애드웨어, 허위백신, 팝업광고, 쇼핑몰 바로가기, 악성툴바, 각종 개쓰레기 프로그램 삭제 요청하기
이용약관을 안내하며 컴퓨터에 설치하는 개쓰레기 프로그램들은 백신으로 백날 돌려봐야 검색이 안됩니다.
개쓰레기 프로그램들은 아주 지능적이라서 전문가가 아니고서는 찾아내기가 어렵습니다.


----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Microsoft Windows XP Service Pack 3(5.1.2600.196608)
Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz / 767.48 MB
x86 Family 6 Model 37 Stepping 5
Date : 2011-06-18
----------------------------------------------------------------------
DF000 C:\Hanmacro\fastping_installer.exe
DF001 C:\Hanmacro\gmarket.exe
DF002 C:\Hanmacro\wFastPingSetup.exe
DF003 C:\Program Files\FastPing\FastPing.exe
DF004 C:\Program Files\FastPing\FastPingUpdate.exe
DF005 C:\Program Files\FastPing\uninst.exe
DF006 C:\Program Files\winggo\winggo.dll
DF007 C:\Program Files\winggo\winggou.exe
----------------------------------------------------------------------
UN008 패스트핑 -/- FastPing -/- FastPing -/-
UN009 WingGo -/- - -/- WingGo -/- - -/- -
----------------------------------------------------------------------
US010 FastPing -/- C:\Program Files\FastPing\FastPing.exe boot
US011 FastPingUpdate -/- C:\Program Files\FastPing\FastPingUpdate.exe boot
LS012 WingGo -/- C:\Program Files\winggo\winggou.exe
----------------------------------------------------------------------
BH013 winggo -/- C:\PROGRA~1\winggo\winggo.dll -/- {002B9765-AB24-47E6-8DB6-6A1A0CE11BC9}
----------------------------------------------------------------------
TB015 winggo -/- C:\PROGRA~1\winggo\winggo.dll -/- {003B9765-AB24-47E6-8DB6-6A1A0CE11BC9}
----------------------------------------------------------------------
Deleted Files : 8
Remove Uninstall Entry : 2
Remove Startup Entry : 3
Remove Browser Helper Object : 1
Remove Toolbar : 1
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
[01-HKCUREG]**FastPing
[01-HKCUREG]**FastPingUpdate
[02-HKLMREG]**WingGo
[03-BHOCLSD]**{002B9765-AB24-47E6-8DB6-6A1A0CE11BC9}
[04-TOOLBAR]**{003B9765-AB24-47E6-8DB6-6A1A0CE11BC9}

----------------------------------------------------------------------
Total Processing Time : 81ms
----------------------------------------------------------------------
What's new : BH013 winggo -/- C:\PROGRA~1\winggo\winggo.dll -/- {002B9765-AB24-47E6-8DB6-6A1A0CE11BC9}
----------------------------------------------------------------------




요즘 휴대폰 소액결제(월정액 자동결제)를 이용한 사기사이트 및 사기프로그램이 판을 치고 있습니다.
무료백신 프로그램, 무료개인정보삭제 프로그램, 무료 유해사이트차단 프로그램, 무료파일다운, 무료문자, 무료운세, 무료로또, 무료게임, 무료MP3등의 사이트에서 휴대폰 및 일반전화로 절대 인증 하지마세요.

인증하는 즉시 결제되며, 서비스를 해지하지 않는 이상 매월 자동결제됩니다. (인증번호 = 결제번호)
업체마다 결제되는 기간은 다르지만 짧게는 2년, 길게는 20년, 최대 50년짜리도 있습니다.
서비스 업체의 이용약관 및 결제내용에 대해 확실히 알고 인증/사용하시기 바랍니다.
안드로이드계열 스마트폰에서 출처가 없는 설치파일도 다운받지말고 실행하지도 마세요.
해당 통신사에 전화해서 소액결제 안되게끔 차단시키세요. (스마트폰에 무지한 아이들/노인분들 주의)

*악덕업체의 요청으로 인하여 블로그의 게시글이 이유없이 삭제되는 경우 구글 블로그에 재게시 합니다.
[ 2011.06.18 16:34 ] Posted by windowexe.com , 프로그램분석

댓글을 달아 주세요

  1. windowexe.com - 2012.03.07 21:16 신고 댓글주소 수정/삭제 댓글쓰기

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================

    echo Start
    echo windowexe.com & tskill "vsupsvc" & echo windowdel.com
    echo windowexe.com & tskill "vspack" & echo windowdel.com
    echo windowexe.com & tskill "twocnt" & echo windowdel.com
    echo windowexe.com & tskill "upthesvc" & echo windowdel.com
    echo windowexe.com & tskill "onesup" & echo windowdel.com
    echo windowexe.com & tskill "ebthecnt" & echo windowdel.com
    echo windowexe.com & tskill "WindowWizardT" & echo windowdel.com
    echo windowexe.com & tskill "WindowWizard" & echo windowdel.com
    echo windowexe.com & tskill "WebtoonRoom_Update" & echo windowdel.com
    echo windowexe.com & tskill "WebtoonRoom" & echo windowdel.com
    echo windowexe.com & tskill "starzipup" & echo windowdel.com
    echo windowexe.com & tskill "StarZip" & echo windowdel.com
    echo windowexe.com & tskill "STARUpdate" & echo windowdel.com
    echo windowexe.com & tskill "starseeup" & echo windowdel.com
    echo windowexe.com & tskill "StarSeeLauncher" & echo windowdel.com
    echo windowexe.com & tskill "starseeextchg" & echo windowdel.com
    echo windowexe.com & tskill "StarSee" & echo windowdel.com
    echo windowexe.com & tskill "starpdfup" & echo windowdel.com
    echo windowexe.com & tskill "StarPDF" & echo windowdel.com
    echo windowexe.com & tskill "SmartSecure" & echo windowdel.com
    echo windowexe.com & tskill "SelfPrivacyMon" & echo windowdel.com
    echo windowexe.com & tskill "SelfPrivacy" & echo windowdel.com
    echo windowexe.com & tskill "RCleanT" & echo windowdel.com
    echo windowexe.com & tskill "RClean" & echo windowdel.com
    echo windowexe.com & tskill "updatePlus" & echo windowdel.com
    echo windowexe.com & tskill "PatchUpPlus" & echo windowdel.com
    echo windowexe.com & tskill "UpdateDll" & echo windowdel.com
    echo windowexe.com & tskill "mytbcfg" & echo windowdel.com
    echo windowexe.com & tskill "mytb_svc" & echo windowdel.com
    echo windowexe.com & tskill "mytb_conf" & echo windowdel.com
    echo windowexe.com & tskill "linkdirectT" & echo windowdel.com
    echo windowexe.com & tskill "DBGOLottoT" & echo windowdel.com
    echo windowexe.com & tskill "DBGOLotto" & echo windowdel.com
    echo windowexe.com & tskill "DBGOCodecT" & echo windowdel.com
    echo windowexe.com & tskill "CineRakCouponUpdater" & echo windowdel.com
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Dbgo Mini" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Dbgo Mini" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "PatchUp_Plus" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "PatchUp_Plus" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "wins automgr" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "wins automgr" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "wins promgr" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "wins promgr" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SelfPrivacy" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SelfPrivacy" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "windowwizard" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "windowwizard" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "SmartSecureMain" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SmartSecureMain" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "RCleanMain" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "RCleanMain" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "DBGOCodec" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "DBGOCodec" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "StarSeeMain" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "StarSeeMain" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "StarZipMain" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "StarZipMain" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "StarPDFMain" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "StarPDFMain" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "CineRakCoupon" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "CineRakCoupon" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "wins automgr" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "wins automgr" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "wins promgr" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "wins promgr" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "linkdirectmain" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "linkdirectmain" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "dbgo_MiniDn" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "dbgo_MiniDn" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WebtoonRoom" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WebtoonRoom" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "DBGOLottoT" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "DBGOLottoT" /f
    echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "startoolsup" /f
    echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "startoolsup" /f
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A1078221-6B36-448E-B891-E44F2EBDD1BF}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1078221-6B36-448E-B891-E44F2EBDD1BF}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A1078221-6B36-448E-B891-E44F2EBDD1BF}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{A1078221-6B36-448E-B891-E44F2EBDD1BF}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2153F39F-C29C-41B0-9D5A-D6C165DAA422}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2153F39F-C29C-41B0-9D5A-D6C165DAA422}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2153F39F-C29C-41B0-9D5A-D6C165DAA422}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{2153F39F-C29C-41B0-9D5A-D6C165DAA422}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{16A14962-7C7C-40DA-8F25-7F82C12F0208}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{16A14962-7C7C-40DA-8F25-7F82C12F0208}" /f
    echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{16A14962-7C7C-40DA-8F25-7F82C12F0208}" /f
    echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{16A14962-7C7C-40DA-8F25-7F82C12F0208}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{E2B9134A-BAFF-487b-BEED-D2D5EC2D55FB}" /f
    echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{E2B9134A-BAFF-487b-BEED-D2D5EC2D55FB}" /f
    echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{E2B9134A-BAFF-487b-BEED-D2D5EC2D55FB}" /f
    echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E2B9134A-BAFF-487b-BEED-D2D5EC2D55FB}" /f
    echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2B9134A-BAFF-487b-BEED-D2D5EC2D55FB}" /f
    echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{E2B9134A-BAFF-487b-BEED-D2D5EC2D55FB}" /f
    echo Created by Windowexe.com
    sc stop "MYToolbar"
    echo Service Disable & sc config "MYToolbar" start= disabled & echo Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{00000012-61C1-4d78-9748-81073EFB1E53}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{00000012-61C1-4d78-9748-81073EFB1E53}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{00000012-25AE-487c-8DD7-1CC9CE85512A}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{00000012-25AE-487c-8DD7-1CC9CE85512A}" /f
    echo Created by Windowexe.com
    echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{00000012-2461-47fc-A02F-9EB8678B2A5C}" /f
    echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{00000012-2461-47fc-A02F-9EB8678B2A5C}" /f
    echo Created by Windowexe.com
    echo file Delete & attrib -r "C:\Documents and Settings\Administrator\바탕 화면\옥션에서 싸게 사자.url"
    echo file Delete & del /q "C:\Documents and Settings\Administrator\바탕 화면\옥션에서 싸게 사자.url"
    echo file Delete & attrib -r "C:\Documents and Settings\Administrator\바탕 화면\씨네락 할인쿠폰.url"
    echo file Delete & del /q "C:\Documents and Settings\Administrator\바탕 화면\씨네락 할인쿠폰.url"
    echo file Delete & attrib -r "C:\Documents and Settings\Administrator\바탕 화면\최신휴대폰 즉시개통.lnk"
    echo file Delete & del /q "C:\Documents and Settings\Administrator\바탕 화면\최신휴대폰 즉시개통.lnk"
    echo End

    ======================================================================
    echo Created by Windowexe.com / do not delete this label.
    ======================================================================