방명록을 남겨주세요!

  1. tjstkfh 2015.07.27 20:46  수정/삭제  댓글쓰기

    우연히 들렸다 도음 많이 됬습니다.
    다시 들리겟습니다.

  2. nightsong 2015.06.30 11:25  수정/삭제  댓글쓰기

    http://www.windowexe.com/bbs/board.php?q=nossvc-exe-c-program-files-incainternet-nprotect-online-security-nossvc-exe

    nProtect Online Security(NOS)가 예전버전은 상위 방법으로 서비스중지가 가능했는데..버전업이 된건지 오늘 새로 해보니 중지가 되지 않더군요..
    시간되실때 체크한번 부탁드립니다.

    항상 정보 감사합니다.

    • windowexe.com 2015.06.30 14:24 신고  수정/삭제

      자기방어 형식으로 변경되어 적용이 안되는거 같네요. 프로그램을 아예 삭제해보세요.

    • nightsong 2015.07.01 08:01  수정/삭제

      아무래도 그래야겟죠? 매번 번거롭네요..우리나라 깔리는 보안프로그램은 많은데 그닥 효용성이 느껴지진 않으니 원..
      몇번 신세진거 같은데 매번 감사합니다. 좋은하루 되시길~

  3. 돼지고기 2014.04.11 13:29  수정/삭제  댓글쓰기

    그렇게 했는데 폴더가 지워지지않았네요 안전모드로 들어가서 그런것같은데...... 표준모드로 들어가서 했던걸 다시 보내드릴께요
    ----------------------------------------------------------------------
    Logfile of WindowexeAllkiller / Version : 1.0.5199.35991
    Website : http://windowexeallkiller.com
    Running from C:\Documents and Settings\_USER_NAME_\Local Settings\Temp\_AZTMP3_\Exec
    Operating System : Microsoft Windows XP Professional / Service Pack 3 / 51 / 32bit
    Internet Explorer Version : 8.0.6001.18702 / svcVersion : N.A
    Internet Explorer Homepage : http://www.nate.com/
    Boot mode : Normal
    ----------------------------------------------------------------------

