
Hey Vanna,
Well you had a number of infections that AVG took care of . There are still a few things that need to be done. First of all uninstall
backWeb-7288971.exe from Add/Remove Programs, and then delete the file:
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\
backWeb-7288971.exe
Then change your Privacy settings in your Mozilla browser to delete cookies when exiting the browser.
OK next, please download SpySweeper, CCleaner, and Shot the Messenger from my signaturre, then boot into Safe Mode.
Run Shoot the Messenger, it will disable the Windows Messenger, a useless utility that leaves you vulnerable to PopUp attacks.
Then run CCleaner, and make sure that all of the options are checked, including Advanced, answer yes or OK to all warnings. Click on Analyze, then Run Cleaner. Repeat until no files are available to clean.
Next run SpySweeper, making sure that under Options, in the Sweep tab, all options are checked in Customer Sweep. Let it quarrantine everything that it finds, and save a log to post back here.
Now boot back into Regular Mode, and fix the following if they are still there in HijackThis. Making sure that no other windows are open.
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\
PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) -
http://www.schaeffersresearch.com/download/CfxIEAx.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) -
http://static.zangocash.com/cab/Seek...ridge-c420.cab
Locate and delete any files and folders in bold.
Rerun a new
HJT log, and post back here with the SpySweeper log.
Looking forward to your reply,
TTFN
LGW