애드웨어, 허위백신, 팝업광고, 쇼핑몰 바로가기, 악성툴바, 각종 개쓰레기 프로그램 삭제 요청하기
이용약관을 안내하며 컴퓨터에 설치하는 개쓰레기 프로그램들은 백신으로 백날 돌려봐야 검색이 안됩니다.
개쓰레기 프로그램들은 아주 지능적이라서 전문가가 아니고서는 찾아내기가 어렵습니다.


----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Microsoft Windows XP Service Pack 3(5.1.2600.196608)
Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz / 767.48 MB
x86 Family 6 Model 37 Stepping 5
Date : 2011-06-10
----------------------------------------------------------------------
DF000 C:\Program Files\Downday\7z32.dll
DF001 C:\Program Files\Downday\Ark32.dll
DF002 C:\Program Files\Downday\DowndayDown.exe
DF003 C:\Program Files\Downday\DownDayUp.exe
DF004 C:\Program Files\Downday\enswerapi.dll
DF005 C:\Program Files\Downday\enswerapiworker.dll
DF006 C:\Program Files\Downday\nat.dll
DF007 C:\Program Files\Downday\Uninstall.exe
DF008 C:\Program Files\NAT Service\natsvc.exe
DF009 C:\Program Files\NAT Service\unins000.exe
DF010 C:\Program Files\NAT Service\upsvc.exe
DF011 C:\Program Files\WebCompass\free.exe
DF012 C:\Program Files\WebCompass\sqlite3.dll
DF013 C:\Program Files\WebCompass\unins000.exe
DF014 C:\Program Files\WebCompass\update.exe
DF015 C:\Program Files\WebCompass\wc_src_3f8.dll
DF016 C:\Program Files\WebCompass\wcsv.dll
DF017 C:\WINDOWS\Downloaded Program Files\DowndayWebControlX.dll
DF018 C:\WINDOWS\system32\svc_setup.exe
DF019 C:\WINDOWS\system32\WSLdownday.exe
----------------------------------------------------------------------
SC020 NATService -/- NATService -/- - -/-  -/- C:\Program Files\NAT Service\natsvc.exe
SC021 wcsv -/- WebCompass Updater Service -/- - -/- C:\Program Files\WebCompass\wcsv.dll -/- C:\WINDOWS\system32\svchost.exe -k WebCompass
----------------------------------------------------------------------
UN022 다운데이 -/- 라온퓨처 -/- Downday -/- - -/- -
UN023 WebCompass(웹컴파스) -/- Datawave Inc. -/- WebCompass(웹컴파스)_is1 -/-
UN024 NAT Service 2.3.0.19 -/- - -/- {CA6C4F90-F1C1-4CE9-AF2E-B09CD2939671}_is1 -/- - -/- -
----------------------------------------------------------------------
----------------------------------------------------------------------
BH025 WebCompass Search Class -/- C:\PROGRA~1\WEBCOM~1\WC_SRC~1.DLL -/- {2D3BA117-A67B-4BE3-B692-A0F399E7EBC3}
----------------------------------------------------------------------
X026 {2806CFE2-9742-4B29-89FC-D4182AECFF9D} - DowndayX Web Control -
----------------------------------------------------------------------
Deleted Files : 20
Remove Service : 2
Remove Uninstall Entry : 3
Remove Browser Helper Object : 1
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
[03-BHOCLSD]**{2D3BA117-A67B-4BE3-B692-A0F399E7EBC3}
[05-SERVICE]**NATService
[05-SERVICE]**wcsv
----------------------------------------------------------------------
Total Processing Time : 365ms
----------------------------------------------------------------------




요즘 휴대폰 소액결제(월정액 자동결제)를 이용한 사기사이트 및 사기프로그램이 판을 치고 있습니다.
무료백신 프로그램, 무료개인정보삭제 프로그램, 무료 유해사이트차단 프로그램, 무료파일다운, 무료문자, 무료운세, 무료로또, 무료게임, 무료MP3등의 사이트에서 휴대폰 및 일반전화로 절대 인증 하지마세요.

인증하는 즉시 결제되며, 서비스를 해지하지 않는 이상 매월 자동결제됩니다. (인증번호 = 결제번호)
업체마다 결제되는 기간은 다르지만 짧게는 2년, 길게는 20년, 최대 50년짜리도 있습니다.
서비스 업체의 이용약관 및 결제내용에 대해 확실히 알고 인증/사용하시기 바랍니다.
안드로이드계열 스마트폰에서 출처가 없는 설치파일도 다운받지말고 실행하지도 마세요.
해당 통신사에 전화해서 소액결제 안되게끔 차단시키세요. (스마트폰에 무지한 아이들/노인분들 주의)

*악덕업체의 요청으로 인하여 블로그의 게시글이 이유없이 삭제되는 경우 구글 블로그에 재게시 합니다.
[ 2011.06.11 12:44 ] Posted by windowexe.com , 프로그램분석

댓글을 달아 주세요

  1. windowexe.com - 2012.03.12 17:12 신고 댓글주소 수정/삭제 댓글쓰기

    System Analyzer Report 2012, 03, 12

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================

    echo Start
    echo windowexe.com & tskill "tosghelp" & echo windowdel.com
    echo windowexe.com & tskill "ToolOnUpdateKF" & echo windowdel.com
    echo windowexe.com & tskill "SmartUtil" & echo windowdel.com
    echo windowexe.com & tskill "Playgames_LuncherU" & echo windowdel.com
    echo windowexe.com & tskill "Microsolution_updater" & echo windowdel.com
    echo windowexe.com & tskill "Microsolution_se" & echo windowdel.com
    echo windowexe.com & tskill "Microsolution" & echo windowdel.com
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "toolonupdateKF" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "toolonupdateKF" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "topvaccinestart.exe" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "topvaccinestart.exe" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "topvaccine main" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "topvaccine main" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "processingicc" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "processingicc" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SmartUtil" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SmartUtil" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "PlaygamesUpdater" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "PlaygamesUpdater" /f
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{884EAA16-CA35-4666-845A-DC084DCDF356}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{884EAA16-CA35-4666-845A-DC084DCDF356}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{884EAA16-CA35-4666-845A-DC084DCDF356}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{884EAA16-CA35-4666-845A-DC084DCDF356}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{514FE04D-4442-415c-8AFE-C6B7BFB2DA33}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{514FE04D-4442-415c-8AFE-C6B7BFB2DA33}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{514FE04D-4442-415c-8AFE-C6B7BFB2DA33}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{514FE04D-4442-415c-8AFE-C6B7BFB2DA33}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{397CFDD8-762F-44D4-9517-E3969F89639E}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{397CFDD8-762F-44D4-9517-E3969F89639E}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{397CFDD8-762F-44D4-9517-E3969F89639E}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{397CFDD8-762F-44D4-9517-E3969F89639E}" /f
    echo Created by Windowexe.com
    sc stop "microsolution Update Service"
    echo Service Disable & sc config "microsolution Update Service" start= disabled & echo Windowexe.com
    echo End

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================