    [00-PROCESS]**explorer -/- C:\WINDOWS\explorer.exe
    [00-PROCESS]**Acrotray -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
    [00-PROCESS]**ALZip -/- C:\Program Files\ESTsoft\ALZip\ALZip.exe
    [00-PROCESS]**AppleMobileDeviceService -/- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    [00-PROCESS]**ASDSvc -/- C:\Program Files\AhnLab\V3IS90\ASDSvc.exe
    [00-PROCESS]**Ati2evxx -/- C:\WINDOWS\system32\ati2evxx.exe
    [00-PROCESS]**ccc -/- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    [00-PROCESS]**conime -/- C:\WINDOWS\system32\conime.exe
    [00-PROCESS]**ctfmon -/- C:\WINDOWS\system32\ctfmon.exe
    [00-PROCESS]**FNPLicensingService -/- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    [00-PROCESS]**iPodService -/- C:\Program Files\iPod\bin\iPodService.exe
    [00-PROCESS]**iTunesHelper -/- C:\Program Files\iTunes\iTunesHelper.exe
    [00-PROCESS]**mDNSResponder -/- C:\Program Files\Bonjour\mDNSResponder.exe
    [00-PROCESS]**MOM -/- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    [00-PROCESS]**NATEONMain -/- C:\program files\sk communications\NATEON\BIN\NATEONMain.exe
    [00-PROCESS]**RTHDCPL -/- C:\WINDOWS\RTHDCPL.EXE
    [00-PROCESS]**SpyHunter4 -/- C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
    [00-PROCESS]**V3UI -/- C:\Program Files\AhnLab\V3IS90\V3UI.exe
    [01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
    [01-HKCUREG]**NATEON -/- c:\program files\sk communications\nateon\bin\nateon.exe -as
    [02-HKLMREG]**Acrobat Assistant 8.0 -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
    [02-HKLMREG]**HncUpdate -/- C:\Program Files\Common Files\Hnc\HncUtils\HncUpdate.exe /A
    [02-HKLMREG]**IMJPMIG8.1 -/- C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
    [02-HKLMREG]**iTunesHelper -/- C:\Program Files\iTunes\iTunesHelper.exe
    [02-HKLMREG]**Korean IME Migration -/- C:\Program Files\Common Files\Microsoft Shared\IME12\IMEKR\IMKRMIG.EXE
    [02-HKLMREG]**PHIME2002A -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    [02-HKLMREG]**PHIME2002ASync -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    [02-HKLMREG]**RTHDCPL -/- RTHDCPL.EXE
    [02-HKLMREG]**StartCCC -/- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun
    [02-HKLMREG]**V3Tray -/- C:\Program Files\AhnLab\V3IS90\V3UI.exe /tray
    [03-BHOCLSD]**{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -/- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    [03-BHOCLSD]**{AE7CD045-E861-484f-8273-0445EE161910} -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    [04-TOOLBAR]**{47833539-D0C5-4125-9FA8-0819E2EAAC93} -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    [04-TOOLBAR]**10 -/- CLSID Nothing
    [05-SERVICE]**AdobeFlashPlayerUpdateSvc -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    [05-SERVICE]**Alerter -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\system32\alrsvc.dll
    [05-SERVICE]**ALG -/- C:\WINDOWS\system32\alg.exe
    [05-SERVICE]**Apple Mobile Device -/- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    [05-SERVICE]**AppMgmt -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\appmgmts.dll
    [05-SERVICE]**aspnet_state -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
    [05-SERVICE]**Ati HotKey Poller -/- C:\WINDOWS\system32\ati2evxx.exe
    [05-SERVICE]**AudioSrv -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\audiosrv.dll
    [05-SERVICE]**Autodesk Licensing Service -/- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    [05-SERVICE]**BITS -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\qmgr.dll
    [05-SERVICE]**Bonjour Service -/- C:\Program Files\Bonjour\mDNSResponder.exe
    [05-SERVICE]**Browser -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\browser.dll
    [05-SERVICE]**CiSvc -/- C:\WINDOWS\system32\cisvc.exe
    [05-SERVICE]**ClipSrv -/- C:\WINDOWS\system32\clipsrv.exe
    [05-SERVICE]**clr_optimization_v2.0.50727_32 -/- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    [05-SERVICE]**clr_optimization_v4.0.30319_32 -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    [05-SERVICE]**COMSysApp -/- C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
    [05-SERVICE]**CryptSvc -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\cryptsvc.dll
    [05-SERVICE]**DcomLaunch -/- C:\WINDOWS\system32\svchost -k DcomLaunch -/- C:\WINDOWS\system32\rpcss.dll
    [05-SERVICE]**Dhcp -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\dhcpcsvc.dll
    [05-SERVICE]**dmadmin -/- C:\WINDOWS\System32\dmadmin.exe /com
    [05-SERVICE]**dmserver -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\dmserver.dll
    [05-SERVICE]**Dnscache -/- C:\WINDOWS\system32\svchost.exe -k NetworkService -/- C:\WINDOWS\System32\dnsrslvr.dll
    [05-SERVICE]**Dot3svc -/- C:\WINDOWS\System32\svchost.exe -k dot3svc -/- C:\WINDOWS\System32\dot3svc.dll
    [05-SERVICE]**EapHost -/- C:\WINDOWS\System32\svchost.exe -k eapsvcs -/- C:\WINDOWS\System32\eapsvc.dll
    [05-SERVICE]**ERSvc -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\ersvc.dll
    [05-SERVICE]**Eventlog -/- C:\WINDOWS\system32\services.exe
    [05-SERVICE]**EventSystem -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\es.dll
    [05-SERVICE]**FastUserSwitchingCompatibility -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\shsvcs.dll
    [05-SERVICE]**FLEXnet Licensing Service -/- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    [05-SERVICE]**FontCache3.0.0.0 -/- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
    [05-SERVICE]**helpsvc -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
    [05-SERVICE]**HidServ -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\hidserv.dll
    [05-SERVICE]**hkmsvc -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\kmsvc.dll
    [05-SERVICE]**HTTPFilter -/- C:\WINDOWS\System32\svchost.exe -k HTTPFilter -/- C:\WINDOWS\System32\w3ssl.dll
    [05-SERVICE]**idsvc -/- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
    [05-SERVICE]**ImapiService -/- C:\WINDOWS\system32\imapi.exe
    [05-SERVICE]**iPod Service -/- C:\Program Files\iPod\bin\iPodService.exe
    [05-SERVICE]**lanmanserver -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\srvsvc.dll
    [05-SERVICE]**lanmanworkstation -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\wkssvc.dll
    [05-SERVICE]**LmHosts -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\System32\lmhsvc.dll
    [05-SERVICE]**Messenger -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\msgsvc.dll
    [05-SERVICE]**mnmsrvc -/- C:\WINDOWS\system32\mnmsrvc.exe
    [05-SERVICE]**MSDTC -/- C:\WINDOWS\system32\msdtc.exe
    [05-SERVICE]**MSIServer -/- C:\WINDOWS\system32\msiexec.exe /V
    [05-SERVICE]**napagent -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\qagentrt.dll
    [05-SERVICE]**Net Driver HPZ12 -/- C:\WINDOWS\System32\svchost.exe -k HPZ12 -/- C:\WINDOWS\system32\HPZinw12.dll
    [05-SERVICE]**NetDDE -/- C:\WINDOWS\system32\netdde.exe
    [05-SERVICE]**NetDDEdsdm -/- C:\WINDOWS\system32\netdde.exe
    [05-SERVICE]**Netlogon -/- C:\WINDOWS\system32\lsass.exe
    [05-SERVICE]**Netman -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\netman.dll
    [05-SERVICE]**NetTcpPortSharing -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
    [05-SERVICE]**Nla -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\mswsock.dll
    [05-SERVICE]**NtLmSsp -/- C:\WINDOWS\system32\lsass.exe
    [05-SERVICE]**NtmsSvc -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\ntmssvc.dll
