애드웨어, 허위백신, 팝업광고, 쇼핑몰 바로가기, 악성툴바, 각종 개쓰레기 프로그램 삭제 요청하기
이용약관을 안내하며 컴퓨터에 설치하는 개쓰레기 프로그램들은 백신으로 백날 돌려봐야 검색이 안됩니다.
개쓰레기 프로그램들은 아주 지능적이라서 전문가가 아니고서는 찾아내기가 어렵습니다.


----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Microsoft Windows XP Service Pack 3(5.1.2600.196608)
Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz / 767.48 MB
x86 Family 6 Model 37 Stepping 5
Date : 2012-03-15
----------------------------------------------------------------------
DF000 C:\Program Files\MYPC\CallWebService.exe
DF001 C:\Program Files\MYPC\MyPC.exe
DF002 C:\Program Files\MYPC\MyPcCheck.exe
DF003 C:\Program Files\MYPC\MyPcUpdate.exe
DF004 C:\Program Files\MYPC\MYPCusage.exe
DF005 C:\Program Files\MYPC\OpenPot.exe
DF006 C:\Program Files\MYPC\PcCheckMasterX.ocx
----------------------------------------------------------------------
SC007 PcONUsageService -/- PcON Usage Application -/- - -/-  -/- "C:\Program Files\MYPC\MYPCusage.exe"
----------------------------------------------------------------------
UN008 MYPC -/- mypcis.com -/- {DFEFAD95-76AC-4BFB-B64D-2590C2DDDB77} -/- mypcis.com -/-
----------------------------------------------------------------------
US009 OpenPot -/- C:\Program Files\MYPC\OpenPot.exe
----------------------------------------------------------------------
001. adm.adgod.co.kr/app/config*.***
002. adm.adgod.co.kr/app/index.php?domain=mypcis.com&ap*.***
003. adm.adgod.co.kr/app/setup.php?app=42&mode=exec*.***
004. adm.adgod.co.kr/app/setup.php?app=42&mode=inst*.***
005. ww*.ebuzz.co.kr/static/news/ranking/__icsFiles/afieldfile/2012/**.***
006. ww*.goodfile.net/xml/iframe_goodfile*.***
007. ww*.google-analytics.com/__utm.gif?utmwv=5.2.5&utms=1&utmn=4061**.***
008. ww*.google-analytics.com/__utm.gif?utmwv=5.2.5&utms=2&utmn=1256**.***
009. ww*.google-analytics.com/g*.***
010. ww*.mypcis.*.***
011. ww*.mypcis.com/app/counter/counter_proc.php?kind=0&ist_yn=1&ptn**.***
012. ww*.mypcis.com/app/counter/counter_proc.php?kind=0&ist_yn=1&ptn**.***
013. ww*.mypcis.com/app/counter/counter_proc.php?kind=1&ist_yn=1&ptn**.***
014. ww*.mypcis.com/app/mypc/update/mypcupdate*.***
015. ww*.mypcis.com/css/style*.***
016. ww*.mypcis.com/css/style_iframe*.***
017. ww*.mypcis.com/favicon*.***
018. ww*.mypcis.com/images/btn_mypcDown*.***
019. ww*.mypcis.com/images/idx_visual_banner*.***
020. ww*.mypcis.com/images/idx_visual01*.***
021. ww*.mypcis.com/images/mypc_03*.***
022. ww*.mypcis.com/js/commo*.***
023. ww*.mypcis.com/js/jquery-1.7.mi*.***
024. ww*.mypcis.com/m*.***
025. ww*.mypcis.com/mypc/down*.***
----------------------------------------------------------------------
Deleted Files : 7
Remove Service : 1
Remove Uninstall Entry : 1
Remove Startup Entry : 1
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
WindowexeAllkiller Remove Database 2012-03-15
[01-HKCUREG]**OpenPot
[05-SERVICE]**PcONUsageService
----------------------------------------------------------------------
Total Processing Time : 44ms
----------------------------------------------------------------------

신고



요즘 휴대폰 소액결제(월정액 자동결제)를 이용한 사기사이트 및 사기프로그램이 판을 치고 있습니다.
무료백신 프로그램, 무료개인정보삭제 프로그램, 무료 유해사이트차단 프로그램, 무료파일다운, 무료문자, 무료운세, 무료로또, 무료게임, 무료MP3등의 사이트에서 휴대폰 및 일반전화로 절대 인증 하지마세요.

인증하는 즉시 결제되며, 서비스를 해지하지 않는 이상 매월 자동결제됩니다. (인증번호 = 결제번호)
업체마다 결제되는 기간은 다르지만 짧게는 2년, 길게는 20년, 최대 50년짜리도 있습니다.
서비스 업체의 이용약관 및 결제내용에 대해 확실히 알고 인증/사용하시기 바랍니다.
안드로이드계열 스마트폰에서 출처가 없는 설치파일도 다운받지말고 실행하지도 마세요.
해당 통신사에 전화해서 소액결제 안되게끔 차단시키세요. (스마트폰에 무지한 아이들/노인분들 주의)

*악덕업체의 요청으로 인하여 블로그의 게시글이 이유없이 삭제되는 경우 구글 블로그에 재게시 합니다.
[ 2012.03.15 21:03 ] Posted by windowexe.com , 프로그램분석

댓글을 달아 주세요

  1. windowexe.com - 2012.03.15 21:04 신고 댓글주소 수정/삭제 댓글쓰기

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================

    echo Start
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "OpenPot" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "OpenPot" /f
    sc stop "PcONUsageService"
    echo Service Disable & sc config "PcONUsageService" start= disabled & echo Windowexe.com
    echo End

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================

  2. windowexe.com - 2012.03.15 22:31 신고 댓글주소 수정/삭제 댓글쓰기

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================

    echo Start
    echo windowexe.com & tskill "smartsaferU" & echo windowdel.com
    echo windowexe.com & tskill "smartsafer" & echo windowdel.com
    echo windowexe.com & tskill "pwtray" & echo windowdel.com
    echo windowexe.com & tskill "greenopenuper" & echo windowdel.com
    echo windowexe.com & tskill "greenopenhper" & echo windowdel.com
    echo windowexe.com & tskill "greenopench" & echo windowdel.com
    echo windowexe.com & tskill "greenopen" & echo windowdel.com
    echo windowexe.com & tskill "FavoriteIconsUpdate" & echo windowdel.com
    echo windowexe.com & tskill "FavoriteIconsControl" & echo windowdel.com
    echo windowexe.com & tskill "FavoriteIcons" & echo windowdel.com
    echo windowexe.com & tskill "DownLoadGetupHp" & echo windowdel.com
    echo windowexe.com & tskill "DownLoadGetUpgrade" & echo windowdel.com
    echo windowexe.com & tskill "DownLoadGet" & echo windowdel.com
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "PowerPc" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "PowerPc" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "smartsafer main" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "smartsafer main" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "everytoolbar" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "everytoolbar" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "greenopen" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "greenopen" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Favorite_Icons" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Favorite_Icons" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "DGup2Start" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "DGup2Start" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "DGStart" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "DGStart" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "DirectKeyword2" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "DirectKeyword2" /f
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67421A26-71F2-4E57-89B2-E49C6FD90DA1}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67421A26-71F2-4E57-89B2-E49C6FD90DA1}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{67421A26-71F2-4E57-89B2-E49C6FD90DA1}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{67421A26-71F2-4E57-89B2-E49C6FD90DA1}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D4D2A74-0249-49E6-BC41-0586A0333CB3}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D4D2A74-0249-49E6-BC41-0586A0333CB3}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4D4D2A74-0249-49E6-BC41-0586A0333CB3}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{4D4D2A74-0249-49E6-BC41-0586A0333CB3}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1DD969CD-3842-4EAD-A912-1429DCC1638D}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1DD969CD-3842-4EAD-A912-1429DCC1638D}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1DD969CD-3842-4EAD-A912-1429DCC1638D}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{1DD969CD-3842-4EAD-A912-1429DCC1638D}" /f
    echo Created by Windowexe.com
    sc stop "smartsafer Update Service"
    echo Service Disable & sc config "smartsafer Update Service" start= disabled & echo Windowexe.com
    echo 000 & reg.exe delete "HKCR\CLSID\{A1D34FA0-8E38-4CB2-BDB1-662110652C08}" /f & echo windowdel.com
    echo Created by Windowexe.com
    echo End

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================

  3. windowexe.com - 2012.06.06 21:50 신고 댓글주소 수정/삭제 댓글쓰기

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================

    echo Start
    echo windowexe.com & tskill "microsofttoppoint" & echo windowdel.com
    echo windowexe.com & tskill "natsvc" & echo windowdel.com
    echo windowexe.com & tskill "natsvc" & echo windowdel.com
    echo windowexe.com & tskill "SCChkUpd" & echo windowdel.com
    echo windowexe.com & tskill "sidematch" & echo windowdel.com
    echo windowexe.com & tskill "WinCloud" & echo windowdel.com
    echo windowexe.com & tskill "WinCloud" & echo windowdel.com
    echo windowexe.com & tskill "WindowServiceNT" & echo windowdel.com
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "sidematch" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "sidematch" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicrosoftToppoint" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicrosoftToppoint" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "scchk" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "scchk" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicrowindowSearch" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicrowindowSearch" /f
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{86727A1A-8140-4CFA-ABFA-1620398FCEC5}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86727A1A-8140-4CFA-ABFA-1620398FCEC5}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{86727A1A-8140-4CFA-ABFA-1620398FCEC5}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{86727A1A-8140-4CFA-ABFA-1620398FCEC5}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87F960CE-F106-4AE2-A395-33F819275B6F}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87F960CE-F106-4AE2-A395-33F819275B6F}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{87F960CE-F106-4AE2-A395-33F819275B6F}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{87F960CE-F106-4AE2-A395-33F819275B6F}" /f
    echo Created by Windowexe.com
    sc stop "ApplicationSpecialManagement"
    echo Service Disable & sc config "ApplicationSpecialManagement" start= disabled & echo Windowexe.com
    sc stop "BioTools"
    echo Service Disable & sc config "BioTools" start= disabled & echo Windowexe.com
    sc stop "NATService"
    echo Service Disable & sc config "NATService" start= disabled & echo Windowexe.com
    sc stop "Owuylvd"
    echo Service Disable & sc config "Owuylvd" start= disabled & echo Windowexe.com
    sc stop "WinCloud"
    echo Service Disable & sc config "WinCloud" start= disabled & echo Windowexe.com
    sc stop "wlauncnt SVC"
    echo Service Disable & sc config "wlauncnt SVC" start= disabled & echo Windowexe.com
    sc stop "wnpdscnt SVC"
    echo Service Disable & sc config "wnpdscnt SVC" start= disabled & echo Windowexe.com
    sc stop "Xyduyer"
    echo Service Disable & sc config "Xyduyer" start= disabled & echo Windowexe.com
    sc stop "ApplicationOffice"
    echo Service Disable & sc config "ApplicationOffice" start= disabled & echo Windowexe.com
    echo End

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================