애드웨어, 허위백신, 팝업광고, 쇼핑몰 바로가기, 악성툴바, 각종 개쓰레기 프로그램 삭제 요청하기
이용약관을 안내하며 컴퓨터에 설치하는 개쓰레기 프로그램들은 백신으로 백날 돌려봐야 검색이 안됩니다.
개쓰레기 프로그램들은 아주 지능적이라서 전문가가 아니고서는 찾아내기가 어렵습니다.


----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Microsoft Windows XP Service Pack 3(5.1.2600.196608)
Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz / 767.48 MB
x86 Family 6 Model 37 Stepping 5
Date : 2011-06-10
----------------------------------------------------------------------
DF000 C:\Documents and Settings\Administrator\Local Settings\Application Data\setup1.exe
DF001 C:\Documents and Settings\Administrator\Local Settings\Application Data\setup2.exe
DF002 C:\Program Files\BaroSearch\barosearch.exe
DF003 C:\Program Files\BaroSearch\barosearchs.exe
DF004 C:\Program Files\Filebus\AZMain.dll
DF005 C:\Program Files\Filebus\ElevationWrap.exe
DF006 C:\Program Files\Filebus\FilebusCMC.dll
DF007 C:\Program Files\Filebus\FilebusDown.exe
DF008 C:\Program Files\Filebus\FilebusUp.exe
DF009 C:\Program Files\Filebus\Firewall.exe
DF010 C:\Program Files\Filebus\HoleAddon.dll
DF011 C:\Program Files\Filebus\msvcr71.dll
DF012 C:\Program Files\Filebus\pthreadVC2.dll
DF013 C:\Program Files\Filebus\qdownload_setup.exe
DF014 C:\Program Files\Filebus\Uninstall.exe
DF015 C:\Program Files\Filebus\WebhardAddon.dll
DF016 C:\Program Files\QuickDownloadService\ElevationWrap.exe
DF017 C:\Program Files\QuickDownloadService\Firewall.exe
DF018 C:\Program Files\QuickDownloadService\HoleAddon.dll
DF019 C:\Program Files\QuickDownloadService\qdownagent.exe
DF020 C:\Program Files\QuickDownloadService\qdownservice.exe
DF021 C:\Program Files\QuickDownloadService\sc.exe
DF022 C:\Program Files\QuickDownloadService\StopMegaService.exe
DF023 C:\Program Files\QuickDownloadService\unins000.exe
DF024 C:\Program Files\QuickDownloadService\UPnP.dll
DF025 C:\Program Files\sponsorkeyword\sponsorkeyword.exe
DF026 C:\Program Files\sponsorkeyword\sponsorkeyword_uninstall.exe
DF027 C:\Program Files\STerra\SafeTerra.exe
DF028 C:\Program Files\STerra\SafeTerraUpdate.exe
DF029 C:\Program Files\STerra\STUninstall.exe
DF030 C:\Program Files\WiseLook Application\juso.dll
DF031 C:\Program Files\WiseLook Application\WiseLook.exe
DF032 C:\WINDOWS\barosearchuninstall.exe
DF033 C:\WINDOWS\Downloaded Program Files\FilebusWebControl.dll
DF034 C:\WINDOWS\system32\barosearch_p1.exe
DF035 C:\WINDOWS\system32\SafeTerra.exe
DF036 C:\WINDOWS\system32\setup_filebus_.exe
----------------------------------------------------------------------
SC037 QuickDownload Agent -/- QuickDownload Agent -/- - -/-  -/- C:\Program Files\QuickDownloadService\qdownagent.exe
SC038 QuickDownload Service -/- QuickDownload Service -/- - -/-  -/- C:\Program Files\QuickDownloadService\qdownservice.exe
----------------------------------------------------------------------
UN039 BaroSearch -/- - -/- BaroSearch -/- - -/- -
UN040 파일버스 for InnoGrid -/- (주)웹팩토리 -/- Filebus -/-
UN041 Safe Terra -/- 한국고시아카데미 -/- SafeTerra -/-
UN042 sponsorkeyword Uninstall -/- (주)인터넷마케팅연구소 -/- sponsorkeyword -/- - -
UN043 QuickDownloadService -/- QuickDownloadService -/- {F44CB7E4-870C-4021-B1F9-0CF352200519}_is1 -/- - -/- -
UN044 WiseLook Application -/- - -/- WiseLook Application -/- - -/- -
----------------------------------------------------------------------
US045 sponsorkeyword -/- C:\Program Files\sponsorkeyword\sponsorkeyword.exe
US046 BaroSearch -/- C:\Program Files\BaroSearch\\barosearchs.exe
US047 Safeterra -/- C:\Program Files\STerra\SafeTerraUpdate.exe
US048 WiseLook Application -/- C:\Program Files\WiseLook Application\WiseLook.exe
----------------------------------------------------------------------
BH049 WiseLook Application -/- C:\PROGRA~1\WISELO~1\juso.dll -/- {7CCA4EA6-CA02-4789-9419-34E85C7AC2DC}
----------------------------------------------------------------------
A001 innocdn.com
A002 in.sponsorkeyword.co.kr
A003 download.barosearch.co.kr
A004 cpq.clickstory.co.kr
A005 appsrv.filebus.co.kr
A006 api.sponsorkeyword.co.kr
A007 adm.cpaacademy.co.kr
----------------------------------------------------------------------
Deleted Files : 37
Remove Service : 2
Remove Uninstall Entry : 6
Remove Startup Entry : 4
Remove Browser Helper Object : 1
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
[01-HKCUREG]**sponsorkeyword
[01-HKCUREG]**BaroSearch
[01-HKCUREG]**Safeterra
[01-HKCUREG]**WiseLook Application
[03-BHOCLSD]**{7CCA4EA6-CA02-4789-9419-34E85C7AC2DC}
[05-SERVICE]**QuickDownload Agent
[05-SERVICE]**QuickDownload Service
----------------------------------------------------------------------
Total Processing Time : 460ms
----------------------------------------------------------------------
What's new : US045 sponsorkeyword -/- C:\Program Files\sponsorkeyword\sponsorkeyword.exe
----------------------------------------------------------------------

