Incident Status Location
Adware:Adware/VirusBurst Not disinfected C:\WINDOWS\system32\gqagksr.dll
Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared [email protected][2].txt
Spyware:Cookie/Gorillanation Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared [email protected][2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@advertising[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@atdmt[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared [email protected][1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@belnk[2].txt
Spyware:Cookie/Barelylegal Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared [email protected][1].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@ccbill[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared [email protected][1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@doubleclick[1].txt
Spyware:Cookie/E-eliminator Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@evidence-eliminator[1].txt
Spyware:Cookie/GangbangSquad Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@gangbangsquad[1].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@gostats[2].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@kinghost[1].txt
Spyware:Cookie/Outster Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@outster[2].txt
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@rightmedia[2].txt
Spyware:Cookie/TeensForCash Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@teensforcash[1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@toplist[1].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared kueter@webpower[2].txt
Spyware:Cookie/GangbangSquad Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared [email protected][1].txt
Spyware:Cookie/Safetyhomepage Not disinfected C:\Documents and Settings\Jared Kueter\Cookies\jared [email protected][1].txt
Adware:Adware/PestTrap Not disinfected C:\Documents and Settings\Jared Kueter\Local Settings\Temporary Internet Files\Content.IE5\SHOXIVCL\safetyhomepage[1].htm
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jesse Kueter\Cookies\jesse kueter@2o7[1].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Jesse Kueter\Cookies\jesse [email protected][2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Jesse Kueter\Cookies\jesse kueter@advertising[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jesse Kueter\Cookies\jesse kueter@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Jesse Kueter\Cookies\jesse kueter@atwola[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jesse Kueter\Cookies\jesse kueter@doubleclick[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Jesse Kueter\Cookies\jesse kueter@overture[1].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Jesse Kueter\Cookies\jesse kueter@revenue[2].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Jesse Kueter\Cookies\jesse [email protected][1].txt
Spyware:Cookie/VirusBurst Not disinfected C:\Documents and Settings\Jesse Kueter\Cookies\jesse [email protected][1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Jesse Kueter\Cookies\jesse kueter@zedo[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Jesse Kueter\Desktop\SmitfraudFix\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Jesse Kueter\Desktop\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Adware:Adware/PestTrap Not disinfected C:\Documents and Settings\Jesse Kueter\Local Settings\Temporary Internet Files\Content.IE5\X7DN6BZ5\theuptodatesafety[1].htm
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@2o7[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy [email protected][2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy [email protected][2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@advertising[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@atdmt[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@doubleclick[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@drivecleaner[1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy [email protected][1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@go[1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@hitbox[2].txt
Spyware:Cookie/Malwarewipe Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@malwarewipe[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@mediaplex[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@overture[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@questionmarket[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@serving-sys[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy [email protected][2].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy kueter@winantivirus[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy [email protected][2].txt
Spyware:Cookie/VirusBurst Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy [email protected][2].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Sandy Kueter\Cookies\sandy [email protected][2].txt
Adware:Adware/PestTrap Not disinfected C:\Documents and Settings\Sandy Kueter\Local Settings\Temporary Internet Files\Content.IE5\61PE3618\theuptodatesafety[1].htm
Adware:Adware/PestTrap Not disinfected C:\Documents and Settings\Sandy Kueter\Local Settings\Temporary Internet Files\Content.IE5\PN7FPHWI\safetyhomepage[1].htm
Spyware:Cookie/VirusBurst Not disinfected C:\Documents and Settings\Travis Kueter\Cookies\travis [email protected][2].txt
Adware:Adware/PestTrap Not disinfected C:\Documents and Settings\Travis Kueter\Local Settings\Temporary Internet Files\Content.IE5\AHET8T0B\theuptodatesafety[1].htm
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@adultfriendfinder[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@advertising[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@atwola[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@belnk[1].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler [email protected][2].txt
Spyware:Cookie/Barelylegal Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler [email protected][1].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler [email protected][2].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@ccbill[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@cgi-bin[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler [email protected][2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@doubleclick[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@drivecleaner[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@fastclick[2].txt
Spyware:Cookie/Powerscan Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@gammae[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@gostats[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@go[2].txt
Spyware:Cookie/Malwarewipe Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@malwarewipe[2].txt
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@rightmedia[2].txt
Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@sexlist[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@statcounter[2].txt
Spyware:Cookie/TeensForCash Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@teensforcash[1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@toplist[1].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@webpower[1].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler kueter@winantivirus[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler [email protected][1].txt
Spyware:Cookie/VirusBurst Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler [email protected][2].txt
Spyware:Cookie/MyWay Not disinfected C:\Documents and Settings\Tyler Kueter\Cookies\tyler [email protected][2].txt
Potentially unwanted tool:Application/VirusBurst Not disinfected C:\Documents and Settings\Tyler Kueter\Local Settings\Temp\vb365.exe
Adware:Adware/PestTrap Not disinfected C:\Documents and Settings\Tyler Kueter\Local Settings\Temporary Internet Files\Content.IE5\G7CUXEIB\theuptodatesafety[1].htm
Adware:Adware/PCodec Not disinfected C:\Program Files\VideosCodec\isauninst.exe
Adware:Adware/IntCodec Not disinfected C:\RECYCLER\S-1-5-21-914090876-3095290957-2122901767-1011\Dc45.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\SYSTEM32\Process.exe
Here is my Hijack This log
Logfile of HijackThis v1.99.1
Scan saved at 9:02:42 AM, on 10/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\Documents and Settings\Sandy Kueter\Desktop\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\eAcceleration\Station\station.exe
C:\Documents and Settings\Sandy Kueter\Desktop\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Hijackthis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {B753C7C5-0942-4b7f-BC27-942B52BDAC66} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
O2 - BHO: AIM Helper - {D70E6A20-7060-4829-B3D7-B6624A1DE7C6} - C:\Program Files\AIM Toolbar\aimhelper.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\Sandy Kueter\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.iowatelecom.net
O16 - DPF: symsupportutil - https://www-secure.s...supportutil.CAB
O16 - DPF: Yahoo! Checkers - http://download.game...nts/y/kt3_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.game...nts/y/it1_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: hydrodictyon - {b166be07-30a4-4d38-b781-44528a630706} - C:\WINDOWS\system32\gqagksr.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\Sandy Kueter\Desktop\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Can you help me remove everything that needs to be removed.
Thanks!!