FOLLOWING IS [WORDPAD] COPY OF MWAV 'VIRUS LOG' PORTION OF MWAV SCAN

These are saved in the same location as OTListIt2.Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. File C:\WINDOWS\WNBackup\WNS52\wnun52.exe tagged as not-a-virus:Tool.Win32.Reboot. Also, something is blocking my windows security center for running automatic updates. INeedHelpFast., Jan 27, 2017 at 3:46 PM, in forum: Virus & Other Malware Removal Replies: 0 Views: 51 INeedHelpFast. http://www.bleepingcomputer.com/forums/t/205303/tinybarc-smitfraud-virtumondethe-works/

I ran the check again and it still showed up with a TinyBar.C (hijack) and Virtumonde (Trojan Horse BHO.BJE).

File C:\WINDOWS\Downloaded Program Files\gdnUS1858.exe infected by "Trojan.Win32.Dialer.ht" Virus!

Okay so I had to reboot after running the fix on OTListIt2 before I could get the "results" but when I rebooted, I got a notepad that looks like it had

File C:\_RESTORE\TEMP\A0074760.CPY infected by "Trojan-Downloader.Win32.Agent.li" Virus! http://www.spywareinfoforum.com/topic/48409-cwindowstinybarexe/ Back to top #9 mtflis mtflis Member Full Member 12 posts Posted 22 May 2005 - 09:49 PM AH, YES...LOVELY. If you have a new issue, please start a New Topic. Everyone else please begin a New Topic.

I went through the basic things like updating spybot and running a check and then clicking remove which spybot said it removed with big green check marks, but to no avail.

HAVING FOLLOWED YOUR LEAD, DURRING PROCESS...AFTER DELETING SAID ITEM...DIALER WINDOW NOT CURRENTLY COMING UP OF ITS OWN.AWAITING FURTHER INSTRUCTIONS.Logfile of HijackThis v1.99.1Scan saved at 9:37:50 PM, on 5/22/2005Platform: Windows ME (Win9x File not foundO24 - Desktop Components:0 (My Current Home Page) - About:HomeO31 - SafeBoot: AlternateShell - cmd.exeO32 - HKLM CDRom: AutoRun - 1O33 - MountPoints2\{ae7706f9-dffb-11dc-b9bd-000ea623473c}\Shell\AutoRun\command - "" = .exeO33 - MountPoints2\{ae7706f9-dffb-11dc-b9bd-000ea623473c}\Shell\explore\Command File C:\Program Files\Internet Explorer\pfdmclru.exe infected by "Trojan-Downloader.Win32.Agent.ck" Virus! p.s. - As a side note, writing in all caps is sometimes considered yelling in the online world.

Entry "HKCR\PCHealth.BugRepSysInfo.1" refers to invalid object "{F25BC7B7-C60D-4FB9-AAE4-3CA0F6C7038A}". File D:\Zilla Dial-up Accelerator\zca3001.exe tagged as "not-a-virus:AdWare.NavExcel". Action Taken: No Action Taken. OTListIt.Txt and Extras.Txt.

File not foundO2 - BHO: (no name) - {82bf8ceb-a299-48e0-968a-820d2907261f} - C:\WINDOWS\system32\plthxl.dll ()O3 - HKLM\..\Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. Terms Privacy Security Status Help You can't perform that action at this time. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O3 - Toolbar: Yahoo!

File not foundIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local FF - HKLM\software\mozilla\CompuServe 7.0\Extensions\\ -> -> FF - HKLM\software\mozilla\CompuServe 7.0\Extensions\\Components -> %CommonProgramFiles%\CSSHARE\PLUGINS0942 [C:\PROGRAM FILES\COMMON FILES\CSSHARE\PLUGINS0942] ->