프로그램분석

Code : REajsOmDADJAdDZ7OjVV/g4onl3fvFqRgxyscHkXHmM=

프로세스 천국 2013. 12. 18. 15:10

[00-PROCESS]**alg -/- C:\WINDOWS\System32\alg.exe
[00-PROCESS]**aspnet_state -/- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
[00-PROCESS]**cisvc -/- C:\WINDOWS\system32\cisvc.exe
[00-PROCESS]**clipsrv -/- C:\WINDOWS\system32\clipsrv.exe
[00-PROCESS]**csrss -/- C:\WINDOWS\system32\csrss.exe
[00-PROCESS]**ctfmon -/- C:\WINDOWS\system32\ctfmon.exe
[00-PROCESS]**daemonu -/- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
[00-PROCESS]**dllhost -/- C:\WINDOWS\system32\dllhost.exe
[00-PROCESS]**explorer -/- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[00-PROCESS]**FlashPlayerUpdateService -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[00-PROCESS]**GoogleUpdaterService -/- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
[00-PROCESS]**HncChecker -/- C:\Program Files\Common Files\Hnc\HncUtils\HncChecker.exe
[00-PROCESS]**IEXPLORE -/- C:\Program Files\Internet Explorer\IEXPLORE.EXE
[00-PROCESS]**imapi -/- C:\WINDOWS\system32\imapi.exe
[00-PROCESS]**IMKRMIG -/- C:\Program Files\Common Files\Microsoft Shared\IME12\IMEKR\IMKRMIG.EXE
[00-PROCESS]**infocard -/- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
[00-PROCESS]**jqs -/- C:\Program Files\Java\jre6\bin\jqs.exe
[00-PROCESS]**LMS -/- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
[00-PROCESS]**locator -/- C:\WINDOWS\system32\locator.exe
[00-PROCESS]**lsass -/- C:\WINDOWS\system32\lsass.exe
[00-PROCESS]**mdm -/- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
[00-PROCESS]**mnmsrvc -/- C:\WINDOWS\system32\mnmsrvc.exe
[00-PROCESS]**mscorsvw -/- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
[00-PROCESS]**msdtc -/- C:\WINDOWS\system32\msdtc.exe
[00-PROCESS]**msiexec -/- C:\WINDOWS\system32\msiexec.exe
[00-PROCESS]**netdde -/- C:\WINDOWS\system32\netdde.exe
[00-PROCESS]**npentac -/- C:\Program Files\INCAInternet\nProtect Enterprise 3.0\npentac.exe
[00-PROCESS]**npentagentsvc -/- C:\Program Files\INCAInternet\nProtect Enterprise 3.0\npentagentsvc.exe
[00-PROCESS]**npkcmsvc -/- C:\WINDOWS\system32\npkcmsvc.exe
[00-PROCESS]**npkfxsvc -/- C:\WINDOWS\system32\npkfxsvc.exe
[00-PROCESS]**nvsvc32 -/- C:\WINDOWS\system32\nvsvc32.exe
[00-PROCESS]**ODSERV -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[00-PROCESS]**OSE -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[00-PROCESS]**PaperSrv -/- C:\WINDOWS\system32\PaperSecu\PaperSrv.exe
[00-PROCESS]**PaSvc -/- C:\Program Files\AhnLab\APC2\Policy Agent\PaSvc.exe
[00-PROCESS]**popdev -/- C:\Documents and Settings\Administrator\Application Data\popdev\popdev.exe
[00-PROCESS]**popdevv -/- C:\Documents and Settings\Administrator\Application Data\popdev\popdevv.exe
[00-PROCESS]**PresentationFontCache -/- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
[00-PROCESS]**RKService -/- C:\WINDOWS\system32\RKService.exe
[00-PROCESS]**rsvp -/- C:\WINDOWS\system32\rsvp.exe
[00-PROCESS]**RTHDCPL -/- C:\WINDOWS\RTHDCPL.EXE
[00-PROCESS]**rundll32 -/- C:\WINDOWS\system32\rundll32.exe
[00-PROCESS]**SCardSvr -/- C:\WINDOWS\System32\SCardSvr.exe
[00-PROCESS]**SecuGate -/- C:\WINDOWS\system32\PaperSecu\SecuGate.exe
[00-PROCESS]**services -/- C:\WINDOWS\system32\services.exe
[00-PROCESS]**sessmgr -/- C:\WINDOWS\system32\sessmgr.exe
[00-PROCESS]**sharmav -/- C:\Documents and Settings\Administrator\Application Data\sharma\sharmav.exe