    [05-SERVICE]**odserv -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
    [05-SERVICE]**ose -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    [05-SERVICE]**PlugPlay -/- C:\WINDOWS\system32\services.exe
    [05-SERVICE]**Pml Driver HPZ12 -/- C:\WINDOWS\System32\svchost.exe -k HPZ12 -/- C:\WINDOWS\system32\HPZipm12.dll
    [05-SERVICE]**PolicyAgent -/- C:\WINDOWS\system32\lsass.exe
    [05-SERVICE]**ProtectedStorage -/- C:\WINDOWS\system32\lsass.exe
    [05-SERVICE]**RasAuto -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\rasauto.dll
    [05-SERVICE]**RasMan -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\rasmans.dll
    [05-SERVICE]**RDSessMgr -/- C:\WINDOWS\system32\sessmgr.exe
    [05-SERVICE]**RemoteAccess -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\mprdim.dll
    [05-SERVICE]**RemoteRegistry -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\system32\regsvc.dll
    [05-SERVICE]**RpcLocator -/- C:\WINDOWS\system32\locator.exe
    [05-SERVICE]**RpcSs -/- C:\WINDOWS\system32\svchost -k rpcss -/- C:\WINDOWS\system32\rpcss.dll
    [05-SERVICE]**RSVP -/- C:\WINDOWS\system32\rsvp.exe
    [05-SERVICE]**SamSs -/- C:\WINDOWS\system32\lsass.exe
    [05-SERVICE]**SCardSvr -/- C:\WINDOWS\system32\scardsvr.exe
    [05-SERVICE]**Schedule -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\schedsvc.dll
    [05-SERVICE]**seclogon -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\seclogon.dll
    [05-SERVICE]**SENS -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\sens.dll
    [05-SERVICE]**SharedAccess -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\ipnathlp.dll
    [05-SERVICE]**ShellHWDetection -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\shsvcs.dll
    [05-SERVICE]**Spooler -/- C:\WINDOWS\system32\spoolsv.exe
    [05-SERVICE]**srservice -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\srsvc.dll
    [05-SERVICE]**SSDPSRV -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\System32\ssdpsrv.dll
    [05-SERVICE]**stisvc -/- C:\WINDOWS\system32\svchost.exe -k imgsvc -/- C:\WINDOWS\system32\wiaservc.dll
    [05-SERVICE]**SwPrv -/- C:\WINDOWS\system32\dllhost.exe /Processid:{69F8E583-4366-45DB-8EDE-33386712E8E2}
    [05-SERVICE]**SysmonLog -/- C:\WINDOWS\system32\smlogsvc.exe
    [05-SERVICE]**TapiSrv -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\tapisrv.dll
    [05-SERVICE]**TermService -/- C:\WINDOWS\System32\svchost -k DComLaunch -/- C:\WINDOWS\System32\termsrv.dll
    [05-SERVICE]**Themes -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\shsvcs.dll
    [05-SERVICE]**TlntSvr -/- C:\WINDOWS\system32\tlntsvr.exe
    [05-SERVICE]**TrkWks -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\trkwks.dll
    [05-SERVICE]**upnphost -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\System32\upnphost.dll
    [05-SERVICE]**UPS -/- C:\WINDOWS\system32\ups.exe
    [05-SERVICE]**V3Svc -/- C:\Program Files\AhnLab\V3IS90\ASDSvc.exe
    [05-SERVICE]**VSS -/- C:\WINDOWS\system32\vssvc.exe
    [05-SERVICE]**W32Time -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\w32time.dll
    [05-SERVICE]**WebClient -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\System32\webclnt.dll
    [05-SERVICE]**winmgmt -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\wbem\WMIsvc.dll
    [05-SERVICE]**WmdmPmSN -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\MsPMSNSv.dll
    [05-SERVICE]**Wmi -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\advapi32.dll
    [05-SERVICE]**WmiApSrv -/- C:\WINDOWS\system32\wbem\wmiapsrv.exe
    [05-SERVICE]**WMPNetworkSvc -/- C:\Program Files\Windows Media Player\wmpnetwk.exe
    [05-SERVICE]**WPFFontCache_v0400 -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
    [05-SERVICE]**wscsvc -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\wscsvc.dll
    [05-SERVICE]**wuauserv -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\wuauserv.dll
    [05-SERVICE]**WudfSvc -/- C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup -/- C:\WINDOWS\System32\WUDFSvc.dll
    [05-SERVICE]**WZCSVC -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\wzcsvc.dll
    [05-SERVICE]**xmlprov -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\xmlprov.dll
    [06-TASKLST]**Adobe Flash Player Updater -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    [06-TASKLST]**AppleSoftwareUpdate -/- C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
    [06-TASKLST]**Microsoft Windows XP 서비스 중단 알림 로그인 -/- C:\WINDOWS\system32\xp_eos.exe -c
    [06-TASKLST]**월별 Microsoft Windows XP 서비스 중단 알림 -/- C:\WINDOWS\system32\xp_eos.exe
    [16-SEARCHS]**{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -/- http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
    [16-SEARCHS]**{13F8A7E6-2EDE-4bf5-BF99-939A6CAAA637} -/- http://gsp.gomtv.com/rd?version=111&sid=0&bypass=1&keyword={searchTerms}
    [16-SEARCHS]**{8AF268BF-A11B-45d1-A67A-65BDEA013148} -/- http://search.nate.com/search/search.asp?SearchField=1&q={searchTerms}&query={searchTerms}
    [16-SEARCHS]**{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} -/- http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=101&systemid=488&v=n11470-311&apn_uid=3241229067544048&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
    [17-CONTEXT]**Adobe PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    [17-CONTEXT]**Microsoft Excel로 내보내기(&X) -/- res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    [17-CONTEXT]**기존 PDF에 추가 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    [17-CONTEXT]**링크 대상을 Adobe PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    [17-CONTEXT]**링크 대상을 기존 PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    [17-CONTEXT]**선택 영역을 Adobe PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    [17-CONTEXT]**선택 영역을 기존 PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    [17-CONTEXT]**선택한 링크를 Adobe PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    [17-CONTEXT]**선택한 링크를 기존 PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    [18-EXTRABT]**{92780B25-18CC-41C8-B9BE-3C9C571A8263} -/- N.A
    [18-EXTRABT]**{e2e2dd38-d088-4134-82b7-f2ba38496583} -/- %windir%\Network Diagnostic\xpnetdiag.exe
    [18-EXTRABT]**{FB5F1910-F110-11d2-BB9E-00C04F795683} -/- C:\Program Files\Messenger\msmsgs.exe
    [18-EXTRABT]**CmdMapping -/- N.A
    [21-SHELLFI]**AcShellExtension.AcContextMenuHandler -/- C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll
    [21-SHELLFI]**Adobe.Acrobat.ContextMenu -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll
    [21-SHELLFI]**ALZip -/- C:\Program Files\ESTsoft\ALZip\AZCTM.dll
    [21-SHELLFI]**DLLRegSvr -/- C:\Program Files\SK Communications\NATEON\BIN\SMailExt.dll
    [22-SHELLDX]**ALZip -/- C:\Program Files\ESTsoft\ALZip\AZCTM.dll
    [29-SHELLDI]**Hwp.Print -/- 한글 문서(Hwp) 인쇄(&P)
    [30-SHELLFX]**Adobe.Acrobat.ContextMenu -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll
    [30-SHELLFX]**ALZip -/- C:\Program Files\ESTsoft\ALZip\AZCTM.dll
    [38-HANDLER]**ms-help -/- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    [38-HANDLER]**s-http -/- C:\Program Files\Initech\SHTTP\InitechSHTTPInterface.11015.dll
    [39-HOMEPAG]**http://www.google.com -/- If LEAVE IT CHECKED, Set your IE homepage
    [40-WNLOGON]**[HKLM.DEFAULT] -/- Shell : Explorer.exe / Userinit : C:\WINDOWS\system32\userinit.exe,
    [41-APPINIT]**[DEFAULT] -/- AppInit_DLLs :
    [42-RMHOSTS]**[DEFAULT] -/- If LEAVE IT CHECKED, Delete the %WINDIR%\system32\drivers\etc\hosts file and create default hosts file.

