애드웨어, 허위백신, 팝업광고, 쇼핑몰 바로가기, 악성툴바, 각종 개쓰레기 프로그램 삭제 요청하기
이용약관을 안내하며 컴퓨터에 설치하는 개쓰레기 프로그램들은 백신으로 백날 돌려봐야 검색이 안됩니다.
개쓰레기 프로그램들은 아주 지능적이라서 전문가가 아니고서는 찾아내기가 어렵습니다.


----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeSystemLog
----------------------------------------------------------------------
Section Info
[R] Current Running Process
[U] HKEY_CURRENT_USER Startup Entry
[L] HKEY_LOCAL_MACHINE Startup Entry
[S] Service Entry(Service Name - Display Name - Type - Status - Dll and Exe Path
[B] Browser Helper Object Entry
[T] Internet explorer Toolbar Entry
[M] Internet Explorer Context menu Entry
[Z] Internet Explorer Trusted Site(2) / Restricted Site(4)
[X] ActiveX Entry
[C] Control Panel Program Add/Remove Entry
----------------------------------------------------------------------
R000 C:\VMWARE\KatMouse\KatMouse.exe
R001 C:\WINDOWS\system32\svchost.exe
R002 C:\WINDOWS\Explorer.EXE
R003 C:\VMWARE\Symbol Commander Pro\Sensiva.exe
R004 C:\WINDOWS\system32\csrss.exe
R005 C:\WINDOWS\system32\lsass.exe
R006 C:\WINDOWS\system32\svchost.exe
R007 C:\WINDOWS\system32\svchost.exe
R008 C:\WINDOWS\system32\services.exe
R009 C:\WINDOWS\system32\svchost.exe
R010 C:\VMWARE\Tfilemon.exe
R011 C:\VMWARE\WindowexeSystemLog.exe
R012 C:\WINDOWS\system32\svchost.exe
R013 C:\Program Files\BitAnalyzer\BitAnalyzer.exe
R014 C:\Program Files\CholReward\CholRewardStrt.exe
R015 C:\Program Files\VMware\VMware Tools\VMwareUser.exe
R016 C:\Program Files\CholToolBand\CholToolStrt.exe
R017 C:\Program Files\VMware\VMware Tools\VMwareService.exe
R018 C:\WINDOWS\system32\winlogon.exe
R019 C:\Program Files\Internet Explorer\IEXPLORE.EXE
R020 C:\Program Files\VMware\VMware Tools\vmacthlp.exe
R021 C:\WINDOWS\system32\smss.exe
R022 C:\VMWARE\ProcessExplorer\procexp.exe
----------------------------------------------------------------------
U023 Sensiva - C:\VMWARE\Symbol Commander Pro\Sensiva.exe
U024 KatMouse - C:\VMWARE\KatMouse\KatMouse.exe
U025 procexp - C:\VMWARE\ProcessExplorer\procexp.exe
U026 Tfilemon - C:\VMWARE\Tfilemon.exe
U027 Starcraft-wLauncher - C:\Program Files\wLauncher\wDup.exe -s
U028 6f636d726b7f6028637e63 - C:\Documents and Settings\Administrator\Application Data\tmyf.exe
U029 cholcpc_searchUpDate.exe - C:\Program Files\cholcpc_search\cholcpc_searchUpDate.exe
U030 linkdirectmain - C:\Program Files\linkdirect\linkdirectT.exe -o
U031 WebtoonRoom - C:\Program Files\WebtoonRoom\WebtoonRoom_Update.exe -r
U032 startoolsup - C:\Program Files\STARtools\StarToolsUP\STARUpdate.exe -o
U033 AnCamera - C:\Program Files\AHNSOFT\ancamera3\ancameraup.exe -o
U034 AnCamCorder - C:\Program Files\\AHNSOFT\AnCamCorder\ancamcorderupdate.exe -o
U035 Sing_MiniDn - C:\Program Files\Sing Mini\MiniSearchDn.exe -o
L036 VMware Tools - C:\Program Files\VMware\VMware Tools\VMwareTray.exe
L037 VMware User Process - C:\Program Files\VMware\VMware Tools\VMwareUser.exe
L038 funtop - C:\Program Files\fun\funtop\funtop.exe
L039 PcGkimi - C:\Program Files\PcGkimi\PcGkimi.exe /run1
L040 PostTip - C:\Program Files\PostTip\PostTip.exe
L041 PrivacyGreen - C:\Program Files\PrivacyGreen\PrivacyGreen.exe /run1
L042 VaccineScanMain - C:\Program Files\VaccineScan\VaccineScan.exe /Boot
L043 happylotto - C:\Program Files\HappyLotto\HappyLottoT.exe -o
L044 windowwizard - C:\Program Files\WindowWizard\WindowWizardT.exe -o
L045 StarSeeMain - C:\Program Files\STARtools\StarSee\starseeup.exe /boot
L046 StarPDFMain - C:\Program Files\STARtools\StarPDF\starpdfup.exe /boot
