SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 08/27/2008 at 11:39 AM Application Version : 4.20.1046 Core Rules Database Version : 3546 Trace Rules Database Version: 1535 Scan type : Complete Scan Total Scan Time : 00:20:04 Memory items scanned : 288 Memory threats detected : 1 Registry items scanned : 3404 Registry threats detected : 8 File items scanned : 13930 File threats detected : 13 Trojan.Unclassified/C00-WL/A C:\WINDOWS\SYSTEM32\__C0024CED.DAT C:\WINDOWS\SYSTEM32\__C0024CED.DAT Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\__c0024CED Trojan.Unclassified/C00-Installer [A00FB01092.exe] C:\DOCUME~1\HIMMEL\LOKALE~1\TEMP\_A00FB01092.EXE C:\DOCUME~1\HIMMEL\LOKALE~1\TEMP\_A00FB01092.EXE C:\DOCUMENTS AND SETTINGS\HIMMEL\LOKALE INNSTILLINGER\TEMP\_A00FB01092.EXE Adware.Tracking Cookie C:\Documents and Settings\himmel\Cookies\himmel@adtech[1].txt C:\Documents and Settings\himmel\Cookies\himmel@atdmt[1].txt C:\Documents and Settings\himmel\Cookies\himmel@advertising[1].txt C:\Documents and Settings\himmel\Cookies\himmel@findexa.adbureau[1].txt C:\Documents and Settings\himmel\Cookies\himmel@scanner.msscanner[2].txt C:\Documents and Settings\himmel\Cookies\himmel@scanner.antivir-64[1].txt C:\Documents and Settings\himmel\Cookies\himmel@track.adform[2].txt C:\Documents and Settings\himmel\Cookies\himmel@tradedoubler[1].txt C:\Documents and Settings\himmel\Cookies\himmel@indextools[2].txt Trojan.Unclassified/C00-WL HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\__C0024CED HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\__C0024CED#Asynchronous HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\__C0024CED#DllName HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\__C0024CED#Impersonate HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\__C0024CED#Startup HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\__C0024CED#Logon Rogue.AntiVirus 2009/Installer C:\DOCUMENTS AND SETTINGS\HIMMEL\LOKALE INNSTILLINGER\TEMPORARY INTERNET FILES\CONTENT.IE5\HNCAR2IG\AV2009INSTALL_77052104[1].EXE