    ----------------------------------------------------------------------

    • windowexe.com 2014.04.11 13:30 신고  수정/삭제

      폴더는 직접 삭제하세요.

    • 돼지고기 2014.04.11 13:43  수정/삭제

      폴더를 직접 휴지통에 넣거나 삭제를 눌러도 안됩니다.

    • windowexe.com 2014.04.11 21:37 신고  수정/삭제

      이상하네요. 로그에 bitguard 항목은 없는데요.

      37- 이나 41- 에 대부분 위치해 있는데 보이지 않네요.
      네트워크 모드 말고 안전모드로 부팅해서 그냥 삭제해보세요.
      안전모드에서도 삭제가 안되면 폴더나 파일의 권한 문제같은데 확인해보세요.

  4. 돼지고기 2014.04.11 11:50  수정/삭제  댓글쓰기

    컴퓨터에 bitguard란 폴더가 생겼는데 지워지지도 않고 인터넷광고창도 저절로 생겨나고 제어판 프로그램 추가/제거에 Internet Explorer Distribution Of Earnings 란 프로그램은 지워지지도 않네요
    방명록에 windowexeallkiller 제 컴퓨터 상황을 남깁니다.
    죄송합니다만 확인 부탁드립니다.
    ----------------------------------------------------------------------
    Logfile of WindowexeAllkiller / Version : 1.0.5199.35991
    Website : http://windowexeallkiller.com
    Running from C:\Documents and Settings\_USER_NAME_\Local Settings\Temp\_AZTMP2_\Exec
    Operating System : Microsoft Windows XP Professional / Service Pack 3 / 51 / 32bit
    Internet Explorer Version : 8.0.6001.18702 / svcVersion : N.A
    Internet Explorer Homepage : http://www.nate.com/
    Boot mode : Safe.Networking
    ----------------------------------------------------------------------

