This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

About:blank Hijacker

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I actually have a post in the solved hijacks forum, and I tried to email a moderator to get it moved back here, but each time I tried to email I kept getting an error message saying I wasn't permitted to email.
I'm having the same problem I had before. I have scanned my computer with Spybot Search and Destroy, AdAware, and AVG Anti-Virus, and as far as my computer tells me, I have each of those programs updated. Since the last time I had this problem I have also installed ZoneAlarm firewall and have tried to visit only websites I've not had problems with in the past.
My problem is that if I try going to certain pages (for example, some pages in Amazon.com or AOL), I keep getting hijacked by a webpage which says about:blank that advertises different things such as Viagra, Spyware, Casinos, etc.). I can't go to Microsoft's website either to get updates there because I get hijacked if I try. When I try to adjust my browser settings, they don't stay permanent.
My computer knowledge is somewhat limited, so I do apologize in advance if I haven't followed proper protocol in any way. I have tried to read the instructions on this site and follow them to the best of my ability.
An additional problem that I have is that my computer originally came with Norton AntiVirus, which I have also used to scan my computer, but now when I turn on my computer, the Norton AntiVirus program says it is disabled even though it still seems to operate. Whenever I try to enable it, it doesn't do anything, yet I am still able to open it and scan the computer. But on the bottom of my screen its icon has a red "X" over it. I don't know if this is in any way related to the hijacking problem, but I thought I'd mention it just in case.
Thank you for any help you might be able to give me.

Here is my Hijackthis log:

Logfile of HijackThis v1.98.2
Scan saved at 1:16:27 AM, on 1/3/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\msvcmm32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\MOVIEL~1\MOVIEL~1\MOVIEL~1.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\America Online 9.0\aolwbspd.exe
C:\Program Files\Common Files\Real\Update_OB\realevent.exe
C:\Program Files\Common Files\Real\Update_OB\realevent.exe
C:\Program Files\Common Files\Real\Update_OB\realevent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8l.hpwis.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us8l.hpwis.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\hp\tmp\src\psptr\Patch\Uninst\HPHupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [LoadMSvcmm] C:\WINDOWS\System32\msvcmm32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5CD0CAB1-3088-48E8-970B-248411632EB8}: NameServer = 198.81.16.4
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
Please open HJT>Config>Misc Tools and update to v1.99

Post a new log when done. Click here to download mwavscan. Double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, anything found will be displayed in the lower pane. Highlight it, CTRL C and paste it in your next reply.
Here is my updated hijack log. I have installed the virus software you asked me to and will scan my computer shortly and send you the results of that as soon as I have them.

