프로그램분석

Code : fY3JkkPRxjabzplY8nnWTobKojeBxAHej5A41zSAp+aezm/7Qo9FZA==

프로세스 천국 2013. 9. 14. 23:40

[00-PROCESS]**alg -/- C:\windows\System32\alg.exe
[00-PROCESS]**AppSrv -/- C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
[00-PROCESS]**btwdins -/- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
[00-PROCESS]**ccSvcHst -/- C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe
[00-PROCESS]**csrss -/- C:\windows\system32\csrss.exe
[00-PROCESS]**CVHSVC -/- C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
[00-PROCESS]**dllhost -/- C:\windows\system32\dllhost.exe
[00-PROCESS]**DMAgent -/- C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
[00-PROCESS]**downhelper_se -/- C:\windows\system32\downhelper_se.exe
[00-PROCESS]**Dwm -/- C:\windows\system32\Dwm.exe
[00-PROCESS]**entering-se -/- C:\windows\system32\entering-se.exe
[00-PROCESS]**enumerate_gtu -/- C:\Program Files\enumerate\gt\enumerate_gtu.exe
[00-PROCESS]**enumst -/- C:\Program Files\enumerate\gt\enumst.exe
[00-PROCESS]**Explorer -/- C:\windows\Explorer.EXE
[00-PROCESS]**flashlinker-se -/- C:\windows\system32\flashlinker-se.exe
[00-PROCESS]**FlashPlayerUpdateService -/- C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[00-PROCESS]**fxssvc -/- C:\windows\system32\fxssvc.exe
[00-PROCESS]**GameConsoleService -/- C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe
[00-PROCESS]**GoogleUpdate -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[00-PROCESS]**GoogleUpdaterService -/- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
[00-PROCESS]**iexplore -/- C:\Program Files\Internet Explorer\iexplore.exe
[00-PROCESS]**infocard -/- C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
[00-PROCESS]**infoconditionalreset -/- C:\windows\infoconditionalreset.exe
[00-PROCESS]**InfoScan -/- C:\KMC\InfoScan\InfoScan.exe
[00-PROCESS]**InfoSvc -/- C:\KMC\Svc\InfoSvc.exe
[00-PROCESS]**InfoWrk -/- C:\KMC\InfoScan\InfoWrk.exe
[00-PROCESS]**internetdownload_se -/- C:\windows\system32\internetdownload_se.exe
[00-PROCESS]**locator -/- C:\windows\system32\locator.exe
[00-PROCESS]**lsass -/- C:\windows\system32\lsass.exe
[00-PROCESS]**lsm -/- C:\windows\system32\lsm.exe
[00-PROCESS]**MpCmdRun -/- c:\program files\windows defender\MpCmdRun.exe
[00-PROCESS]**mscorsvw -/- C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
[00-PROCESS]**mscorsvw -/- C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
[00-PROCESS]**msdtc -/- C:\windows\System32\msdtc.exe
[00-PROCESS]**msiexec -/- C:\windows\system32\msiexec.exe
[00-PROCESS]**multiboanService -/- C:\Program Files\multiboan\multiboanService.exe
[00-PROCESS]**NaverAdminAPISvc -/- C:\Program Files\Naver\NaverCommon\NaverAdminAPISvc.exe
[00-PROCESS]**NCleanService -/- C:\Program Files\Naver\NaverCleaner\NCleanService.exe
[00-PROCESS]**NOBuAgent -/- C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe
[00-PROCESS]**npkfxsvc -/- C:\windows\system32\npkfxsvc.exe
[00-PROCESS]**ODSERV -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[00-PROCESS]**OSE -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[00-PROCESS]**OSPPSVC -/- C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
[00-PROCESS]**PresentationFontCache -/- C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
[00-PROCESS]**ProcessClean -/- C:\Program Files\ProcessClean\ProcessClean.exe
[00-PROCESS]**RPGSvcMan -/- C:\Users\Administrator\AppData\Roaming\RapidGet\RPGSvcMan.exe
