Time Module Object Name Threat Action User Information 13/05/2008 12:28:08 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1288.exe multiple infiltrations quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:28:06 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1280.exe probably a variant of Win32/TrojanClicker.Small trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:28:04 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1273.exe probably a variant of Win32/Adware.NaviPromo application quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:28:03 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1272.exe probably a variant of Win32/Adware.NaviPromo application quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:28:01 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1122.exe probably a variant of Win32/Agent trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:59 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1118.exe probably unknown NewHeur_PE virus quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:57 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1117.exe probably unknown NewHeur_PE virus quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:54 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1116.tmp a variant of Win32/Spy.Agent.NFB trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:52 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1115.tmp a variant of Win32/Spy.Agent.NFB trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:49 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1114.tmp a variant of Win32/Spy.Agent.NFB trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:47 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1110.tmp Win32/Spy.Agent.NFQ trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:45 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1109.tmp Win32/Spy.Agent.NFQ trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:42 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1108.tmp probably a variant of Win32/Wigon trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:40 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1107.tmp Win32/Spy.Agent.NFQ trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:39 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1106.tmp Win32/Spy.Agent.NFQ trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:37 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1104.tmp a variant of Win32/TrojanDownloader.Wigon.O trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:35 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1098.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:34 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1097.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:32 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1096.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:31 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1095.tmp a variant of Win32/Spy.Agent.NFB trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:29 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1094.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:28 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1093.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:26 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1092.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:24 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1091.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:23 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1090.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:21 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1089.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:19 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1088.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:17 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1087.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:15 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1086.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:14 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1080.tmp probably unknown NewHeur_PE virus quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:12 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1079.tmp Win32/Spy.Agent.NFQ trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:11 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1073.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:09 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1070.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:07 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1069.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:06 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1068.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:03 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1067.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:27:02 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1066.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 12:26:59 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1065.tmp Win32/Spy.Agent.NFN trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 11:44:40 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc953.exe probably a variant of Win32/Adware.NaviPromo application quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 11:02:34 AMON file C:\Documents and Settings\raph ze best\Bureau\naked0453.com Win32/IRCBot.NAG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 13/05/2008 11:01:41 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc943.exe Win32/Adware.SaveNow application quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 09:48:50 AMON file C:\WINDOWS\system32\drivers\nkv2.sys Win32/Rootkit.Agent.AGF trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a new file created by the application: C:\WINDOWS\System32\svchost.exe. The file was moved to quarantine. You may close this window. 13/05/2008 09:48:45 AMON file C:\WINDOWS\system32\drivers\Jor82.sys Win32/Wigon.BY trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\TEMP\BN5D.tmp. The file was moved to quarantine. You may close this window. 13/05/2008 09:42:33 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc3.exe probably a variant of Win32/TrojanProxy.Dlena trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 09:42:22 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc2.exe probably a variant of Win32/TrojanProxy.Dlena trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 09:42:20 AMON file C:\RECYCLER\S-1-5-21-1409082233-484763869-854245398-1004\Dc1.exe probably a variant of Win32/TrojanProxy.Dlena trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window. 13/05/2008 09:13:01 AMON file C:\WINDOWS\system32\drivers\Jor82.sys Win32/Wigon.BY trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a modified file. The file was moved to quarantine. You may close this window. 13/05/2008 09:10:48 AMON file C:\WINDOWS\system32\drivers\nkv2.sys Win32/Rootkit.Agent.AGF trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a new file created by the application: C:\WINDOWS\System32\svchost.exe. The file was moved to quarantine. You may close this window. 13/05/2008 09:03:03 Kernel file C:\WINDOWS\system32\WinNt32.dll probably a variant of Win32/Wigon trojan 13/05/2008 09:02:49 Kernel file C:\WINDOWS\system32\winnt32.dll probably a variant of Win32/Wigon trojan 13/05/2008 09:01:40 Kernel file C:\WINDOWS\system32\drivers\jor82.sys Win32/Wigon.BY trojan Alert was generated during the system startup file check. 13/05/2008 08:58:34 Kernel file C:\WINDOWS\system32\WinNt32.dll probably a variant of Win32/Wigon trojan 13/05/2008 08:57:42 AMON file C:\WINDOWS\system32\drivers\nkv2.sys Win32/Rootkit.Agent.AGF trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a new file created by the application: C:\WINDOWS\System32\svchost.exe. The file was moved to quarantine. You may close this window. 09/05/2008 16:12:13 AMON file C:\WINDOWS\system32\WinData.cab probably a variant of Win32/Wigon trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\TEMP\BN5E.tmp. The file was moved to quarantine. You may close this window. 09/05/2008 16:12:12 AMON file C:\WINDOWS\system32\drivers\nkv2.sys Win32/Rootkit.Agent.AGF trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a new file created by the application: C:\WINDOWS\System32\svchost.exe. The file was moved to quarantine. You may close this window. 09/05/2008 13:07:21 AMON file C:\WINDOWS\system32\drivers\nkv2.sys Win32/Rootkit.Agent.AGF trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a new file created by the application: C:\WINDOWS\System32\svchost.exe. The file was moved to quarantine. You may close this window. 09/05/2008 12:40:49 AMON file C:\WINDOWS\b149.exe_old a variant of Win32/TrojanDropper.Agent.NJY trojan quarantined - deleted PC-USER1\1 Event occurred on a file modified by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. The file was moved to quarantine. You may close this window. 09/05/2008 12:36:23 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:36:06 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:35:49 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:35:33 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:35:15 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:34:59 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:34:42 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:34:24 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:34:07 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:33:50 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:33:34 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:33:16 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:32:59 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:32:42 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:32:25 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:32:08 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:31:52 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:31:34 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:31:17 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:30:59 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:30:43 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:30:25 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:30:08 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:29:50 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:29:33 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:29:17 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:29:00 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:20:36 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 12:13:15 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 11:55:06 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 11:54:08 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 11:52:09 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 11:41:58 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 11:30:49 AMON file C:\WINDOWS\system32\WinNt32.dll Win32/Wigon trojan AUTORITE NT\SYSTEM Event occurred at an attempt to access the file by the application: \??\C:\WINDOWS\system32\winlogon.exe. 09/05/2008 11:23:58 AMON file C:\Documents and Settings\1\zvzrnb.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:56 AMON file C:\Documents and Settings\1\wrmdsx.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:55 AMON file C:\Documents and Settings\1\wqpvco.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:53 AMON file C:\Documents and Settings\1\wkutpk.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:52 AMON file C:\Documents and Settings\1\wguwgf.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:50 AMON file C:\Documents and Settings\1\vmordp.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:49 AMON file C:\Documents and Settings\1\vgqnqv.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:47 AMON file C:\Documents and Settings\1\vcjmup.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:46 AMON file C:\Documents and Settings\1\vaaqid.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:44 AMON file C:\Documents and Settings\1\unzphu.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:43 AMON file C:\Documents and Settings\1\sxaotd.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:41 AMON file C:\Documents and Settings\1\ssgfle.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:40 AMON file C:\Documents and Settings\1\smmsrb.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:38 AMON file C:\Documents and Settings\1\rxthaa.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:37 AMON file C:\Documents and Settings\1\qpuqmd.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:08 AMON file C:\Documents and Settings\1\lrohxt.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:07 AMON file C:\Documents and Settings\1\lfahgb.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:05 AMON file C:\Documents and Settings\1\kvbhoy.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:03 AMON file C:\Documents and Settings\1\kummai.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:02 AMON file C:\Documents and Settings\1\kiwann.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:23:00 AMON file C:\Documents and Settings\1\kishoa.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:59 AMON file C:\Documents and Settings\1\kfmppq.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:58 AMON file C:\Documents and Settings\1\jnynmm.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:56 AMON file C:\Documents and Settings\1\jkirmg.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:55 AMON file C:\Documents and Settings\1\humxcw.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:53 AMON file C:\Documents and Settings\1\hksdyj.exe Win32/TrojanProxy.Daemonize.NAD trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:52 AMON file C:\Documents and Settings\1\gpfxcy.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:51 AMON file C:\Documents and Settings\1\ghgkrb.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:49 AMON file C:\Documents and Settings\1\fosjfk.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:48 AMON file C:\Documents and Settings\1\ennxkc.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:46 AMON file C:\Documents and Settings\1\doqoxo.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:44 AMON file C:\Documents and Settings\1\dcrrwk.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:43 AMON file C:\Documents and Settings\1\cvzicl.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:41 AMON file C:\Documents and Settings\1\cfaxzh.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:38 AMON file C:\Documents and Settings\1\bynlxf.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:36 AMON file C:\Documents and Settings\1\ahjten.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:22:32 AMON file C:\Documents and Settings\1\abtytm.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 11:21:51 AMON file C:\Program Files\iSecurity\Ultimate Defender\install.exe Win32/Adware.UltimateDefender application deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 10:12:19 AMON file C:\Program Files\MailSkinner\OLSkinner.dll Win32/Adware.NaviPromo application deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 09:54:10 AMON file C:\Documents and Settings\1\Local Settings\Temp\loader.exe Win32/TrojanDownloader.Agent.HLT trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 09:54:00 AMON file C:\Documents and Settings\1\Local Settings\Temp\1BA.tmp.exe Win32/TrojanDownloader.Agent.HLT trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 09:46:16 AMON file C:\Program Files\Dot1XCfg\Dot1XCfg.exe Win32/TrojanDownloader.Adload.PR trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 09:46:04 AMON file C:\WINDOWS\mrofinu1148.exe.tmp Win32/TrojanDownloader.Agent.BLS trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 09:44:46 AMON file C:\WINDOWS\default.htm Win32/TrojanDownloader.FakeAlert.AV trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 09:44:39 AMON file C:\WINDOWS\b122.exe Win32/TrojanDownloader.Adload.PR trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 09:44:29 AMON file C:\upaq.exe Win32/Rustock.NDF trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 09:44:10 AMON file C:\cvbkwtb.exe Win32/Wigon.AO trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 09:39:10 AMON file C:\WINDOWS\yyzmgq.exe Win32/TrojanDownloader.Small.HSG trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 09:39:04 AMON file C:\WINDOWS\b151.exe Win32/TrojanDownloader.Agent.FJN trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe. 09/05/2008 09:33:08 AMON file C:\Program Files\3917182.exe Win32/TrojanDropper.Agent.EYA trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 09:33:06 AMON file C:\Program Files\3945062.exe Win32/TrojanDropper.Agent.EYA trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 09:33:02 AMON file C:\Program Files\3973303.exe Win32/TrojanDropper.Small.NHF trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 09:32:01 AMON file C:\Program Files\4027891.exe Win32/TrojanDropper.Small.NHF trojan deleted PC-USER1\1 Event occurred at an attempt to access the file by the application: C:\WINDOWS\Explorer.EXE. 09/05/2008 09:17:07 AMON file C:\WINDOWS\system32\WinData.cab Win32/Wigon trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a modified file. The file was moved to quarantine. You may close this window. 09/05/2008 09:17:06 AMON file C:\WINDOWS\system32\WinData.cab probably a variant of Win32/Wigon trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\TEMP\BN5D.tmp. The file was moved to quarantine. You may close this window. 09/05/2008 09:17:06 AMON file C:\WINDOWS\system32\drivers\Jor82.sys Win32/Wigon.BV trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a modified file. The file was moved to quarantine. You may close this window. 08/05/2008 19:09:16 AMON file C:\WINDOWS\system32\WinData.cab probably a variant of Win32/Wigon trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a new file created by the application: C:\WINDOWS\TEMP\BN5F.tmp. The file was moved to quarantine. You may close this window. 08/05/2008 19:09:16 AMON file C:\WINDOWS\system32\drivers\nkv2.sys Win32/Rootkit.Agent.AGF trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\System32\svchost.exe. The file was moved to quarantine. You may close this window. 08/05/2008 19:09:15 AMON file C:\WINDOWS\system32\WinData.cab probably a variant of Win32/Wigon trojan quarantined - deleted AUTORITE NT\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\TEMP\BN5D.tmp. The file was moved to quarantine. You may close this window. 08/05/2008 19:04:59 Kernel file C:\WINDOWS\system32\socksys.dll probably a variant of Win32/TrojanDownloader.Agent trojan 08/05/2008 19:04:52 Kernel file C:\Program Files\Helper\superfindout.dll Win32/Adware.BHO.NBR application Alert was generated during the system startup file check. 08/05/2008 19:04:52 Kernel file C:\Program Files\Helper\Helper10.dll Win32/BHO.CC trojan Alert was generated during the system startup file check. 08/05/2008 19:04:47 Kernel file C:\WINDOWS\Installer\{8597ffc5-f290-48f3-bf5a-f92a190e1254}\zip.dll Win32/TrojanDropper.Agent.EYA trojan Alert was generated during the system startup file check. 08/05/2008 19:04:43 Kernel file C:\WINDOWS\system32\WinNt32.dll probably a variant of Win32/Wigon trojan 08/05/2008 19:04:43 Kernel file C:\WINDOWS\system32\LogCrypt.dll a variant of Win32/Wigon trojan 08/05/2008 19:04:41 Kernel file C:\WINDOWS\system32\winnt32.dll probably a variant of Win32/Wigon trojan 08/05/2008 19:04:41 Kernel file C:\WINDOWS\system32\logcrypt.dll a variant of Win32/Wigon trojan 08/05/2008 19:04:41 Kernel file c:\windows\installer\{8597ffc5-f290-48f3-bf5a-f92a190e1254}\zip.dll Win32/TrojanDropper.Agent.EYA trojan Alert was generated during the system startup file check. 08/05/2008 19:04:38 Kernel file C:\WINDOWS\system32\socksys.dll probably a variant of Win32/TrojanDownloader.Agent trojan 08/05/2008 19:04:33 Kernel file c:\program files\helper\superfindout.dll Win32/Adware.BHO.NBR application Alert was generated during the system startup file check. 08/05/2008 19:04:33 Kernel file c:\program files\helper\helper10.dll Win32/BHO.CC trojan Alert was generated during the system startup file check. 08/05/2008 19:04:09 Kernel file C:\WINDOWS\mgrs.exe probably a variant of Win32/TrojanClicker.Agent.NBS trojan 08/05/2008 18:56:36 Kernel file C:\WINDOWS\lsass.exe probably unknown NewHeur_PE virus 08/05/2008 18:55:20 Kernel file c:\windows\lsass.exe probably unknown NewHeur_PE virus