[00-PROCESS]**SMemo -/- C:\SMYSoft\SMemo\SMemo.exe
[00-PROCESS]**smlogsvc -/- C:\WINDOWS\system32\smlogsvc.exe
[00-PROCESS]**smss -/- C:\WINDOWS\System32\smss.exe
[00-PROCESS]**spoolsv -/- C:\WINDOWS\system32\spoolsv.exe
[00-PROCESS]**svchost -/- C:\WINDOWS\system32\svchost.exe
[00-PROCESS]**svcpaper -/- C:\WINDOWS\system32\PaperSecu\svcpaper.exe
[00-PROCESS]**tdinstchk_c -/- C:\WINDOWS\system32\install\tdinstchk_c.exe
[00-PROCESS]**tlntsvr -/- C:\WINDOWS\system32\tlntsvr.exe
[00-PROCESS]**TsService -/- C:\WINDOWS\system32\TsService.exe
[00-PROCESS]**UNS -/- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
[00-PROCESS]**ups -/- C:\WINDOWS\System32\ups.exe
[00-PROCESS]**uptnt -/- C:\Program Files\subjet\uptnt.exe
[00-PROCESS]**V3SP -/- C:\Program Files\AhnLab\V3IS80\V3SP.exe
[00-PROCESS]**V3Svc -/- C:\Program Files\AhnLab\V3IS80\V3Svc.exe
[00-PROCESS]**vssvc -/- C:\WINDOWS\System32\vssvc.exe
[00-PROCESS]**winlogon -/- C:\WINDOWS\system32\winlogon.exe
[00-PROCESS]**wmiapsrv -/- C:\WINDOWS\system32\wbem\wmiapsrv.exe
[00-PROCESS]**wmiprvse -/- C:\WINDOWS\system32\wbem\wmiprvse.exe
[00-PROCESS]**WMPNetwk -/- C:\Program Files\Windows Media Player\WMPNetwk.exe
[00-PROCESS]**wuauclt -/- C:\WINDOWS\system32\wuauclt.exe
[01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[01-HKCUREG]**HncUpdate -/- C:\Program Files\Common Files\Hnc\HncUtils\HncChecker.exe
[01-HKCUREG]**IMJPMIG8.1 -/- C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
[01-HKCUREG]**Korean IME Migration -/- C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE
[01-HKCUREG]**npent -/- C:\Program Files\INCAInternet\nProtect Enterprise 3.0\npent.exe
[01-HKCUREG]**NvCplDaemon -/- RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[01-HKCUREG]**PaTray -/- C:\Program Files\AhnLab\APC2\Policy Agent\patray.exe
[01-HKCUREG]**PHIME2002A -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
[01-HKCUREG]**PHIME2002ASync -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
[01-HKCUREG]**RTHDCPL -/- RTHDCPL.EXE
[01-HKCUREG]**SMemo Start -/- C:\SMYSoft\SMemo\SMemo.exe /login
[01-HKCUREG]**subjet -/- C:\Program Files\subjet\subjete.exe
[01-HKCUREG]**SunJavaUpdateSched -/- C:\Program Files\Common Files\Java\Java Update\jusched.exe
[01-HKCUREG]**TIMU Client -/- C:\WINDOWS\system32\install\\tdinstchk_c.exe
[01-HKCUREG]**uptnt -/- C:\Program Files\subjet\uptnt.exe
[01-HKCUREG]**V3 Session Process -/- C:\Program Files\AhnLab\V3IS80\V3SP.exe
[02-HKLMREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[02-HKLMREG]**HncUpdate -/- C:\Program Files\Common Files\Hnc\HncUtils\HncChecker.exe
[02-HKLMREG]**IMJPMIG8.1 -/- C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
[02-HKLMREG]**Korean IME Migration -/- C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE
[02-HKLMREG]**npent -/- C:\Program Files\INCAInternet\nProtect Enterprise 3.0\npent.exe
[02-HKLMREG]**NvCplDaemon -/- RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[02-HKLMREG]**PaTray -/- C:\Program Files\AhnLab\APC2\Policy Agent\patray.exe
[02-HKLMREG]**PHIME2002A -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
[02-HKLMREG]**PHIME2002ASync -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
[02-HKLMREG]**RTHDCPL -/- RTHDCPL.EXE
[02-HKLMREG]**SMemo Start -/- C:\SMYSoft\SMemo\SMemo.exe /login
[02-HKLMREG]**subjet -/- C:\Program Files\subjet\subjete.exe
[02-HKLMREG]**SunJavaUpdateSched -/- C:\Program Files\Common Files\Java\Java Update\jusched.exe
[02-HKLMREG]**TIMU Client -/- C:\WINDOWS\system32\install\\tdinstchk_c.exe
[02-HKLMREG]**uptnt -/- C:\Program Files\subjet\uptnt.exe
[02-HKLMREG]**V3 Session Process -/- C:\Program Files\AhnLab\V3IS80\V3SP.exe
[05-SERVICE]**AdobeFlashPlayerUpdateSvc -/- Adobe Flash Player Update Service -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[05-SERVICE]**GCRunS -/- GCodec Service -/- C:\PROGRA~1\GCodec\gcodecsvc.exe
[05-SERVICE]**gusvc -/- Google Software Updater -/- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
[05-SERVICE]**InfoSvc -/- InfoScan Manager -/- C:\KMC\Svc\InfoSvc.exe
[05-SERVICE]**JavaQuickStarterService -/- Java Quick Starter -/- C:\Program Files\Java\jre6\bin\jqs.exe -service -config C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf
[05-SERVICE]**LMS -/- Intel(R) Management and Security Application Local Management Service -/- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
[05-SERVICE]**MDM -/- Machine Debug Manager -/- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
[05-SERVICE]**napagent -/- Network Access Protection Agent -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\System32\qagentrt.dll
[05-SERVICE]**npAgentSvc -/- EnterpriseAgentService -/- C:\Program Files\INCAInternet\nProtect Enterprise 3.0\npentagentsvc.exe
[05-SERVICE]**NPENTAC -/- nProtect Enterprise 3.0 Access Control Service -/- C:\Program Files\INCAInternet\nProtect Enterprise 3.0\npentac.exe
[05-SERVICE]**npkcmsvc -/- npkcmsvc -/- C:\WINDOWS\system32\npkcmsvc.exe
[05-SERVICE]**npkfxsvc -/- npkfxsvc -/- C:\WINDOWS\system32\npkfxsvc.exe
[05-SERVICE]**NVSvc -/- NVIDIA Driver Helper Service -/- C:\WINDOWS\system32\nvsvc32.exe
[05-SERVICE]**nvUpdatusService -/- NVIDIA Update Service Daemon -/- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
[05-SERVICE]**odserv -/- Microsoft Office Diagnostics Service -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[05-SERVICE]**ose -/- Office Source Engine -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[05-SERVICE]**paSvc -/- Policy Agent Service -/- C:\Program Files\AhnLab\APC2\Policy Agent\PaSvc.exe
[05-SERVICE]**Pml Driver HPZ12 -/- Pml Driver HPZ12 -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\system32\HPZipm12.dll
[05-SERVICE]**popdevv -/- Now Dream Service Application -/- C:\Documents and Settings\Administrator\Application Data\popdev\popdevv.exe
[05-SERVICE]**RKSvc -/- RealKeyword Updater -/- C:\WINDOWS\system32\RKService.exe
[05-SERVICE]**RunS -/- MultidownLoad Service -/- C:\Documents and Settings\Administrator\APPLIC~1\MULTID~1\MultiDownLoadSvc.exe
[05-SERVICE]**sharmav -/- SubShop -/- C:\Documents and Settings\Administrator\Application Data\sharma\sharmav.exe
[05-SERVICE]**TCCheckAgent -/- TCCheckAgent -/- C:\Program Files\AdvTopC\TCCheckAgent.exe
[05-SERVICE]**TsService -/- TsService -/- C:\WINDOWS\system32\TsService.exe
[05-SERVICE]**UNS -/- Intel(R) Management and Security Application User Notification Service -/- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
[05-SERVICE]**V3 Service -/- V3 Service -/- C:\Program Files\AhnLab\V3IS80\V3Svc.exe
[05-SERVICE]**W32Print -/- Windows Spooler -/- C:\WINDOWS\system32\PaperSecu\svcpaper.exe
[05-SERVICE]**Windows WinsPop Diagnostics Service -/- Windows WinsPop Diagnostics Service -/- C:\WINDOWS\System32\wdrwspsvc.exe