    [00-PROCESS]**explorer -/- C:\WINDOWS\explorer.exe
    [00-PROCESS]**ALZip -/- C:\Program Files\ESTsoft\ALZip\ALZip.exe
    [00-PROCESS]**iexplore -/- C:\Program Files\Internet Explorer\iexplore.exe
    [01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
    [01-HKCUREG]**iniweblink -/- C:\Documents and Settings\_USER_NAME_\Local Settings\Application Data\weblink\weblinkup.exe
    [01-HKCUREG]**NATEON -/- c:\program files\sk communications\nateon\bin\nateon.exe -as
    [02-HKLMREG]**Acrobat Assistant 8.0 -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
    [02-HKLMREG]**HncUpdate -/- C:\Program Files\Common Files\Hnc\HncUtils\HncUpdate.exe /A
    [02-HKLMREG]**IMJPMIG8.1 -/- C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
    [02-HKLMREG]**iTunesHelper -/- C:\Program Files\iTunes\iTunesHelper.exe
    [02-HKLMREG]**Korean IME Migration -/- C:\Program Files\Common Files\Microsoft Shared\IME12\IMEKR\IMKRMIG.EXE
    [02-HKLMREG]**PHIME2002A -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    [02-HKLMREG]**PHIME2002ASync -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    [02-HKLMREG]**RTHDCPL -/- RTHDCPL.EXE
    [02-HKLMREG]**SpyHunter Security Suite -/- C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
    [02-HKLMREG]**StartCCC -/- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun
    [02-HKLMREG]**V3Tray -/- C:\Program Files\AhnLab\V3IS90\V3UI.exe /tray
    [03-BHOCLSD]**{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -/- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    [03-BHOCLSD]**{375A6AB2-FEEC-445D-B853-2139FB561F80} -/- C:\Program Files\GRETECH\GomHelper\gomsearch.dll
    [03-BHOCLSD]**{AE7CD045-E861-484f-8273-0445EE161910} -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    [04-TOOLBAR]**{47833539-D0C5-4125-9FA8-0819E2EAAC93} -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    [04-TOOLBAR]**10 -/- CLSID Nothing
    [05-SERVICE]**AdobeFlashPlayerUpdateSvc -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    [05-SERVICE]**Alerter -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\system32\alrsvc.dll
    [05-SERVICE]**ALG -/- C:\WINDOWS\system32\alg.exe
    [05-SERVICE]**Apple Mobile Device -/- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    [05-SERVICE]**AppMgmt -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\appmgmts.dll
    [05-SERVICE]**aspnet_state -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
    [05-SERVICE]**Ati HotKey Poller -/- C:\WINDOWS\system32\ati2evxx.exe
    [05-SERVICE]**AudioSrv -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\audiosrv.dll
    [05-SERVICE]**Autodesk Licensing Service -/- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    [05-SERVICE]**BITS -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\qmgr.dll
    [05-SERVICE]**Bonjour Service -/- C:\Program Files\Bonjour\mDNSResponder.exe
    [05-SERVICE]**Browser -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\browser.dll
    [05-SERVICE]**CiSvc -/- C:\WINDOWS\system32\cisvc.exe
    [05-SERVICE]**ClipSrv -/- C:\WINDOWS\system32\clipsrv.exe
    [05-SERVICE]**clr_optimization_v2.0.50727_32 -/- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    [05-SERVICE]**clr_optimization_v4.0.30319_32 -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    [05-SERVICE]**COMSysApp -/- C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
    [05-SERVICE]**CryptSvc -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\cryptsvc.dll
    [05-SERVICE]**DcomLaunch -/- C:\WINDOWS\system32\svchost -k DcomLaunch -/- C:\WINDOWS\system32\rpcss.dll
    [05-SERVICE]**Dhcp -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\dhcpcsvc.dll
    [05-SERVICE]**dmadmin -/- C:\WINDOWS\System32\dmadmin.exe /com
    [05-SERVICE]**dmserver -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\dmserver.dll
    [05-SERVICE]**Dnscache -/- C:\WINDOWS\system32\svchost.exe -k NetworkService -/- C:\WINDOWS\System32\dnsrslvr.dll
    [05-SERVICE]**Dot3svc -/- C:\WINDOWS\System32\svchost.exe -k dot3svc -/- C:\WINDOWS\System32\dot3svc.dll
    [05-SERVICE]**EapHost -/- C:\WINDOWS\System32\svchost.exe -k eapsvcs -/- C:\WINDOWS\System32\eapsvc.dll
    [05-SERVICE]**ERSvc -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\ersvc.dll
    [05-SERVICE]**Eventlog -/- C:\WINDOWS\system32\services.exe
    [05-SERVICE]**EventSystem -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\es.dll
    [05-SERVICE]**FastUserSwitchingCompatibility -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\shsvcs.dll
    [05-SERVICE]**FLEXnet Licensing Service -/- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    [05-SERVICE]**FontCache3.0.0.0 -/- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
    [05-SERVICE]**gcdefv -/- C:\Documents and Settings\_USER_NAME_\Application Data\gcdef\gcdefvc.exe
    [05-SERVICE]**GomService -/- C:\Program Files\GRETECH\GomHelper\gomsearch.exe /service
    [05-SERVICE]**helpsvc -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
    [05-SERVICE]**HidServ -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\hidserv.dll
    [05-SERVICE]**hkmsvc -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\kmsvc.dll
    [05-SERVICE]**HTTPFilter -/- C:\WINDOWS\System32\svchost.exe -k HTTPFilter -/- C:\WINDOWS\System32\w3ssl.dll
    [05-SERVICE]**idsvc -/- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
    [05-SERVICE]**ImapiService -/- C:\WINDOWS\system32\imapi.exe
    [05-SERVICE]**iPod Service -/- C:\Program Files\iPod\bin\iPodService.exe
    [05-SERVICE]**lanmanserver -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\srvsvc.dll
    [05-SERVICE]**lanmanworkstation -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\wkssvc.dll
    [05-SERVICE]**LmHosts -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\System32\lmhsvc.dll
    [05-SERVICE]**Messenger -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\msgsvc.dll
    [05-SERVICE]**mnmsrvc -/- C:\WINDOWS\system32\mnmsrvc.exe
    [05-SERVICE]**MSDTC -/- C:\WINDOWS\system32\msdtc.exe
    [05-SERVICE]**MSIServer -/- C:\WINDOWS\system32\msiexec.exe /V
    [05-SERVICE]**napagent -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\qagentrt.dll
    [05-SERVICE]**Net Driver HPZ12 -/- C:\WINDOWS\System32\svchost.exe -k HPZ12 -/- C:\WINDOWS\system32\HPZinw12.dll
    [05-SERVICE]**NetDDE -/- C:\WINDOWS\system32\netdde.exe
    [05-SERVICE]**NetDDEdsdm -/- C:\WINDOWS\system32\netdde.exe
    [05-SERVICE]**Netlogon -/- C:\WINDOWS\system32\lsass.exe
    [05-SERVICE]**Netman -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\netman.dll
    [05-SERVICE]**NetTcpPortSharing -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
    [05-SERVICE]**Nla -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\mswsock.dll
    [05-SERVICE]**NtLmSsp -/- C:\WINDOWS\system32\lsass.exe
    [05-SERVICE]**NtmsSvc -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\ntmssvc.dll
    [05-SERVICE]**odserv -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
    [05-SERVICE]**ose -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    [05-SERVICE]**PlugPlay -/- C:\WINDOWS\system32\services.exe
    [05-SERVICE]**Pml Driver HPZ12 -/- C:\WINDOWS\System32\svchost.exe -k HPZ12 -/- C:\WINDOWS\system32\HPZipm12.dll
    [05-SERVICE]**PolicyAgent -/- C:\WINDOWS\system32\lsass.exe
    [05-SERVICE]**ProtectedStorage -/- C:\WINDOWS\system32\lsass.exe
    [05-SERVICE]**RasAuto -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\rasauto.dll
    [05-SERVICE]**RasMan -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\rasmans.dll
    [05-SERVICE]**RDSessMgr -/- C:\WINDOWS\system32\sessmgr.exe
    [05-SERVICE]**RemoteAccess -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\mprdim.dll
    [05-SERVICE]**RemoteRegistry -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\system32\regsvc.dll
    [05-SERVICE]**RpcLocator -/- C:\WINDOWS\system32\locator.exe
    [05-SERVICE]**RpcSs -/- C:\WINDOWS\system32\svchost -k rpcss -/- C:\WINDOWS\system32\rpcss.dll
    [05-SERVICE]**RSVP -/- C:\WINDOWS\system32\rsvp.exe
    [05-SERVICE]**SamSs -/- C:\WINDOWS\system32\lsass.exe
    [05-SERVICE]**SCardSvr -/- C:\WINDOWS\system32\scardsvr.exe
    [05-SERVICE]**Schedule -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\schedsvc.dll
    [05-SERVICE]**seclogon -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\seclogon.dll
    [05-SERVICE]**SENS -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\sens.dll
    [05-SERVICE]**SharedAccess -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\ipnathlp.dll
    [05-SERVICE]**ShellHWDetection -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\shsvcs.dll
    [05-SERVICE]**Spooler -/- C:\WINDOWS\system32\spoolsv.exe
    [05-SERVICE]**SpyHunter 4 Service -/- C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
    [05-SERVICE]**srservice -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\srsvc.dll
    [05-SERVICE]**SSDPSRV -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\System32\ssdpsrv.dll
    [05-SERVICE]**stisvc -/- C:\WINDOWS\system32\svchost.exe -k imgsvc -/- C:\WINDOWS\system32\wiaservc.dll
    [05-SERVICE]**SwPrv -/- C:\WINDOWS\system32\dllhost.exe /Processid:{69F8E583-4366-45DB-8EDE-33386712E8E2}
    [05-SERVICE]**SysmonLog -/- C:\WINDOWS\system32\smlogsvc.exe
    [05-SERVICE]**TapiSrv -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\tapisrv.dll
    [05-SERVICE]**TermService -/- C:\WINDOWS\System32\svchost -k DComLaunch -/- C:\WINDOWS\System32\termsrv.dll
    [05-SERVICE]**Themes -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\shsvcs.dll
    [05-SERVICE]**TlntSvr -/- C:\WINDOWS\system32\tlntsvr.exe
    [05-SERVICE]**TrkWks -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\trkwks.dll
    [05-SERVICE]**upnphost -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\System32\upnphost.dll
    [05-SERVICE]**UPS -/- C:\WINDOWS\system32\ups.exe
    [05-SERVICE]**V3Svc -/- C:\Program Files\AhnLab\V3IS90\ASDSvc.exe
    [05-SERVICE]**VSS -/- C:\WINDOWS\system32\vssvc.exe
    [05-SERVICE]**W32Time -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\w32time.dll
    [05-SERVICE]**WebClient -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\System32\webclnt.dll
    [05-SERVICE]**winmgmt -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\wbem\WMIsvc.dll
    [05-SERVICE]**WmdmPmSN -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\MsPMSNSv.dll
    [05-SERVICE]**Wmi -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\advapi32.dll
    [05-SERVICE]**WmiApSrv -/- C:\WINDOWS\system32\wbem\wmiapsrv.exe
    [05-SERVICE]**WMPNetworkSvc -/- C:\Program Files\Windows Media Player\wmpnetwk.exe
    [05-SERVICE]**WPFFontCache_v0400 -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
    [05-SERVICE]**wscsvc -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\wscsvc.dll
    [05-SERVICE]**wuauserv -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\wuauserv.dll
    [05-SERVICE]**WudfSvc -/- C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup -/- C:\WINDOWS\System32\WUDFSvc.dll
    [05-SERVICE]**WZCSVC -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\wzcsvc.dll
    [05-SERVICE]**xmlprov -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\xmlprov.dll
    [06-TASKLST]**Adobe Flash Player Updater -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    [06-TASKLST]**AppleSoftwareUpdate -/- C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
    [06-TASKLST]**Microsoft Windows XP 서비스 중단 알림 로그인 -/- C:\WINDOWS\system32\xp_eos.exe -c
    [06-TASKLST]**월별 Microsoft Windows XP 서비스 중단 알림 -/- C:\WINDOWS\system32\xp_eos.exe
    [16-SEARCHS]**{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -/- http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
    [16-SEARCHS]**{13F8A7E6-2EDE-4bf5-BF99-939A6CAAA637} -/- http://gsp.gomtv.com/rd?version=111&sid=0&bypass=1&keyword={searchTerms}
    [16-SEARCHS]**{8AF268BF-A11B-45d1-A67A-65BDEA013148} -/- http://search.nate.com/search/search.asp?SearchField=1&q={searchTerms}&query={searchTerms}
    [16-SEARCHS]**{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} -/- http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=101&systemid=488&v=n11470-311&apn_uid=3241229067544048&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
    [17-CONTEXT]**Adobe PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    [17-CONTEXT]**Microsoft Excel로 내보내기(&X) -/- res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    [17-CONTEXT]**기존 PDF에 추가 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    [17-CONTEXT]**링크 대상을 Adobe PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    [17-CONTEXT]**링크 대상을 기존 PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    [17-CONTEXT]**선택 영역을 Adobe PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    [17-CONTEXT]**선택 영역을 기존 PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    [17-CONTEXT]**선택한 링크를 Adobe PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    [17-CONTEXT]**선택한 링크를 기존 PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    [18-EXTRABT]**{92780B25-18CC-41C8-B9BE-3C9C571A8263} -/- N.A
    [18-EXTRABT]**{e2e2dd38-d088-4134-82b7-f2ba38496583} -/- %windir%\Network Diagnostic\xpnetdiag.exe
    [18-EXTRABT]**{FB5F1910-F110-11d2-BB9E-00C04F795683} -/- C:\Program Files\Messenger\msmsgs.exe
    [18-EXTRABT]**CmdMapping -/- N.A
    [21-SHELLFI]**AcShellExtension.AcContextMenuHandler -/- C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll
    [21-SHELLFI]**Adobe.Acrobat.ContextMenu -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll
    [21-SHELLFI]**ALZip -/- C:\Program Files\ESTsoft\ALZip\AZCTM.dll
    [21-SHELLFI]**DLLRegSvr -/- C:\Program Files\SK Communications\NATEON\BIN\SMailExt.dll
    [22-SHELLDX]**ALZip -/- C:\Program Files\ESTsoft\ALZip\AZCTM.dll
    [29-SHELLDI]**Hwp.Print -/- 한글 문서(Hwp) 인쇄(&P)
    [30-SHELLFX]**Adobe.Acrobat.ContextMenu -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll
    [30-SHELLFX]**ALZip -/- C:\Program Files\ESTsoft\ALZip\AZCTM.dll
    [37-APPCERT]**x64 -/- c:\program files\browser tab search by ask\safetynut\x64\safetycrt.dll
    [38-HANDLER]**ms-help -/- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    [38-HANDLER]**s-http -/- C:\Program Files\Initech\SHTTP\InitechSHTTPInterface.11015.dll
    [39-HOMEPAG]**http://www.google.com -/- If LEAVE IT CHECKED, Set your IE homepage
    [40-WNLOGON]**[HKLM.DEFAULT] -/- Shell : Explorer.exe / Userinit : C:\WINDOWS\system32\userinit.exe,
    [41-APPINIT]**[DEFAULT] -/- AppInit_DLLs :
    [42-RMHOSTS]**[DEFAULT] -/- If LEAVE IT CHECKED, Delete the %WINDIR%\system32\drivers\etc\hosts file and create default hosts file.