[00-PROCESS]**rundll32 -/- \rundll32.exe
[00-PROCESS]**SearchIndexer -/- C:\windows\system32\SearchIndexer.exe
[00-PROCESS]**SearchProtocolHost -/- C:\windows\system32\SearchProtocolHost.exe
[00-PROCESS]**services -/- C:\windows\system32\services.exe
[00-PROCESS]**sftlist -/- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
[00-PROCESS]**sftvsa -/- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
[00-PROCESS]**shadyac -/- C:\windows\system32\config\systemprofile\AppData\Roaming\wingshadyac\shadyac.exe
[00-PROCESS]**shadyacs -/- C:\windows\system32\config\systemprofile\AppData\Roaming\wingshadyac\shadyacs.exe
[00-PROCESS]**SmartKeySvc -/- C:\Program Files\SmartKey\SmartKeySvc.exe
[00-PROCESS]**SmartKeyUpt -/- C:\Program Files\SmartKey\SmartKeyUpt.exe
[00-PROCESS]**smartmode_se -/- C:\windows\system32\smartmode_se.exe
[00-PROCESS]**SmartPopSvc -/- C:\Program Files\SmartPop\SmartPopSvc.exe
[00-PROCESS]**SmartPopUpt -/- C:\Program Files\SmartPop\SmartPopUpt.exe
[00-PROCESS]**smart-update-se -/- C:\Program Files\smart-update\smart-update-se.exe
[00-PROCESS]**SMSvcHost -/- C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
[00-PROCESS]**snmptrap -/- C:\windows\System32\snmptrap.exe
[00-PROCESS]**spoolsv -/- C:\windows\System32\spoolsv.exe
[00-PROCESS]**sppsvc -/- C:\windows\system32\sppsvc.exe
[00-PROCESS]**SUPDSvc -/- C:\windows\System32\SUPDSvc.exe
[00-PROCESS]**svchost -/- C:\windows\system32\svchost.exe
[00-PROCESS]**system-service-se -/- C:\Program Files\system-service\system-service-se.exe
[00-PROCESS]**system-update-se -/- C:\Program Files\system-update\system-update-se.exe
[00-PROCESS]**taskhost -/- C:\windows\system32\taskhost.exe
[00-PROCESS]**TrustedInstaller -/- C:\windows\servicing\TrustedInstaller.exe
[00-PROCESS]**UI0Detect -/- C:\windows\system32\UI0Detect.exe
[00-PROCESS]**Updater -/- C:\Program Files\Skype\Updater\Updater.exe
[00-PROCESS]**updateservice-se -/- C:\Program Files\updateservice\updateservice-se.exe
[00-PROCESS]**userconfigwinreset -/- C:\windows\userconfigwinreset.exe
[00-PROCESS]**vds -/- C:\windows\System32\vds.exe
[00-PROCESS]**vssvc -/- C:\windows\system32\vssvc.exe
[00-PROCESS]**wbengine -/- C:\windows\system32\wbengine.exe
[00-PROCESS]**webedit_svc_10_3 -/- C:\Program Files\WebEdit\webedit_svc_10_3.exe
[00-PROCESS]**wediasvc -/- C:\windows\System32\wediasvc.exe
[00-PROCESS]**WinBstrRamt -/- C:\Program Files\WindowsBooster\WinBstrRamt.exe
[00-PROCESS]**windowuserinforeset -/- C:\windows\windowuserinforeset.exe
[00-PROCESS]**winggou -/- C:\Windows\System32\config\systemprofile\AppData\Roaming\WingGo\winggou.exe
[00-PROCESS]**wininit -/- C:\windows\system32\wininit.exe
[00-PROCESS]**winlogon -/- C:\windows\system32\winlogon.exe
[00-PROCESS]**wlcrasvc -/- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
[00-PROCESS]**WLIDSVC -/- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
[00-PROCESS]**WLIDSvcM -/- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
[00-PROCESS]**WmiApSrv -/- C:\windows\system32\wbem\WmiApSrv.exe
[00-PROCESS]**wmiprvse -/- C:\windows\system32\wbem\wmiprvse.exe
[00-PROCESS]**wmpnetwk -/- C:\Program Files\Windows Media Player\wmpnetwk.exe
[00-PROCESS]**wuauclt -/- C:\windows\system32\wuauclt.exe
[01-HKCUREG]**Configuring -/- rundll32.exe C:\windows\TEMP\178355.txtM
[01-HKCUREG]**Enumerate_gt -/- C:\Program Files\enumerate\gt\enumerate_gtu.exe Runcmd
[01-HKCUREG]**Enumerate_gtst -/- C:\Program Files\enumerate\gt\enumst.exe Runcmd
[01-HKCUREG]**InfoScan Worker -/- C:\KMC\InfoScan\InfoWrk.exe /I
[01-HKCUREG]**ProcessClean -/- C:\Program Files\ProcessClean\ProcessClean.exe
[01-HKCUREG]**SmartKeyUpdater -/- C:\Program Files\SmartKey\SmartKeyUpt.exe
[01-HKCUREG]**SmartPopUpdater -/- C:\Program Files\SmartPop\SmartPopUpt.exe
[01-HKCUREG]**WingGo -/- C:\Windows\System32\config\systemprofile\AppData\Roaming\WingGo\winggou.exe UPDATE
[02-HKLMREG]**Configuring -/- rundll32.exe C:\windows\TEMP\178355.txtM
[02-HKLMREG]**Enumerate_gt -/- C:\Program Files\enumerate\gt\enumerate_gtu.exe Runcmd
[02-HKLMREG]**Enumerate_gtst -/- C:\Program Files\enumerate\gt\enumst.exe Runcmd
[02-HKLMREG]**InfoScan Worker -/- C:\KMC\InfoScan\InfoWrk.exe /I
[02-HKLMREG]**ProcessClean -/- C:\Program Files\ProcessClean\ProcessClean.exe
[02-HKLMREG]**SmartKeyUpdater -/- C:\Program Files\SmartKey\SmartKeyUpt.exe
[02-HKLMREG]**SmartPopUpdater -/- C:\Program Files\SmartPop\SmartPopUpt.exe
[02-HKLMREG]**WingGo -/- C:\Windows\System32\config\systemprofile\AppData\Roaming\WingGo\winggou.exe UPDATE
[03-BHOCLSD]**N.A -/- N.A -/- {C9133CA1-662F-4237-80E3-B623C4D6E461}
[03-BHOCLSD]**Symantec Intrusion Prevention -/- C:\Program Files\Norton Internet Security\Engine\18.7.2.3\IPS\IPSBHO.DLL -/- {6D53EC84-6AAE-4787-AEEE-F4628F01010C}
[03-BHOCLSD]**Symantec NCO BHO -/- C:\Program Files\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll -/- {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}
[04-TOOLBAR]**N.A -/- N.A -/- Locked
[04-TOOLBAR]**Norton Toolbar -/- C:\Program Files\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll -/- {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
[05-SERVICE]**AdobeFlashPlayerUpdateSvc -/- Adobe Flash Player Update Service -/- C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[05-SERVICE]**btwdins -/- Bluetooth Service -/- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
[05-SERVICE]**cvhsvc -/- Client Virtualization Handler -/- C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
[05-SERVICE]**DMAgent -/- 인텔(R) PROSet/무선 WiMAX 레드 벤드 장치 관리 서비스 -/- C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
[05-SERVICE]**downhelper Update Service -/- downhelper Support Service -/- C:\windows\system32\downhelper_se.exe
[05-SERVICE]**enteringservice -/- Entering Service -/- C:\windows\system32\entering-se.exe
[05-SERVICE]**flashlinkerservice -/- Flashlinker Service -/- C:\windows\system32\flashlinker-se.exe
[05-SERVICE]**FontCache -/- Windows Font Cache Service -/- C:\windows\system32\svchost.exe -/- C:\windows\system32\FntCache.dll
[05-SERVICE]**GameConsoleService -/- GameConsoleService -/- C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe
[05-SERVICE]**gupdate -/- Google 업데이트 서비스 (gupdate) -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[05-SERVICE]**gupdatem -/- Google 업데이트 서비스 (gupdatem) -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[05-SERVICE]**gusvc -/- Google Software Updater -/- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
[05-SERVICE]**InfoSvc -/- InfoScan Manager -/- C:\KMC\Svc\InfoSvc.exe
[05-SERVICE]**InternetDownload Update Service -/- InternetDownload Support Service -/- C:\windows\system32\internetdownload_se.exe
[05-SERVICE]**multiboan Update Service -/- multiboan Support Service -/- C:\windows\userconfigwinreset.exe