저작자 표시
신고



요즘 휴대폰 소액결제(월정액 자동결제)를 이용한 사기사이트 및 사기프로그램이 판을 치고 있습니다.
무료백신 프로그램, 무료개인정보삭제 프로그램, 무료 유해사이트차단 프로그램, 무료파일다운, 무료문자, 무료운세, 무료로또, 무료게임, 무료MP3등의 사이트에서 휴대폰 및 일반전화로 절대 인증 하지마세요.

인증하는 즉시 결제되며, 서비스를 해지하지 않는 이상 매월 자동결제됩니다. (인증번호 = 결제번호)
업체마다 결제되는 기간은 다르지만 짧게는 2년, 길게는 20년, 최대 50년짜리도 있습니다.
서비스 업체의 이용약관 및 결제내용에 대해 확실히 알고 인증/사용하시기 바랍니다.
안드로이드계열 스마트폰에서 출처가 없는 설치파일도 다운받지말고 실행하지도 마세요.
해당 통신사에 전화해서 소액결제 안되게끔 차단시키세요. (스마트폰에 무지한 아이들/노인분들 주의)

*악덕업체의 요청으로 인하여 블로그의 게시글이 이유없이 삭제되는 경우 구글 블로그에 재게시 합니다.
[ 2011.06.11 13:40 ] Posted by windowexe.com , 프로그램분석

댓글을 달아 주세요

  1. windowexe.com - 2012.04.19 14:25 신고 댓글주소 수정/삭제 댓글쓰기

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================

    echo Start
    echo windowexe.com & tskill "WkipUpdate" & echo windowdel.com
    echo windowexe.com & tskill "wizenir" & echo windowdel.com
    echo windowexe.com & tskill "svcwin" & echo windowdel.com
    echo windowexe.com & tskill "SafeTerraUpdate" & echo windowdel.com
    echo windowexe.com & tskill "SafeTerra" & echo windowdel.com
    echo windowexe.com & tskill "reservereset" & echo windowdel.com
    echo windowexe.com & tskill "PopLink" & echo windowdel.com
    echo windowexe.com & tskill "Opentabup" & echo windowdel.com
    echo windowexe.com & tskill "Opentabhper" & echo windowdel.com
    echo windowexe.com & tskill "Opentabch" & echo windowdel.com
    echo windowexe.com & tskill "OpenTab" & echo windowdel.com
    echo windowexe.com & tskill "microWebAD" & echo windowdel.com
    echo windowexe.com & tskill "ecomntsv" & echo windowdel.com
    echo windowexe.com & tskill "cloudpop" & echo windowdel.com
    echo windowexe.com & tskill "addentoolagent" & echo windowdel.com
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "cloud_.exe" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "cloud_.exe" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "cloudpop.exe" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "cloudpop.exe" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Wizeni" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Wizeni" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "microWebAD.exe" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "microWebAD.exe" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "plink" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "plink" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "InfoScan Worker" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "InfoScan Worker" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "addentoolagent" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "addentoolagent" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "AddendumAgent" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "AddendumAgent" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Opentabup" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Opentabup" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Opentabhper" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Opentabhper" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Opentab" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Opentab" /f
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DA742A73-CFA7-4DE2-BF28-1FC51CF214BC}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DA742A73-CFA7-4DE2-BF28-1FC51CF214BC}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DA742A73-CFA7-4DE2-BF28-1FC51CF214BC}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{DA742A73-CFA7-4DE2-BF28-1FC51CF214BC}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC01FC6C-7E27-4AFB-AC0E-36230DF6084E}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC01FC6C-7E27-4AFB-AC0E-36230DF6084E}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC01FC6C-7E27-4AFB-AC0E-36230DF6084E}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{CC01FC6C-7E27-4AFB-AC0E-36230DF6084E}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC68E426-72B1-4C4C-9910-D802FF47616D}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC68E426-72B1-4C4C-9910-D802FF47616D}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BC68E426-72B1-4C4C-9910-D802FF47616D}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{BC68E426-72B1-4C4C-9910-D802FF47616D}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B0C52541-4520-44e3-B3D6-5512CF31B89E}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B0C52541-4520-44e3-B3D6-5512CF31B89E}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B0C52541-4520-44e3-B3D6-5512CF31B89E}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{B0C52541-4520-44e3-B3D6-5512CF31B89E}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0000940A-F4A5-4773-9978-C4FF15AC168A}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0000940A-F4A5-4773-9978-C4FF15AC168A}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0000940A-F4A5-4773-9978-C4FF15AC168A}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{0000940A-F4A5-4773-9978-C4FF15AC168A}" /f
    echo Created by Windowexe.com
    sc stop "Wizeni Service"
    echo Service Disable & sc config "Wizeni Service" start= disabled & echo Windowexe.com
    sc stop "wecomntsv"
    echo Service Disable & sc config "wecomntsv" start= disabled & echo Windowexe.com
    sc stop "best-pcService"
    echo Service Disable & sc config "best-pcService" start= disabled & echo Windowexe.com
    sc stop "best-pc Update Service"
    echo Service Disable & sc config "best-pc Update Service" start= disabled & echo Windowexe.com
    sc stop "InfoSvc"
    echo Service Disable & sc config "InfoSvc" start= disabled & echo Windowexe.com
    echo schtasks Delete & schtasks /delete /tn "Windows CloudController Manager_" /f
    echo Created by Windowexe.com
    echo schtasks Delete & schtasks /delete /tn "Windows CloudController Manager" /f
    echo Created by Windowexe.com
    echo schtasks Delete & schtasks /delete /tn "Safeterra" /f
    echo Created by Windowexe.com
    echo schtasks Delete & schtasks /delete /tn "MicroWebAD Installer 1.1" /f
    echo Created by Windowexe.com
    echo schtasks Delete & schtasks /delete /tn "KeywordInfo" /f
    echo Created by Windowexe.com
    echo End

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================