    ----------------------------------------------------------------------

    • windowexe.com 2014.04.11 12:17 신고  수정/삭제

      아래항목 체크
      [00-PROCESS]**explorer
      [00-PROCESS]**ALZip
      [00-PROCESS]**explorer
      [00-PROCESS]**iexplore


      아래항목 체크해제
      [01-HKCUREG]**iniweblink
      [02-HKLMREG]**iniweblink
      [03-BHOCLSD]**{375A6AB2-FEEC-445D-B853-2139FB561F80}
      [05-SERVICE]**gcdefv
      [05-SERVICE]**GomService
      [05-SERVICE]**SpyHunter 4 Service
      [37-APPCERT]**x64


      그 외는 건드리지 말고 상단의 버튼을 누르세요. 목록에 없는 건 무시하고 다음으로 진행하세요.

      재부팅하고 그 폴더 삭제하세요.

    • 돼지고기 2014.04.11 13:28  수정/삭제

      그렇게 했는데 폴더가 지워지지않았네요 안전모드로 들어가서 그런것같은데...... 표준모드로 들어가서 했던걸 다시 보내드릴께요
      ----------------------------------------------------------------------
      Logfile of WindowexeAllkiller / Version : 1.0.5199.35991
      Website : http://windowexeallkiller.com
      Running from C:\Documents and Settings\_USER_NAME_\Local Settings\Temp\_AZTMP3_\Exec
      Operating System : Microsoft Windows XP Professional / Service Pack 3 / 51 / 32bit
      Internet Explorer Version : 8.0.6001.18702 / svcVersion : N.A
      Internet Explorer Homepage : http://www.nate.com/
      Boot mode : Normal
      ----------------------------------------------------------------------

