First of all....I was able to manually remove it. I had to mess around with
with some settings that I never had to mess with before. I changed the
profile rights settings of the folder with the malware (System Volume
Information), from the System profile to my own profile. This allowed me to
manually delete the files.
But anyway...Here is what the log file from the scan said. I have "X'ed" out
the computer and user names.
Hændelsestype: Advarsel
Hændelseskilde: WinDefend
Hændelseskategori: Ingen
Hændelses-id: 1006
Dato: 01-03-2006
Klokkeslæt: 18:26:55
Bruger: Ikke tilgængelig
Computer: XXXXXX
Beskrivelse:
Windows Defender scan has detected potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {C2860A37-D9F1-40C2-9125-75BE6E274C65}
Scan Type: AntiSpyware
Scan Parameters: Full Scan
User: XXXXXXX\XXXXXXX
Threat Name: Unclassified.Spyware.Loader
Threat Id: 15100
Threat Severity: 5
Threat Category: 2
Path Found: file:E:\System Volume
Information\_restore{F6FFCD50-7EAE-468A-94BA-0CDCCDB2B293}\RP46\A0008557.EXE->(wise0059);file:E:\System
Volume
Information\_restore{72F92272-DDD3-41E0-8D33-819056D33F49}\RP4\A0000628.EXE->(wise0059);file:E:\System
Volume
Information\_restore{72F92272-DDD3-41E0-8D33-819056D33F49}\RP4\A0000299.EXE->(wise0059);file:E:\System
Volume
Information\_restore{44094093-A5D8-49B6-9141-506E1AF21489}\RP1\A0003436.EXE->(wise0059);file:E:\System
Volume
Information\_restore{44094093-A5D8-49B6-9141-506E1AF21489}\RP1\A0002352.EXE->(wise0059);file:E:\System
Volume
Information\_restore{44094093-A5D8-49B6-9141-506E1AF21489}\RP1\A0001303.EXE->(wise0059);file:E:\System
Volume
Information\_restore{44094093-A5D8-49B6-9141-506E1AF21489}\RP1\A0000578.EXE->(wise0059);file:E:\System
Volume
Information\_restore{302453BC-35A6-4F3B-BE89-C7C45EA8D58C}\RP34\A0006080.EXE->(wise0059);file:E:\System
Volume
Information\_restore{302453BC-35A6-4F3B-BE89-C7C45EA8D58C}\RP34\A0005650.EXE->(wise0059);file

:\Dokumenter\Homepage\Tu
Detection Type: Signatures
Yderligere oplysninger finder du under Hjælp og support på
http://go.microsoft.com/fwlink/events.asp.
And here is the message from where it failed to remove it (red circle /w
X)...and it seems you're right (archive file):
Hændelsestype: Fejl
Hændelseskilde: WinDefend
Hændelseskategori: Ingen
Hændelses-id: 1008
Dato: 01-03-2006
Klokkeslæt: 18:29:13
Bruger: Ikke tilgængelig
Computer: XXXXXX
Beskrivelse:
Windows Defender has encountered an error when taking action on potential
malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {C2860A37-D9F1-40C2-9125-75BE6E274C65}
Scan Type: AntiMalware
User: XXXXXX\XXXXX
Threat Name: Unclassified.Spyware.Loader
Threat Id: 15100
Threat Severity: 5
Threat Category: 2
Action: Remove
Error Code: 0x80508026
Error description: Windows Defender cannot remove a potentially harmful
item from the contents of an archived file. To remove the item, you need to
delete the archive or you can search for options for removing spyware in Help
and Support.
Yderligere oplysninger finder du under Hjælp og support på
http://go.microsoft.com/fwlink/events.asp.
*****************************************