애드웨어, 허위백신, 팝업광고, 쇼핑몰 바로가기, 악성툴바, 각종 개쓰레기 프로그램 삭제 요청하기
이용약관을 안내하며 컴퓨터에 설치하는 개쓰레기 프로그램들은 백신으로 백날 돌려봐야 검색이 안됩니다.
개쓰레기 프로그램들은 아주 지능적이라서 전문가가 아니고서는 찾아내기가 어렵습니다.


----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Microsoft Windows XP Service Pack 3(5.1.2600.196608)
Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz / 767.48 MB
x86 Family 6 Model 37 Stepping 5
Date : 2011-08-09
----------------------------------------------------------------------
DF002 C:\Program Files\PODCorn\PCorn_Updater.exe
DF003 C:\Program Files\PODCorn\PCornR.exe
DF004 C:\Program Files\PODCorn\PCornUninst.exe
DF005 C:\Program Files\PODCorn\Podcorn_Downloader.exe
DF006 C:\Program Files\PODCorn\Podcorn_Searcher.exe
DF007 C:\Program Files\PODCorn\Podcorn_Update.exe
DF008 C:\Program Files\PODCorn\Podcorn_Updater.exe
DF009 C:\Program Files\PODCorn\uninst.exe
DF010 C:\WINDOWS\system32\FLXGDKO.DLL
DF011 C:\WINDOWS\system32\I_P.exe
DF012 C:\WINDOWS\system32\INETKO.DLL
DF013 C:\WINDOWS\system32\MSCMCKO.DLL
DF014 C:\WINDOWS\system32\MSFLXGRD.OCX
DF015 C:\WINDOWS\system32\MSINET.OCX
DF016 C:\WINDOWS\system32\SPR32X60.ocx
DF017 C:\WINDOWS\system32\U_P.exe
DF018 C:\WINDOWS\system32\UD_P.exe
DF019 C:\WINDOWS\system32\VB6STKIT.DLL
----------------------------------------------------------------------
UN020 PODCorn SoundCasting Mashup 0.0.7 -/- DreamCatch Team -/- PODCorn SoundCasting Mashup -/--/- -
----------------------------------------------------------------------
US021 PODCorn -/- C:\Program Files\PODCorn\PCorn_Updater.exe
----------------------------------------------------------------------
NA000 ad.livepot.co.kr/check_counter.php?gu=631EDEEE3470643783C6E5665**.***
NA001 friender.co.kr/updateserver/MP3Setting/Chatsite*.***
NA002 friender.co.kr/updateserver/MP3Setting/Setting*.***
NA003 friender.co.kr/updateserver/MP3Setting/UpdateInfo*.***
NA004 friender.co.kr/updateserver/MP3UpdateList/ver03/Podcorn_Update.**.***
NA005 friender.co.kr/updateserver/MP3updateversion/version*.***
NA006 friender.co.kr/updateserver/MP3updateversion/versionChk*.***
NA007 livepot.co.kr/updateserver/analysis/PODCorn_Booting.*.***
NA008 livepot.co.kr/updateserver/analysis/podcorn_install.*.***
NA009 livepot.co.kr/updateserver/analysis/PODCorn_RealLog.*.***
NA010 livepot.co.kr/updateserver/analysis/PODCorn_Update.*.***
NA011 livepot.co.kr/updateserver/analysis/scree*.***
NA012 music.mnet.com/chart/chart_RealUp*.***
NA013 podcorn.co.kr/podcorn/livemp3/live*.***
----------------------------------------------------------------------
Deleted Files : 20
Remove Uninstall Entry : 1
Remove Startup Entry : 1
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
[01-HKCUREG]**PODCorn
----------------------------------------------------------------------
Total Processing Time : 78ms
----------------------------------------------------------------------

신고



요즘 휴대폰 소액결제(월정액 자동결제)를 이용한 사기사이트 및 사기프로그램이 판을 치고 있습니다.
무료백신 프로그램, 무료개인정보삭제 프로그램, 무료 유해사이트차단 프로그램, 무료파일다운, 무료문자, 무료운세, 무료로또, 무료게임, 무료MP3등의 사이트에서 휴대폰 및 일반전화로 절대 인증 하지마세요.

인증하는 즉시 결제되며, 서비스를 해지하지 않는 이상 매월 자동결제됩니다. (인증번호 = 결제번호)
업체마다 결제되는 기간은 다르지만 짧게는 2년, 길게는 20년, 최대 50년짜리도 있습니다.
서비스 업체의 이용약관 및 결제내용에 대해 확실히 알고 인증/사용하시기 바랍니다.
안드로이드계열 스마트폰에서 출처가 없는 설치파일도 다운받지말고 실행하지도 마세요.
해당 통신사에 전화해서 소액결제 안되게끔 차단시키세요. (스마트폰에 무지한 아이들/노인분들 주의)

*악덕업체의 요청으로 인하여 블로그의 게시글이 이유없이 삭제되는 경우 구글 블로그에 재게시 합니다.
[ 2011.08.10 00:21 ] Posted by windowexe.com , 프로그램분석

댓글을 달아 주세요

  1. windowexe.com - 2012.02.05 23:45 신고 댓글주소 수정/삭제 댓글쓰기

    System Analyzer Report 2012, 02, 05


    ======================================================================
    ======================================================================

    echo Start
    echo windowexe.com & tskill "DownLoadGet" & echo windowdel.com
    echo windowexe.com & tskill "DownLoadGetUpgrade" & echo windowdel.com
    echo windowexe.com & tskill "DownLoadGetupHp" & echo windowdel.com
    echo windowexe.com & tskill "everytoolbarapp" & echo windowdel.com
    echo windowexe.com & tskill "iNoonopen" & echo windowdel.com
    echo windowexe.com & tskill "INoonSvc" & echo windowdel.com
    echo windowexe.com & tskill "kos_earchup" & echo windowdel.com
    echo windowexe.com & tskill "ntasvr" & echo windowdel.com
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "DGStart" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "DGStart" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "DGup2Start" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "DGup2Start" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "kos_earchup" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "kos_earchup" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "ProcessingUnit" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "ProcessingUnit" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "ntasvr" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "ntasvr" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "boansolution main" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "boansolution main" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "boansolutionstart.exe" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "boansolutionstart.exe" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "everytoolbar" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "everytoolbar" /f
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11234321-ABCD-9878-0102-030A0F0B094F}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11234321-ABCD-9878-0102-030A0F0B094F}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11234321-ABCD-9878-0102-030A0F0B094F}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{11234321-ABCD-9878-0102-030A0F0B094F}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1DD969CD-3842-4EAD-A912-1429DCC1638D}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1DD969CD-3842-4EAD-A912-1429DCC1638D}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1DD969CD-3842-4EAD-A912-1429DCC1638D}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{1DD969CD-3842-4EAD-A912-1429DCC1638D}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC92C53E-A5C1-4D33-995C-AB7BB869E0E6}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC92C53E-A5C1-4D33-995C-AB7BB869E0E6}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BC92C53E-A5C1-4D33-995C-AB7BB869E0E6}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{BC92C53E-A5C1-4D33-995C-AB7BB869E0E6}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E9176D00-F8EB-4E40-B09C-04FD140CA277}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E9176D00-F8EB-4E40-B09C-04FD140CA277}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E9176D00-F8EB-4E40-B09C-04FD140CA277}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{E9176D00-F8EB-4E40-B09C-04FD140CA277}" /f
    echo Created by Windowexe.com
    sc stop "pcupgrade Update Service"
    echo Service Disable & sc config "pcupgrade Update Service" start= disabled & echo Windowexe.com
    sc stop "pcupgradeService"
    echo Service Disable & sc config "pcupgradeService" start= disabled & echo Windowexe.com
    sc stop "INoonSvc"
    echo Service Disable & sc config "INoonSvc" start= disabled & echo Windowexe.com
    sc stop "SlService"
    echo Service Disable & sc config "SlService" start= disabled & echo Windowexe.com
    sc stop "SlProtectService"
    echo Service Disable & sc config "SlProtectService" start= disabled & echo Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{4FF9A494-ED8E-4A13-A675-88983140B3CB}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{4FF9A494-ED8E-4A13-A675-88983140B3CB}" /f
    echo Created by Windowexe.com
    echo 000 & reg.exe delete "HKCR\CLSID\{A1D34FA0-8E38-4CB2-BDB1-662110652C08}" /f & echo windowdel.com
    echo Created by Windowexe.com
    echo file Delete & attrib -r "C:\Documents and Settings\Administrator\바탕 화면\11st.URL"
    echo file Delete & del /q "C:\Documents and Settings\Administrator\바탕 화면\11st.URL"
    echo file Delete & attrib -r "C:\Documents and Settings\Administrator\바탕 화면\G마켓.URL"
    echo file Delete & del /q "C:\Documents and Settings\Administrator\바탕 화면\G마켓.URL"
    echo file Delete & attrib -r "C:\Documents and Settings\Administrator\바탕 화면\옥션.URL"
    echo file Delete & del /q "C:\Documents and Settings\Administrator\바탕 화면\옥션.URL"
    echo End

    ======================================================================
    ======================================================================