iWare\iWare Mouse\3.2\lwbwheel.exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [BIOV] C:\WINDOWS\BIOV.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Bib camp less option] C:\Documents and Settings\All Users\Application Data\Software stop bib camp\SeekMedia.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [Rdr Option] C:\DOCUME~1\Mary\APPLIC~1\INTERA~1\Fork Help Build.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'farlsp.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Hearts -
http://download.game...nts/y/ht1_x.cabO16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -
http://www.nick.com/.../GrooveAX27.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: ViRobot Expert Monitoring (vrmonsvc) - HAURI - C:\Program Files\ViRobotXP\vrmonsvc.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 1:06:56 PM, 7/10/2005
+ Report-Checksum: D179F947
+ Scan result:
C:\Documents and Settings\Mary\Cookies\mary@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\mary@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\mary@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\
[email protected][1].txt -> Spyware.Cookie.Lop : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\mary@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\
[email protected][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\Hijackthis\backups\backup-20050709-234422-934.dll -> Trojan.Puper.m : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1179\A0278264.exe -> TrojanDownloader.Small.gr : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1179\A0278268.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1179\A0278269.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1179\A0278270.dll -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1179\A0278271.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1179\A0278272.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1179\A0278273.exe -> Trojan.Puper.w : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1179\A0278274.exe -> Trojan.Puper.w : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1180\A0278280.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1180\A0278281.dll -> Trojan.Agent.ff : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1180\A0278299.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1180\A0278348.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1180\A0278412.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1180\A0278433.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1180\A0278451.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1180\A0278467.dll -> Trojan.Puper.t : Cleaned with backup
::Report End
Pre-run Files Present
~~~ Program Files ~~~
~~~ Shortcuts ~~~
PSGuard.com
~~~ system32 ~~~
hp***.tmp
shnlog.exe
intmon.exe
hhk.dll
~~~ Windows directory ~~~
~~~ Drive root ~~~
Post-run Files Present
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ system32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Wininet.dll ~~~
Infected!
~~~ Replaced wininet.dll from dllcache ~~~
~~~ Upon reboot ~~~
wininet.old present!
oleadm.dll not present!
~~~ Upon completion ~~~
wininet.old not present!
oleadm.dll not present!
Panda scan
Incident Status Location
Adware:Adware/Lop No disinfected c:\docume~1\mary\locals~1\temp\nyqzgidf.exe
Adware:Adware/Lop No disinfected C:\DOCUME~1\ALLUSE~1\APPLIC~1\SOFTWA~1\SEEKME~1.EXE
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\Bargain Buddy
Adware:Adware/MyWay No disinfected C:\Program Files\MyWay
Adware:Adware/nCase No disinfected C:\WINDOWS\msbb*
Adware:Adware/CWS No disinfected C:\Documents and Settings\Mary\Favorites\Online Gambling\Online Gambling.url
Adware:Adware/SideSearch No disinfected C:\Documents and Settings\Mary\Application Data\Lycos
Adware:Adware/ExactSearch No disinfected Windows Registry
Adware:Adware/SuperSpider No disinfected C:\Documents and Settings\Mary\Favorites\online dating.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Mary\Favorites\Black Jack Online.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy\Adipex.url
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\01 NOUN.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\active bone.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\bikeregs.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\CakePhone.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\cash save.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\download aim.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\FORGLUE.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\Heart deaf.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\Livedownload.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\ooze bat.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\safevc.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\SeekMedia.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\Thatpoke.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\All Users\Application Data\Software stop bib camp\wma ford.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Application Data\Inter Amen\attcfeja.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Application Data\Inter Amen\Error Internet Spam.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Application Data\Inter Amen\Fork Help Build.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Application Data\Inter Amen\multi bits ace find.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Application Data\Inter Amen\zcfhgxrz.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Application Data\meet for dent\ItchBone.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Local Settings\Temp\aepyfgaf.exe
Adware:Adware/Envolo No disinfected C:\Documents and Settings\Bob\Local Settings\Temp\AutoUpdate0\setup.inf
Adware:Adware/WinActive No disinfected C:\Documents and Settings\Bob\Local Settings\Temp\bz2289.tmp[bz2289.tmp]
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Local Settings\Temp\eiujgjjy.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Local Settings\Temp\izcqsvez.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Local Settings\Temp\omflfqhm.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Local Settings\Temp\pch287.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Local Settings\Temp\pch289.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Local Settings\Temp\pch331.exe
Adware:Adware/WinTools No disinfected C:\Documents and Settings\Bob\Local Settings\Temp\temp.cab[toolbar.dll]
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Local Settings\Temp\uleqtsiw.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Bob\Local Settings\Temp\wyxyucmq.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Connor\Application Data\Inter Amen\Error Internet Spam.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Connor\Application Data\Inter Amen\Fork Help Build.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Connor\Application Data\Inter Amen\multi bits ace find.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Connor\Application Data\Inter Amen\oswunemf.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Connor\Application Data\Inter Amen\pyaqbfqr.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Connor\Application Data\Inter Amen\rxivtcry.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Connor\Local Settings\Temp\cnkxqdxk.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Connor\Local Settings\Temp\Inside Program.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Connor\Local Settings\Temporary Internet Files\Content.IE5\V6C7JT01\upAYB[1].int
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\azkljxkx.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\cezthlgd.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\ddxgqbwq.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\Error Internet Spam.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\Fork Help Build.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\gtckeeaw.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\hpdnkdzd.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\jatojvfm.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\jwwcwseo.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\multi bits ace find.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\nvdyanji.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\rgdhhmws.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\xewyxbxk.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Application Data\Inter Amen\xvoijlkt.exe
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Mary\Favorites\Black Jack Online.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Mary\Favorites\Home Loan.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Mary\Favorites\Network Security.url
Adware:Adware/SuperSpider No disinfected C:\Documents and Settings\Mary\Favorites\Online Dating.url
Adware:Adware/CWS No disinfected C:\Documents and Settings\Mary\Favorites\Online Gambling\Online Gambling.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Mary\Favorites\Online Gambling.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy\Adipex.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy\Alprazolam.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy\Carisoprodol.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy\Diazepam.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy\Hydrocodone.url
Adware:Adware/CWS No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy\Lortab.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy\Online Pharmacy.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy\Prozac.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy\Valium.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy\Vicodin.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy\Xanax.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Mary\Favorites\Online Pharmacy.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Mary\Favorites\Remove Spyware.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Mary\Favorites\Spam Filters.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Mary\Favorites\Web Detective.url
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Local Settings\Temp\nyqzgidf.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Mary\Local Settings\Temp\vzcmayix.exe
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\bargain.exe
Adware:Adware/nCase No disinfected C:\WINDOWS\msbbau.dat