Fri May 18 22:57:15 2007 => Loading Spyware Signatures from new External Database [Name: C:\DOCUME~1\TANGME~1\LOCALS~1\Temp\spydb.avs, Size: 226628].
Fri May 18 22:57:18 2007 => Indexed Spyware Databases Successfully Created...
Fri May 18 22:57:26 2007 => Offending file found: C:\WINDOWS\system32\moveex.exe
Fri May 18 22:57:26 2007 => System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (moveex.exe)! Action taken: Entries Removed.
Fri May 18 22:57:26 2007 => Object "trojan-downloader.bat.ftp.ab Trojan-Downloader" found in File System! Action Taken: Entries Removed.
Fri May 18 22:57:27 2007 => Offending file found: C:\WINDOWS\system32\pmuninst.exe
Fri May 18 22:57:27 2007 => System found infected with w32.myzor.fk@yf Trojan (pmuninst.exe)! Action taken: Entries Removed.
Fri May 18 22:57:27 2007 => Object "w32.myzor.fk@yf Trojan" found in File System! Action Taken: Entries Removed.
Fri May 18 22:57:27 2007 => Offending file found: C:\WINDOWS\system32\swreg.exe
Fri May 18 22:57:27 2007 => System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (swreg.exe)! Action taken: Entries Removed.
Fri May 18 22:57:27 2007 => Object "trojan-downloader.bat.ftp.ab Trojan-Downloader" found in File System! Action Taken: Entries Removed.
Fri May 18 22:57:27 2007 => Offending file found: C:\WINDOWS\system32\swsc.exe
Fri May 18 22:57:27 2007 => System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (swsc.exe)! Action taken: Entries Removed.
Fri May 18 22:57:27 2007 => Object "trojan-downloader.bat.ftp.ab Trojan-Downloader" found in File System! Action Taken: Entries Removed.
Fri May 18 22:57:43 2007 => Checking MountPoints2 Registry Key...
Fri May 18 22:57:43 2007 => Invalid Command Found in {e2dd8de6-fc7d-11db-815e-0013ce850c9e}\Shell\AutoRun\command: E:\LaunchU3.exe
Fri May 18 22:57:43 2007 => Offending Key found: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e2dd8de6-fc7d-11db-815e-0013ce850c9e} !!!
Fri May 18 22:57:43 2007 => Deleting Registry Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e2dd8de6-fc7d-11db-815e-0013ce850c9e}
Fri May 18 22:57:43 2007 => Object "Possible Fujacks-type Worm" found in File System! Action Taken: Entries Removed.
Fri May 18 22:57:43 2007 => Checking CLSID Reference Entries...
Fri May 18 22:58:01 2007 => Checking Module Usage Entries...
Fri May 18 22:58:01 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\ActivexChart.ocx". Action Taken: Entries Removed.
Fri May 18 22:58:02 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll". Action Taken: Entries Removed.
Fri May 18 22:58:02 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\HPGetDownloadManager.ocx". Action Taken: Entries Removed.
Fri May 18 22:58:02 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\rufsi.dll". Action Taken: Entries Removed.
Fri May 18 22:58:02 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\wlscBase.dll". Action Taken: Entries Removed.
Fri May 18 22:58:02 2007 => Checking User Trusted External App Entries...
Fri May 18 22:58:02 2007 => Entry "HKCU\Software\Netscape\Netscape Navigator\User Trusted External Applications" refers to invalid object ""C:\Program Files\IBM\Java142\jre\javaws\\javaws.exe\"". Action Taken: Entries Removed.
Fri May 18 22:58:02 2007 => Checking Shared DLL Entries...
Fri May 18 22:58:04 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\ActivexChart.ocx". Action Taken: Entries Removed.
Fri May 18 22:58:04 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\HPGetDownloadManager.ocx". Action Taken: Entries Removed.
Fri May 18 22:58:04 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\rufsi.dll". Action Taken: Entries Removed.
Fri May 18 22:58:04 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll". Action Taken: Entries Removed.
Fri May 18 22:58:05 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\wlscBase.dll". Action Taken: Entries Removed.
Fri May 18 22:58:05 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\RFA\readme.txt". Action Taken: Entries Removed.
Fri May 18 22:58:05 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Yahoo!\NSS\ReadMe.txt". Action Taken: Entries Removed.
Fri May 18 22:58:05 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\ACT\SfxBar.dll". Action Taken: Entries Removed.
Fri May 18 22:58:05 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\ACT\Cfx4032.ocx". Action Taken: Entries Removed.
Fri May 18 22:58:05 2007 => Checking Installer Entries...
Fri May 18 22:58:05 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\". Action Taken: Entries Removed.
Fri May 18 22:58:06 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\Decomposers\". Action Taken: Entries Removed.
Fri May 18 22:58:06 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\IDS\". Action Taken: Entries Removed.
Fri May 18 22:58:06 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\WINDOWS\Installer\{C6F5B6CF-609C-428E-876F-CA83176C021B}\". Action Taken: Entries Removed.
Fri May 18 22:58:08 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\Security Center\". Action Taken: Entries Removed.
Fri May 18 22:58:08 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\Script Blocking\". Action Taken: Entries Removed.
Fri May 18 22:58:08 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\VirusDefs\". Action Taken: Entries Removed.
Fri May 18 22:58:08 2007 => Checking Shared Tools Entries...
Fri May 18 22:58:08 2007 => Checking File Extension Entries...
Fri May 18 22:58:08 2007 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".dbf". Action Taken: Entries Removed.
Fri May 18 22:58:08 2007 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".log1". Action Taken: Entries Removed.
Fri May 18 22:58:09 2007 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".tpl". Action Taken: Entries Removed.
Fri May 18 22:58:09 2007 => Checking Application Cache Entries...
Fri May 18 22:58:09 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{032B93E8-D9A1-48D2-AA51-D057ABBA9E52}". Action Taken: Entries Removed.
Fri May 18 22:58:09 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{106E7A1C-22DA-42D7-8E74-37772A9C89FB}". Action Taken: Entries Removed.
Fri May 18 22:58:09 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{2959B9F6-2D49-4E0D-96F4-D684106FE48D}". Action Taken: Entries Removed.
Fri May 18 22:58:09 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{345321B9-E6DC-4606-9C44-CEC373E64CCF}". Action Taken: Entries Removed.
Fri May 18 22:58:09 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{6A6A5A40-FB6D-402C-8516-CC61E6DFE524}". Action Taken: Entries Removed.
Fri May 18 22:58:09 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{91B8E34E-54A1-4574-973D-75EFDFEED13D}". Action Taken: Entries Removed.
Fri May 18 22:58:09 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AA0370C1-BEB2-4C8E-ADFD-B7AFE85F0FBE}". Action Taken: Entries Removed.
Fri May 18 22:58:09 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AAE10BE5-F398-41C1-9AAF-A59EBF17DFDE}". Action Taken: Entries Removed.
Fri May 18 22:58:10 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{B945219C-C51C-4BD0-BAD5-A3FED95B555F}". Action Taken: Entries Removed.
Fri May 18 22:58:10 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{C4535494-0732-4123-BD27-8A000D3B36F2}". Action Taken: Entries Removed.
Fri May 18 22:58:10 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{C4868E88-F5B5-4E45-9592-C7062BD97441}". Action Taken: Entries Removed.
Fri May 18 22:58:10 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{CEB1A88D-195D-4350-A550-C6807B1BBB17}". Action Taken: Entries Removed.
Fri May 18 22:58:10 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{DA256408-A2E7-41A5-8AD6-62ACB86A0FD7}". Action Taken: Entries Removed.
Fri May 18 22:58:10 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{E5EE9939-259F-4DE2-8023-5C49E16A4F43}". Action Taken: Entries Removed.
Fri May 18 22:58:10 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{F5001920-E94E-4287-80C6-158FBC1D7035}". Action Taken: Entries Removed.
Fri May 18 22:58:10 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{F64306A5-4C32-41bb-B153-53986527FAB4}". Action Taken: Entries Removed.
Fri May 18 22:58:10 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{F6EE1D0A-575F-4ACA-999C-A640AF34F6DA}". Action Taken: Entries Removed.
Fri May 18 22:58:10 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{F891AAF3-DE9F-4445-85CF-6E41261A7F5A}". Action Taken: Entries Removed.
Fri May 18 22:58:10 2007 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{FF0311AB-34A0-4B0B-A8D3-B51E72B34F2C}". Action Taken: Entries Removed.
Is this what you want? I've searched thru the whole log and this is only the part where I can find the infected filenames.