      [00-PROCESS]**explorer -/- C:\WINDOWS\explorer.exe
      [00-PROCESS]**Acrotray -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
      [00-PROCESS]**ALZip -/- C:\Program Files\ESTsoft\ALZip\ALZip.exe
      [00-PROCESS]**AppleMobileDeviceService -/- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      [00-PROCESS]**ASDSvc -/- C:\Program Files\AhnLab\V3IS90\ASDSvc.exe
      [00-PROCESS]**Ati2evxx -/- C:\WINDOWS\system32\ati2evxx.exe
      [00-PROCESS]**ccc -/- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
      [00-PROCESS]**conime -/- C:\WINDOWS\system32\conime.exe
      [00-PROCESS]**ctfmon -/- C:\WINDOWS\system32\ctfmon.exe
      [00-PROCESS]**FNPLicensingService -/- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      [00-PROCESS]**iPodService -/- C:\Program Files\iPod\bin\iPodService.exe
      [00-PROCESS]**iTunesHelper -/- C:\Program Files\iTunes\iTunesHelper.exe
      [00-PROCESS]**mDNSResponder -/- C:\Program Files\Bonjour\mDNSResponder.exe
      [00-PROCESS]**MOM -/- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
      [00-PROCESS]**NATEONMain -/- C:\program files\sk communications\NATEON\BIN\NATEONMain.exe
      [00-PROCESS]**RTHDCPL -/- C:\WINDOWS\RTHDCPL.EXE
      [00-PROCESS]**SpyHunter4 -/- C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
      [00-PROCESS]**V3UI -/- C:\Program Files\AhnLab\V3IS90\V3UI.exe
      [01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
      [01-HKCUREG]**NATEON -/- c:\program files\sk communications\nateon\bin\nateon.exe -as
      [02-HKLMREG]**Acrobat Assistant 8.0 -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
      [02-HKLMREG]**HncUpdate -/- C:\Program Files\Common Files\Hnc\HncUtils\HncUpdate.exe /A
      [02-HKLMREG]**IMJPMIG8.1 -/- C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
      [02-HKLMREG]**iTunesHelper -/- C:\Program Files\iTunes\iTunesHelper.exe
      [02-HKLMREG]**Korean IME Migration -/- C:\Program Files\Common Files\Microsoft Shared\IME12\IMEKR\IMKRMIG.EXE
      [02-HKLMREG]**PHIME2002A -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      [02-HKLMREG]**PHIME2002ASync -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      [02-HKLMREG]**RTHDCPL -/- RTHDCPL.EXE
      [02-HKLMREG]**StartCCC -/- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun
      [02-HKLMREG]**V3Tray -/- C:\Program Files\AhnLab\V3IS90\V3UI.exe /tray
      [03-BHOCLSD]**{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -/- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      [03-BHOCLSD]**{AE7CD045-E861-484f-8273-0445EE161910} -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
      [04-TOOLBAR]**{47833539-D0C5-4125-9FA8-0819E2EAAC93} -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
      [04-TOOLBAR]**10 -/- CLSID Nothing
      [05-SERVICE]**AdobeFlashPlayerUpdateSvc -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
      [05-SERVICE]**Alerter -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\system32\alrsvc.dll
      [05-SERVICE]**ALG -/- C:\WINDOWS\system32\alg.exe
      [05-SERVICE]**Apple Mobile Device -/- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      [05-SERVICE]**AppMgmt -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\appmgmts.dll
      [05-SERVICE]**aspnet_state -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
      [05-SERVICE]**Ati HotKey Poller -/- C:\WINDOWS\system32\ati2evxx.exe
      [05-SERVICE]**AudioSrv -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\audiosrv.dll
      [05-SERVICE]**Autodesk Licensing Service -/- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
      [05-SERVICE]**BITS -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\qmgr.dll
      [05-SERVICE]**Bonjour Service -/- C:\Program Files\Bonjour\mDNSResponder.exe
      [05-SERVICE]**Browser -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\browser.dll
      [05-SERVICE]**CiSvc -/- C:\WINDOWS\system32\cisvc.exe
      [05-SERVICE]**ClipSrv -/- C:\WINDOWS\system32\clipsrv.exe
      [05-SERVICE]**clr_optimization_v2.0.50727_32 -/- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
      [05-SERVICE]**clr_optimization_v4.0.30319_32 -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
      [05-SERVICE]**COMSysApp -/- C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
      [05-SERVICE]**CryptSvc -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\cryptsvc.dll
      [05-SERVICE]**DcomLaunch -/- C:\WINDOWS\system32\svchost -k DcomLaunch -/- C:\WINDOWS\system32\rpcss.dll
      [05-SERVICE]**Dhcp -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\dhcpcsvc.dll
      [05-SERVICE]**dmadmin -/- C:\WINDOWS\System32\dmadmin.exe /com
      [05-SERVICE]**dmserver -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\dmserver.dll
      [05-SERVICE]**Dnscache -/- C:\WINDOWS\system32\svchost.exe -k NetworkService -/- C:\WINDOWS\System32\dnsrslvr.dll
      [05-SERVICE]**Dot3svc -/- C:\WINDOWS\System32\svchost.exe -k dot3svc -/- C:\WINDOWS\System32\dot3svc.dll
      [05-SERVICE]**EapHost -/- C:\WINDOWS\System32\svchost.exe -k eapsvcs -/- C:\WINDOWS\System32\eapsvc.dll
      [05-SERVICE]**ERSvc -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\ersvc.dll
      [05-SERVICE]**Eventlog -/- C:\WINDOWS\system32\services.exe
      [05-SERVICE]**EventSystem -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\es.dll
      [05-SERVICE]**FastUserSwitchingCompatibility -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\shsvcs.dll
      [05-SERVICE]**FLEXnet Licensing Service -/- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      [05-SERVICE]**FontCache3.0.0.0 -/- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
      [05-SERVICE]**helpsvc -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
      [05-SERVICE]**HidServ -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\hidserv.dll
      [05-SERVICE]**hkmsvc -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\kmsvc.dll
      [05-SERVICE]**HTTPFilter -/- C:\WINDOWS\System32\svchost.exe -k HTTPFilter -/- C:\WINDOWS\System32\w3ssl.dll
      [05-SERVICE]**idsvc -/- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
      [05-SERVICE]**ImapiService -/- C:\WINDOWS\system32\imapi.exe
      [05-SERVICE]**iPod Service -/- C:\Program Files\iPod\bin\iPodService.exe
      [05-SERVICE]**lanmanserver -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\srvsvc.dll
      [05-SERVICE]**lanmanworkstation -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\wkssvc.dll
      [05-SERVICE]**LmHosts -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\System32\lmhsvc.dll
      [05-SERVICE]**Messenger -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\msgsvc.dll
      [05-SERVICE]**mnmsrvc -/- C:\WINDOWS\system32\mnmsrvc.exe
      [05-SERVICE]**MSDTC -/- C:\WINDOWS\system32\msdtc.exe
      [05-SERVICE]**MSIServer -/- C:\WINDOWS\system32\msiexec.exe /V
      [05-SERVICE]**napagent -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\qagentrt.dll
      [05-SERVICE]**Net Driver HPZ12 -/- C:\WINDOWS\System32\svchost.exe -k HPZ12 -/- C:\WINDOWS\system32\HPZinw12.dll
      [05-SERVICE]**NetDDE -/- C:\WINDOWS\system32\netdde.exe
      [05-SERVICE]**NetDDEdsdm -/- C:\WINDOWS\system32\netdde.exe
      [05-SERVICE]**Netlogon -/- C:\WINDOWS\system32\lsass.exe
      [05-SERVICE]**Netman -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\netman.dll
      [05-SERVICE]**NetTcpPortSharing -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
      [05-SERVICE]**Nla -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\mswsock.dll
      [05-SERVICE]**NtLmSsp -/- C:\WINDOWS\system32\lsass.exe
      [05-SERVICE]**NtmsSvc -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\ntmssvc.dll
      [05-SERVICE]**odserv -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
      [05-SERVICE]**ose -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
      [05-SERVICE]**PlugPlay -/- C:\WINDOWS\system32\services.exe