[05-SERVICE]**multiboanService -/- multiboanService -/- C:\Program Files\multiboan\multiboanService.exe
[05-SERVICE]**Naver Updater -/- Naver Updater -/- C:\Program Files\Naver\NaverCommon\NaverAdminAPISvc.exe
[05-SERVICE]**NCleanService -/- Naver Cleaner Admin Service -/- C:\Program Files\Naver\NaverCleaner\NCleanService.exe
[05-SERVICE]**NIS -/- Norton Internet Security -/- C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe
[05-SERVICE]**NOBU -/- Norton Online Backup -/- C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE
[05-SERVICE]**npkfxsvc -/- npkfxsvc -/- C:\windows\system32\npkfxsvc.exe
[05-SERVICE]**odserv -/- Microsoft Office Diagnostics Service -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[05-SERVICE]**ose -/- Office  Source Engine -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[05-SERVICE]**osppsvc -/- Office Software Protection Platform -/- C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
[05-SERVICE]**pcsystem Update Service -/- pcsystem Support Service -/- C:\windows\infoconditionalreset.exe
[05-SERVICE]**RPGSvcman -/- RPGSvcman -/- C:\Users\Administrator\AppData\Roaming\RapidGet\RPGSvcMan.exe
[05-SERVICE]**Samsung UPD Service -/- Samsung UPD Service -/- C:\windows\System32\SUPDSvc.exe
[05-SERVICE]**sftlist -/- Application Virtualization Client -/- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
[05-SERVICE]**sftvsa -/- Application Virtualization Service Agent -/- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
[05-SERVICE]**shadyac -/- Microsoft AD WS -/- C:\windows\system32\config\systemprofile\AppData\Roaming\wingshadyac\shadyacs.exe
[05-SERVICE]**SkypeUpdate -/- Skype Updater -/- C:\Program Files\Skype\Updater\Updater.exe
[05-SERVICE]**SmartKeyService -/- SmartKey Agent Service -/- C:\Program Files\SmartKey/SmartKeySvc.exe
[05-SERVICE]**SmartMode Update Service -/- SmartMode Support Service -/- C:\windows\system32\smartmode_se.exe
[05-SERVICE]**SmartPopService -/- SmartPop Agent Service -/- C:\Program Files\SmartPop/SmartPopSvc.exe
[05-SERVICE]**smart-updateservice -/- smart-update service -/- C:\Program Files\smart-update\smart-update-se.exe
[05-SERVICE]**system-serviceservice -/- system-service service -/- C:\Program Files\system-service\system-service-se.exe
[05-SERVICE]**system-updateservice -/- system-update service -/- C:\Program Files\system-update\system-update-se.exe
[05-SERVICE]**updateserviceservice -/- updateservice service -/- C:\Program Files\updateservice\updateservice-se.exe
[05-SERVICE]**vaccintoolbar Update Service -/- vaccintoolbar Support Service -/- C:\windows\windowuserinforeset.exe
[05-SERVICE]**WiMAXAppSrv -/- 인텔(R) PROSet/무선 WiMAX 서비스 -/- C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
[05-SERVICE]**Windows WebEdit Diagnostics Service -/- Windows WebEdit Diagnostics Service -/- C:\windows\System32\wediasvc.exe
[05-SERVICE]**Windows WebEdit Update Class -/- Windows WebEdit Update Class -/- C:\Program Files\WebEdit\webedit_svc_10_3.exe
[05-SERVICE]**WindowsBoosterMonitor -/- WindowsBoosterMonitor -/- C:\Program Files\WindowsBooster\WinBstrRamt.exe
[05-SERVICE]**wlcrasvc -/- Windows Live Mesh remote connections service -/- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
[05-SERVICE]**wlidsvc -/- Windows Live ID Sign-in Assistant -/- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
[06-TASKLST]**Adobe Flash Player Updater -/- C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe