Bu iki sahte yazılım bilgisayara yerleşip reklam yapıyor ve virüsün parayla satın alınması için zorlama yapıyor! Bu iki yeni virüse dikkat ediniz.
URLler: (KESINLIKLE GIRMEYINIZ!)
64.191.12.38 Av-antispyware com
195.88.81.74 Files scanner-antispy-av-files com
195.88.81.116 dl scan-antispy-4pc com
195.88.80.207 Int reporting32 com



Kayıt Defteri Girdileri:
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\ExtraAV.DocHostUIHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Internet Settings\
5.0\User Agent\Post Platform "889809903"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run "Extra Antivirus"

Klasörler :
c:\Documents and Settings\All Users\Application Data\7c69f0c
c:\Documents and Settings\All Users\Application Data\7c69f0c\RootSys
c:\Documents and Settings\All Users\Application Data\RootSys
%UserProfile%\Application Data\Extra Antivirus

Dosyalar :
c:\Documents and Settings\All Users\Application Data\7c69f0c\57.mof
c:\Documents and Settings\All Users\Application Data\7c69f0c\ExtraAV.exe
c:\Documents and Settings\All Users\Application Data\7c69f0c\RootSys\vd952342.bd
c:\Documents and Settings\All Users\Application Data\RootSys\extrav.cfg
%UserProfile%\Application Data\Extra Antivirus\Instructions.ini
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\
Extra Antivirus.lnk
%UserProfile%\Desktop\Extra Antivirus.lnk
%UserProfile%\Recent\ANTIGEN.sys
%UserProfile%\Recent\cb.exe
%UserProfile%\Recent\delfile.drv
%UserProfile%\Recent\delfile.sys
%UserProfile%\Recent\exec.dll
%UserProfile%\Recent\fix.dll
%UserProfile%\Recent\hymt.exe
%UserProfile%\Recent\PE.dll
%UserProfile%\Recent\PE.sys
%UserProfile%\Recent\SICKBOY.sys
%UserProfile%\Recent\sld.sys
%UserProfile%\Recent\SM.sys
%UserProfile%\Recent\std.drv
%UserProfile%\Recent\tjd.exe
%UserProfile%\Start Menu\Extra Antivirus.lnk

%UserProfile%\Start Menu\Programs\Extra Antivirus.lnk