L047 singsingfile - C:\Program Files\singsingfile\singsingfileup.exe -r
L048 StarZipMain - C:\Program Files\STARtools\StarZip\starzipup.exe /boot
L049 PCLock - C:\Program Files\PCLock\PCLockUpdate.exe -o
----------------------------------------------------------------------
S050 Alerter - Alerter - Auto - Running - C:\WINDOWS\system32\alrsvc.dll - C:\WINDOWS\system32\svchost.exe -k LocalService
S051 ALG - Application Layer Gateway Service - Manual - Stopped -  - C:\WINDOWS\System32\alg.exe
S052 AppMgmt - Application Management - Manual - Stopped - C:\WINDOWS\System32\appmgmts.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S053 aspnet_state - ASP.NET State Service - Manual - Stopped - - - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
S054 AudioSrv - Windows Audio - Auto - Running - C:\WINDOWS\System32\audiosrv.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S055 BITS - Background Intelligent Transfer Service - Manual - Stopped - C:\WINDOWS\system32\qmgr.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S056 Browser - Computer Browser - Auto - Stopped - C:\WINDOWS\System32\browser.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S057 CiSvc - Indexing Service - Manual - Stopped -  - C:\WINDOWS\system32\cisvc.exe
S058 ClipSrv - ClipBook - Disabled - Stopped -  - C:\WINDOWS\system32\clipsrv.exe
S059 clr_optimization_v2.0.50727_32 - .NET Runtime Optimization Service v2.0.50727_X86 - Disabled - Stopped -  - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
S060 COMSysApp - COM+ System Application - Manual - Stopped -  - C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
S061 CryptSvc - Cryptographic Services - Auto - Running - C:\WINDOWS\System32\cryptsvc.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S062 DcomLaunch - DCOM Server Process Launcher - Auto - Running - C:\WINDOWS\system32\rpcss.dll - C:\WINDOWS\system32\svchost -k DcomLaunch
S063 Dhcp - DHCP Client - Auto - Running - C:\WINDOWS\System32\dhcpcsvc.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S064 dmadmin - Logical Disk Manager Administrative Service - Manual - Stopped - - - C:\WINDOWS\System32\dmadmin.exe /com
S065 dmserver - Logical Disk Manager - Auto - Running - C:\WINDOWS\System32\dmserver.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S066 Dnscache - DNS Client - Auto - Running - C:\WINDOWS\System32\dnsrslvr.dll - C:\WINDOWS\system32\svchost.exe -k NetworkService
S067 ERSvc - Error Reporting Service - Disabled - Stopped - C:\WINDOWS\System32\ersvc.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S068 Eventlog - Event Log - Auto - Running -  - C:\WINDOWS\system32\services.exe
S069 EventSystem - COM+ Event System - Manual - Running - C:\WINDOWS\system32\es.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S070 FastUserSwitchingCompatibility - Fast User Switching Compatibility - Manual - Running - C:\WINDOWS\System32\shsvcs.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S071 helpsvc - Help and Support - Disabled - Stopped - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S072 HidServ - Human Interface Device Access - Disabled - Stopped - C:\WINDOWS\System32\hidserv.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S073 HTTPFilter - HTTP SSL - Manual - Stopped - C:\WINDOWS\System32\w3ssl.dll - C:\WINDOWS\System32\svchost.exe -k HTTPFilter
S074 ImapiService - IMAPI CD-Burning COM Service - Manual - Stopped -  - C:\WINDOWS\system32\imapi.exe
S075 lanmanserver - Server - Auto - Running - C:\WINDOWS\System32\srvsvc.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S076 lanmanworkstation - Workstation - Auto - Running - C:\WINDOWS\System32\wkssvc.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S077 LmHosts - TCP/IP NetBIOS Helper - Auto - Running - C:\WINDOWS\System32\lmhsvc.dll - C:\WINDOWS\system32\svchost.exe -k LocalService
S078 Messenger - Messenger - Disabled - Stopped - C:\WINDOWS\System32\msgsvc.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S079 mnmsrvc - NetMeeting Remote Desktop Sharing - Manual - Stopped -  - C:\WINDOWS\system32\mnmsrvc.exe
S080 MSDTC - Distributed Transaction Coordinator - Manual - Stopped -  - C:\WINDOWS\system32\msdtc.exe
S081 MSIServer - Windows Installer - Manual - Stopped -  - C:\WINDOWS\system32\msiexec.exe /V
S082 NetDDE - Network DDE - Disabled - Stopped -  - C:\WINDOWS\system32\netdde.exe
S083 NetDDEdsdm - Network DDE DSDM - Disabled - Stopped -  - C:\WINDOWS\system32\netdde.exe
S084 Netlogon - Net Logon - Manual - Stopped - - - C:\WINDOWS\system32\lsass.exe
S085 Netman - Network Connections - Manual - Running - C:\WINDOWS\System32\netman.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S086 Nla - NLA(Network Location Awareness) - Manual - Running - C:\WINDOWS\System32\mswsock.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S087 NtLmSsp - NT LM Security Support Provider - Manual - Stopped -  - C:\WINDOWS\system32\lsass.exe
S088 NtmsSvc - Removable Storage - Manual - Stopped - C:\WINDOWS\system32\ntmssvc.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S089 PlugPlay - Plug and Play - Auto - Running -  - C:\WINDOWS\system32\services.exe
S090 PolicyAgent - IPSEC Services - Auto - Running -  - C:\WINDOWS\system32\lsass.exe
S091 ProtectedStorage - Protected Storage - Auto - Running -  - C:\WINDOWS\system32\lsass.exe
S092 RasAuto - Remote Access Auto Connection Manager - Manual - Stopped - C:\WINDOWS\System32\rasauto.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S093 RasMan - Remote Access Connection Manager - Manual - Running - C:\WINDOWS\System32\rasmans.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S094 RDSessMgr - Remote Desktop Help Session Manager - Manual - Stopped -  - C:\WINDOWS\system32\sessmgr.exe
S095 RemoteAccess - Routing and Remote Access - Disabled - Stopped - C:\WINDOWS\System32\mprdim.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S096 RemoteRegistry - Remote Registry - Disabled - Stopped - C:\WINDOWS\system32\regsvc.dll - C:\WINDOWS\system32\svchost.exe -k LocalService
S097 rpcapd - Remote Packet Capture Protocol v.0 (experimental) - Manual - Stopped -  - "C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"
S098 RpcLocator - Remote Procedure Call (RPC) Locator - Manual - Stopped - - - C:\WINDOWS\system32\locator.exe
S099 RpcSs - Remote Procedure Call (RPC) - Auto - Running - C:\WINDOWS\system32\rpcss.dll - C:\WINDOWS\system32\svchost -k rpcss
S100 RSVP - QoS RSVP - Manual - Stopped - - - C:\WINDOWS\system32\rsvp.exe
S101 SamSs - Security Accounts Manager - Auto - Running -  - C:\WINDOWS\system32\lsass.exe
S102 SCardSvr - Smart Card - Manual - Stopped -  - C:\WINDOWS\System32\SCardSvr.exe
S103 Schedule - Task Scheduler - Disabled - Stopped - C:\WINDOWS\system32\schedsvc.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S104 seclogon - Secondary Logon - Disabled - Stopped - C:\WINDOWS\System32\seclogon.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S105 SENS - System Event Notification - Auto - Running - C:\WINDOWS\system32\sens.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S106 SharedAccess - Windows Firewall/Internet Connection Sharing (ICS) - Disabled - Stopped - C:\WINDOWS\System32\ipnathlp.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S107 ShellHWDetection - Shell Hardware Detection - Auto - Running - C:\WINDOWS\System32\shsvcs.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S108 Spooler - Print Spooler - Disabled - Stopped - - - C:\WINDOWS\system32\spoolsv.exe
S109 srservice - System Restore Service - Disabled - Stopped - C:\WINDOWS\system32\srsvc.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S110 SSDPSRV - SSDP Discovery Service - Manual - Running - C:\WINDOWS\System32\ssdpsrv.dll - C:\WINDOWS\system32\svchost.exe -k LocalService
S111 stisvc - Windows Image Acquisition (WIA) - Manual - Stopped - C:\WINDOWS\system32\wiaservc.dll - C:\WINDOWS\system32\svchost.exe -k imgsvc
S112 SwPrv - MS Software Shadow Copy Provider - Manual - Stopped -  - C:\WINDOWS\system32\dllhost.exe /Processid:{02D77A17-B7F1-4127-9506-8FC6CB04A83E}
S113 SysmonLog - Performance Logs and Alerts - Manual - Stopped -  - C:\WINDOWS\system32\smlogsvc.exe
S114 TapiSrv - Telephony - Manual - Running - C:\WINDOWS\System32\tapisrv.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S115 TermService - Terminal Services - Manual - Running - C:\WINDOWS\System32\termsrv.dll - C:\WINDOWS\System32\svchost -k DComLaunch
S116 Themes - Themes - Disabled - Stopped - C:\WINDOWS\System32\shsvcs.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S117 TlntSvr - Telnet - Disabled - Stopped -  - C:\WINDOWS\system32\tlntsvr.exe
S118 TPAutoConnSvc - TP AutoConnect Service - Manual - Stopped -  - "C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe"
S119 TrkWks - Distributed Link Tracking Client - Auto - Running - C:\WINDOWS\system32\trkwks.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S120 upnphost - Universal Plug and Play Device Host - Manual - Stopped - C:\WINDOWS\System32\upnphost.dll - C:\WINDOWS\system32\svchost.exe -k LocalService
S121 UPS - Uninterruptible Power Supply - Manual - Stopped -  - C:\WINDOWS\System32\ups.exe
S122 VMTools - VMware Tools Service - Auto - Running -  - "C:\Program Files\VMware\VMware Tools\VMwareService.exe"
S123 VMware Physical Disk Helper Service - VMware Physical Disk Helper Service - Auto - Running -  - "C:\Program Files\VMware\VMware Tools\vmacthlp.exe"
S124 VSS - Volume Shadow Copy - Manual - Stopped -  - C:\WINDOWS\System32\vssvc.exe
S125 W32Time - Windows Time - Disabled - Stopped - C:\WINDOWS\system32\w32time.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S126 WebClient - WebClient - Auto - Running - C:\WINDOWS\System32\webclnt.dll - C:\WINDOWS\system32\svchost.exe -k LocalService
S127 winmgmt - Windows Management Instrumentation - Auto - Running - C:\WINDOWS\system32\wbem\WMIsvc.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S128 WmdmPmSN - Portable Media Serial Number Service - Manual - Stopped - C:\WINDOWS\system32\mspmsnsv.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S129 Wmi - Windows Management Instrumentation Driver Extensions - Manual - Stopped - C:\WINDOWS\System32\advapi32.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S130 WmiApSrv - WMI Performance Adapter - Manual - Stopped -  - C:\WINDOWS\system32\wbem\wmiapsrv.exe
S131 wscsvc - Security Center - Disabled - Stopped - C:\WINDOWS\system32\wscsvc.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S132 wuauserv - Automatic Updates - Disabled - Stopped - C:\WINDOWS\system32\wuauserv.dll - C:\WINDOWS\system32\svchost.exe -k netsvcs
S133 WZCSVC - Wireless Zero Configuration - Disabled - Stopped - C:\WINDOWS\System32\wzcsvc.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
S134 xmlprov - Network Provisioning Service - Manual - Stopped - C:\WINDOWS\System32\xmlprov.dll - C:\WINDOWS\System32\svchost.exe -k netsvcs
----------------------------------------------------------------------
B135 SmartToolCtl Class - C:\Program Files\SmartTool\SmartTool.dll - {2D891923-34B7-4186-9B47-752624535DC1}
B136 goSupport Class - C:\PROGRA~1\CHOLCP~1\CHOLCP~1.DLL - {4C4C5385-431E-4937-91D2-3E1B92EA90D1}
B137 GOUseApp Class - C:\Program Files\CholToolBand\GOUse.dll - {501A66E8-6B4B-4AC5-927F-AD8B999BF4BD}
B138 천리안 쇼핑 도우미 - C:\Program Files\CholReward\CholReward.dll - {622A2D15-D2E1-436A-AD34-1CC95EF4FDA0}
B139 NA - mscoree.dll - {86a3cdaa-9b25-480e-b73f-c2d359b87966}
B140 PostTip - C:\Program Files\PostTip\PostTip.dll - {C4BF6897-41A2-454b-AC3B-437F30BEA671}
----------------------------------------------------------------------
T141 천리안 툴바 - C:\Program Files\CholToolBand\CholToolBand.dll - {927DD7BF-229D-4297-B64A-67C71EF5CFD8}
T142 NA - mscoree.dll - {c9d02d6f-63c7-457a-b200-0a76f2afa675}
----------------------------------------------------------------------
----------------------------------------------------------------------
M143 New Key #1 - "file://c:\myscript.htm"
----------------------------------------------------------------------
Z144 aaa.com - 4
Z145 bbbbbb.com - 2
----------------------------------------------------------------------
X146 {1EEDB738-CF3C-496D-B0B3-80F414659DA8} - SingSingFileLauncher Control - http://www.singsingfile.com/app/SingSingFileLauncher.cab
----------------------------------------------------------------------
C147 AnCamCorder Uninstall | AnCamCorder
C148 Ancamera3.2 Uninstall | AnCamera
C149 cholcpc_search | cholcpc_search.exe
C150 천리안 쇼핑 도우미 | CholReward
C151 천리안 툴바 | CholToolBand
C152 Windows Apps For Fun. | FunApps_is1
C153 Windows Title bar Info Service | FunTop
C154 해피 로또 | happylotto
C155 LinkDirect | linkdirectmain
C156 피씨지키미 | PcGkimi
C157 PC지킴이 | PCLock
C158 PostTip | PostTip
C159 프라이버시그린 | PrivacyGreen
C160 SingSingFile LauncherControl Uninstall | singsingfile
C161 SmartTool 제거 | SmartTool
C162 별PDF | StarPDFMain
C163 별씨 | StarSeeMain
C164 별툴즈 통합업데이트 | startoolsup
C165 별집 | StarZipMain
C166 Windows IEK tmyf Uninstall | tmyf
C167 VaccineScan | VaccineScanMain
C168 웹툰룸 | WebtoonRoom
C169 WindowWizard | windowwizard
C170 wLauncher | wLauncher
C171 유마일 툴바 | {E13382A1-3F76-4BEF-8DB8-775958A008BD}
----------------------------------------------------------------------




요즘 휴대폰 소액결제(월정액 자동결제)를 이용한 사기사이트 및 사기프로그램이 판을 치고 있습니다.
무료백신 프로그램, 무료개인정보삭제 프로그램, 무료 유해사이트차단 프로그램, 무료파일다운, 무료문자, 무료운세, 무료로또, 무료게임, 무료MP3등의 사이트에서 휴대폰 및 일반전화로 절대 인증 하지마세요.

인증하는 즉시 결제되며, 서비스를 해지하지 않는 이상 매월 자동결제됩니다. (인증번호 = 결제번호)
업체마다 결제되는 기간은 다르지만 짧게는 2년, 길게는 20년, 최대 50년짜리도 있습니다.
서비스 업체의 이용약관 및 결제내용에 대해 확실히 알고 인증/사용하시기 바랍니다.
안드로이드계열 스마트폰에서 출처가 없는 설치파일도 다운받지말고 실행하지도 마세요.
해당 통신사에 전화해서 소액결제 안되게끔 차단시키세요. (스마트폰에 무지한 아이들/노인분들 주의)

*악덕업체의 요청으로 인하여 블로그의 게시글이 이유없이 삭제되는 경우 구글 블로그에 재게시 합니다.
[ 2011. 4. 19. 19:37 ] Posted by 프로세스 천국 , 윈도우
,