Logfile of HijackThis v1.99.0
Scan saved at 9:59:22 AM, on 1/3/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\msvcmm32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\PROGRA~1\MOVIEL~1\MOVIEL~1\MOVIEL~1.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\America Online 9.0\aolwbspd.exe
C:\Program Files\Common Files\Real\Update_OB\realevent.exe
C:\HJT\HijackThis.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\HJT2\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8l.hpwis.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us8l.hpwis.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\hp\tmp\src\psptr\Patch\Uninst\HPHupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [LoadMSvcmm] C:\WINDOWS\System32\msvcmm32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5CD0CAB1-3088-48E8-970B-248411632EB8}: NameServer = 198.81.19.4
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O23 - Service: AOL Connectivity Service - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bluetooth Service - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GBPoll - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: Kodak Camera Connection Software - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Sorry I took so long. I tried highlighting the results and pressing CTRL C, but nothing happened, so I copied the virus results directly from the scan log (not wishing to burden you with the entire scan log). Here are the results (56 of them): File C:\PROGRA~1\AMERIC~1.0\aoltray.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\COMMON~1\SYMANT~1\ccApp.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\HEWLET~1\HPSOFT~1\HPWUSC~1.EXE infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\HP\DIGITA~1\Unload\hpqcmon.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\HP\HPSHAR~1\hpgs2wnd.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\HP\HPCORE~1\hpcmpmgr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\Kodak\KODAKS~1\7288971\Program\KODAKS~1.EXE infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\MESSEN~1\msmsgs.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\MICROS~3\System\mnyexpr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\MUSICM~1\MUSICM~1\mmtask.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\QUICKT~1\qttask.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\SYNAPT~1\SynTP\SynTPEnh.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\WinZip\WZQKPICK.EXE infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\hphmon05.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\ms0b920b.dll infected by "not-a-virus:AdWare.Visiter" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\SYNAPT~1\SynTP\SynTPLpr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\SYNAPT~1\SynTP\SynTPEnh.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\HP\DIGITA~1\Unload\hpqcmon.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\HP\HPSHAR~1\hpgs2wnd.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\hphmon05.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File c:\PROGRA~1\MUSICM~1\MUSICM~1\mmtask.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\HP\HPCORE~1\hpcmpmgr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\COMMON~1\SYMANT~1\ccApp.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\QUICKT~1\qttask.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\HEWLET~1\HPSOFT~1\HPWUSC~1.EXE infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\MESSEN~1\msmsgs.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File c:\PROGRA~1\MICROS~3\System\mnyexpr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\hphmon05.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\ms0b920b.dll infected by "not-a-virus:AdWare.Visiter" Virus. Action Taken: No Action Taken. File C:\Program Files\America Online 9.0\aoltray.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\America Online 9.0\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\HP\Digital Imaging\Unload\HpqCmon.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\HP\hpcoretech\hpcmpmgr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Messenger\msmsgs.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Microsoft Money\System\mnyexpr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\43056C63 infected by "TrojanDownloader.JS.IstBar.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4308165F infected by "TrojanDownloader.JS.IstBar.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Online Services\AOL90US\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\QuickTime\qttask.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Synaptics\SynTP\SynTPEnh.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Synaptics\SynTP\SynTPLpr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\Program Files\WinZip\WZQKPICK.EXE infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{970BF179-4538-46F7-A171-F13CFC09440B}\RP116\A0010252.dll infected by "not-a-virus:AdWare.Visiter" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\a.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\hphmon05.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\ms0b920b.dll infected by "not-a-virus:AdWare.Visiter" Virus. Action Taken: No Action Taken.
Well, I did my best to follow your instructions, but am afraid I wasn't entirely successful. CWShredder, TrendMicro HouseCall, and BitDefender all failed to detect any viruses and therefore nothing was fixed or healed to the best of my knowledge. I was unable to access ETrust. I kept getting the message that "signature files were not loaded" and that it "failed to create file." As I said, my computer knowledge is limited, so I'm not sure what all that means or how to fix it. When I tried to access Command on Demand, I also kept getting an error message that it couldn't be downloaded. And when I tried to access Panda ActiveScan, I was hijacked by the same page that's been hijacking me and prompted me to ask for help here, so I could not scan my computer with the latter three programs. Sorry. I'm not sure what to do.
After some tinkering, I was finally able to get ETrust to scan my computer. It said, "No infections found," and so I assume nothing was fixed.
OK. This is what you have:

http://www3.ca.com/securityadvisor/virusin…s.aspx?id=41046

This is very difficult to remove as it has altered legitimate files to load the trojan's DLL.

We can get rid of the installer, find and delete:

C:\WINDOWS\Downloaded Program Files\a.exe

These are the infected files:

C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\Unload\HpqCmon.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\hphmon05.exe

Do you have the orginal installation files for these - we are probably going to have to reinstall them.
I don't seem to be able to find the installer. This is what is in my Downloaded Program Files folder: ActiveDataInfo Class AvxScanOnline Cotrol CSS Web Installer Class HouseCall Control Java Runtime Environment 1.4.2 Java Runtime Environment 1.4.2 LSSupCtl Class Shockwave Flash Object Symantec AntiVirus scanner Symantec RuFSI Utility Class Update Class WScanCtl Class I don't see anything that says a.exe As for the original installation files, because my computer knowledge is limited, I'm not sure on what some of them even are. I know I can reinstall America Online, Kodak, Bluetooth, and Norton Systemworks. Others, like the Hewlett-Packard programs, MusicMatch, and Microsoft Money came with the computer. I don't remember whether Quicktime and WinZip came with the computer or if I downloaded them. I don't know about the Messenger, Synaptics, or WINDOWS\system32 stuff at all. So I'm not sure. Please advise, and thank you so much for your patience.
OK, let's see if we can start making an impact on it.

Click here to download Pocket Killbox by Option^Explicit. Extract it from the zip file to your desktop.

Start Killbox and click on Tools->Delete Temp Files.

When that finishes, copy and paste the following line into the "Full Path of File to Delete" box in Killbox, and click the red button with the white X on it:

C:\WINDOWS\Downloaded Program Files\a.exe

It it says it couldn't find or delete the file, in the killbox again this time, put a mark next to "Delete on Reboot". Copy and paste the file into the file name box, then click the red button with the X. It will ask you if you want to reboot, answer Yes.

Next, find this file:

C:\WINDOWS\system32\ms0b920b.dll and rename it as:

C:\WINDOWS\system32\ms0b920b.dl_

You will probably get error messages on rebooting from now on - we'll deal with that in due course.

Click Start>Settings>Control Panel>Add or Remove Programs and uninstall WinZip and QuickTime. Reboot when done.

Use the Killbox in the same manner as above on these files:

C:\Program Files\QuickTime\qttask.exe
C:\Program Files\WinZip\WZQKPICK.EXE


Then delete the actual folders from Program Files if still there. Reboot again then download and reinstall from here:

http://www.winzip.com/downwz.htm

http://www.apple.com/quicktime/download/

Re-run the mwavscan and post a new infected log so we can check that the infection has been removed from these programs.
Okay, I was able to delete C:\WINDOWS\Downloaded Program Files\a.exe using Pillbox.
Since I renamed C:\WINDOWS\system32\ms0b920b.dll I have been getting the error message you said I would.
I uninstalled WinZip and Quicktime. I deleted C:\Program Files\QuickTime\qttask.exe using Pillbox but received the message "File doesn't exist" when I tried to delete C:\Program Files\WinZip\WZQKPICK.EXE. Was I supposed to put a mark next to "Delete on Reboot" in Pillbox, and copy and paste the file into the file name box, then click the red button with the X as per your instructions? If so, I forgot to, but just realized it now as I'm rereading your instructions.
I deleted the folders for those programs (actually, the QuickTime folder was the only one present) and reinstalled the programs.
Here is my updated MWAV log:

File C:\PROGRA~1\SYNAPT~1\SynTP\SynTPLpr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\PROGRA~1\SYNAPT~1\SynTP\SynTPEnh.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\PROGRA~1\HP\DIGITA~1\Unload\hpqcmon.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\PROGRA~1\HP\HPSHAR~1\hpgs2wnd.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\hphmon05.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\PROGRA~1\MUSICM~1\MUSICM~1\mmtask.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\PROGRA~1\HP\HPCORE~1\hpcmpmgr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\PROGRA~1\COMMON~1\SYMANT~1\ccApp.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\PROGRA~1\HEWLET~1\HPSOFT~1\HPWUSC~1.EXE infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\PROGRA~1\MESSEN~1\msmsgs.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\PROGRA~1\MICROS~3\System\mnyexpr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\hphmon05.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\ms0b920b.dl infected by "not-a-virus:AdWare.Visiter" Virus. Action Taken: No Action Taken.
File C:\!Submit\a.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\!Submit\qttask.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\America Online 9.0\aoltray.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\America Online 9.0\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\HP\Digital Imaging\Unload\HpqCmon.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\HP\hpcoretech\hpcmpmgr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\Messenger\msmsgs.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\Microsoft Money\System\mnyexpr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\43056C63 infected by "TrojanDownloader.JS.IstBar.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4308165F infected by "TrojanDownloader.JS.IstBar.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\Online Services\AOL90US\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\Synaptics\SynTP\SynTPEnh.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\Synaptics\SynTP\SynTPLpr.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{970BF179-4538-46F7-A171-F13CFC09440B}\RP116\A0010252.dll infected by "not-a-virus:AdWare.Visiter" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{970BF179-4538-46F7-A171-F13CFC09440B}\RP134\A0014556.dll infected by "not-a-virus:AdWare.Visiter" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\hphmon05.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\ms0b920b.dl infected by "not-a-virus:AdWare.Visiter" Virus. Action Taken: No Action Taken.
OK that seems to work. Let's do another.

Click Start>Settings>Control Panel>Add or Remove Programs and uninstall Kodak. Reboot when done.

Open the Killbox, in the 'Full Path of File to Delete' box, copy and paste the following, clicking the red 'Delete File' button after pasting:

C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

Click 'Exit' when done.

Find and delete, C:\Program Files\Kodak\

Reboot and reload from your backup files. Post a new mwavscan when done.

Do you have any HP periferals - printer, scanner etc?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI