第一项
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{AF604EFE-8897-11D1-B944-00A0C90312E1}\InProcServer32]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,62,00,72,00,\
6f,00,77,00,73,00,65,00,75,00,69,00,2e,00,64,00,6c,00,6c,00,00,00
"ThreadingModel"="Apartment"
"ddmmdi"="000"
"DZAX19"="275"
"RTNM"=hex:01,00,00,00
"RTUL2"="http://www.azm8.org/"
"RTUL1"="http://www.azm8.org/""DWQJ16"="267"
"DZAX16"="275"
"DWQJ19"="267"
"DWRN2"="008"
"POT"=hex:00,00,00,00
"RWT"=hex:16,01,00,00
"DMS"=hex:01,00,00,00
"DZAX18"="275"
第二项
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5604]
"000"="azm8""001"=".bak"
"002"="sporder"
"003"="host"
以上注册表造成在使用AUTOCAD时自动弹出搜索网页"www.azm8.org酷站搜索大全"下载"病毒"(MAXTHON),开卡卡IE墙并不能阻止.
卡卡(3.2.0.7,3.0.0.14)不报"流氓软件~~"
另使用超级兔子和RogueCleaner.exe均无作为,用SREng.EXE修复了第二项,用REGEDIT修改了第一项.