      [05-SERVICE]**Pml Driver HPZ12 -/- C:\WINDOWS\System32\svchost.exe -k HPZ12 -/- C:\WINDOWS\system32\HPZipm12.dll
      [05-SERVICE]**PolicyAgent -/- C:\WINDOWS\system32\lsass.exe
      [05-SERVICE]**ProtectedStorage -/- C:\WINDOWS\system32\lsass.exe
      [05-SERVICE]**RasAuto -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\rasauto.dll
      [05-SERVICE]**RasMan -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\rasmans.dll
      [05-SERVICE]**RDSessMgr -/- C:\WINDOWS\system32\sessmgr.exe
      [05-SERVICE]**RemoteAccess -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\mprdim.dll
      [05-SERVICE]**RemoteRegistry -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\system32\regsvc.dll
      [05-SERVICE]**RpcLocator -/- C:\WINDOWS\system32\locator.exe
      [05-SERVICE]**RpcSs -/- C:\WINDOWS\system32\svchost -k rpcss -/- C:\WINDOWS\system32\rpcss.dll
      [05-SERVICE]**RSVP -/- C:\WINDOWS\system32\rsvp.exe
      [05-SERVICE]**SamSs -/- C:\WINDOWS\system32\lsass.exe
      [05-SERVICE]**SCardSvr -/- C:\WINDOWS\system32\scardsvr.exe
      [05-SERVICE]**Schedule -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\schedsvc.dll
      [05-SERVICE]**seclogon -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\seclogon.dll
      [05-SERVICE]**SENS -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\sens.dll
      [05-SERVICE]**SharedAccess -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\ipnathlp.dll
      [05-SERVICE]**ShellHWDetection -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\shsvcs.dll
      [05-SERVICE]**Spooler -/- C:\WINDOWS\system32\spoolsv.exe
      [05-SERVICE]**srservice -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\srsvc.dll
      [05-SERVICE]**SSDPSRV -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\System32\ssdpsrv.dll
      [05-SERVICE]**stisvc -/- C:\WINDOWS\system32\svchost.exe -k imgsvc -/- C:\WINDOWS\system32\wiaservc.dll
      [05-SERVICE]**SwPrv -/- C:\WINDOWS\system32\dllhost.exe /Processid:{69F8E583-4366-45DB-8EDE-33386712E8E2}
      [05-SERVICE]**SysmonLog -/- C:\WINDOWS\system32\smlogsvc.exe
      [05-SERVICE]**TapiSrv -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\tapisrv.dll
      [05-SERVICE]**TermService -/- C:\WINDOWS\System32\svchost -k DComLaunch -/- C:\WINDOWS\System32\termsrv.dll
      [05-SERVICE]**Themes -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\shsvcs.dll
      [05-SERVICE]**TlntSvr -/- C:\WINDOWS\system32\tlntsvr.exe
      [05-SERVICE]**TrkWks -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\trkwks.dll
      [05-SERVICE]**upnphost -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\System32\upnphost.dll
      [05-SERVICE]**UPS -/- C:\WINDOWS\system32\ups.exe
      [05-SERVICE]**V3Svc -/- C:\Program Files\AhnLab\V3IS90\ASDSvc.exe
      [05-SERVICE]**VSS -/- C:\WINDOWS\system32\vssvc.exe
      [05-SERVICE]**W32Time -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\w32time.dll
      [05-SERVICE]**WebClient -/- C:\WINDOWS\system32\svchost.exe -k LocalService -/- C:\WINDOWS\System32\webclnt.dll
      [05-SERVICE]**winmgmt -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\wbem\WMIsvc.dll
      [05-SERVICE]**WmdmPmSN -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\MsPMSNSv.dll
      [05-SERVICE]**Wmi -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\advapi32.dll
      [05-SERVICE]**WmiApSrv -/- C:\WINDOWS\system32\wbem\wmiapsrv.exe
      [05-SERVICE]**WMPNetworkSvc -/- C:\Program Files\Windows Media Player\wmpnetwk.exe
      [05-SERVICE]**WPFFontCache_v0400 -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
      [05-SERVICE]**wscsvc -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\wscsvc.dll
      [05-SERVICE]**wuauserv -/- C:\WINDOWS\system32\svchost.exe -k netsvcs -/- C:\WINDOWS\system32\wuauserv.dll
      [05-SERVICE]**WudfSvc -/- C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup -/- C:\WINDOWS\System32\WUDFSvc.dll
      [05-SERVICE]**WZCSVC -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\wzcsvc.dll
      [05-SERVICE]**xmlprov -/- C:\WINDOWS\System32\svchost.exe -k netsvcs -/- C:\WINDOWS\System32\xmlprov.dll
      [06-TASKLST]**Adobe Flash Player Updater -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
      [06-TASKLST]**AppleSoftwareUpdate -/- C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
      [06-TASKLST]**Microsoft Windows XP 서비스 중단 알림 로그인 -/- C:\WINDOWS\system32\xp_eos.exe -c
      [06-TASKLST]**월별 Microsoft Windows XP 서비스 중단 알림 -/- C:\WINDOWS\system32\xp_eos.exe
      [16-SEARCHS]**{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -/- http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
      [16-SEARCHS]**{13F8A7E6-2EDE-4bf5-BF99-939A6CAAA637} -/- http://gsp.gomtv.com/rd?version=111&sid=0&bypass=1&keyword={searchTerms}
      [16-SEARCHS]**{8AF268BF-A11B-45d1-A67A-65BDEA013148} -/- http://search.nate.com/search/search.asp?SearchField=1&q={searchTerms}&query={searchTerms}
      [16-SEARCHS]**{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} -/- http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=101&systemid=488&v=n11470-311&apn_uid=3241229067544048&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
      [17-CONTEXT]**Adobe PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      [17-CONTEXT]**Microsoft Excel로 내보내기(&X) -/- res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      [17-CONTEXT]**기존 PDF에 추가 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      [17-CONTEXT]**링크 대상을 Adobe PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      [17-CONTEXT]**링크 대상을 기존 PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      [17-CONTEXT]**선택 영역을 Adobe PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      [17-CONTEXT]**선택 영역을 기존 PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      [17-CONTEXT]**선택한 링크를 Adobe PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      [17-CONTEXT]**선택한 링크를 기존 PDF로 변환 -/- res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      [18-EXTRABT]**{92780B25-18CC-41C8-B9BE-3C9C571A8263} -/- N.A
      [18-EXTRABT]**{e2e2dd38-d088-4134-82b7-f2ba38496583} -/- %windir%\Network Diagnostic\xpnetdiag.exe
      [18-EXTRABT]**{FB5F1910-F110-11d2-BB9E-00C04F795683} -/- C:\Program Files\Messenger\msmsgs.exe
      [18-EXTRABT]**CmdMapping -/- N.A
      [21-SHELLFI]**AcShellExtension.AcContextMenuHandler -/- C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll
      [21-SHELLFI]**Adobe.Acrobat.ContextMenu -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll
      [21-SHELLFI]**ALZip -/- C:\Program Files\ESTsoft\ALZip\AZCTM.dll
      [21-SHELLFI]**DLLRegSvr -/- C:\Program Files\SK Communications\NATEON\BIN\SMailExt.dll
      [22-SHELLDX]**ALZip -/- C:\Program Files\ESTsoft\ALZip\AZCTM.dll
      [29-SHELLDI]**Hwp.Print -/- 한글 문서(Hwp) 인쇄(&P)
      [30-SHELLFX]**Adobe.Acrobat.ContextMenu -/- C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll
      [30-SHELLFX]**ALZip -/- C:\Program Files\ESTsoft\ALZip\AZCTM.dll
      [38-HANDLER]**ms-help -/- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
      [38-HANDLER]**s-http -/- C:\Program Files\Initech\SHTTP\InitechSHTTPInterface.11015.dll
      [39-HOMEPAG]**http://www.google.com -/- If LEAVE IT CHECKED, Set your IE homepage
      [40-WNLOGON]**[HKLM.DEFAULT] -/- Shell : Explorer.exe / Userinit : C:\WINDOWS\system32\userinit.exe,
      [41-APPINIT]**[DEFAULT] -/- AppInit_DLLs :
      [42-RMHOSTS]**[DEFAULT] -/- If LEAVE IT CHECKED, Delete the %WINDIR%\system32\drivers\etc\hosts file and create default hosts file.

      ----------------------------------------------------------------------

  5. 슬픈운명 2014.04.09 16:56  수정/삭제  댓글쓰기

    관리자님 안녕하세요?
    오래전부터 즐겨찾기 해놓고 오랜만에 방문합니다
    컴퓨터 관리에 대한 좋은 정보 항상 잘보고 갑니다

    다름이 아니라 제가 이번에 컴퓨터 관리방법에 대한 글로
    컴퓨터 관리방법과 최적화등 여러 초보분들에게 도움이 되고자 글을 만들고 있습니다
    그러던중 최적화 부분중에 '그리드 딜리버리'에 관한 설명과 프로그램을 제거하려는
    글을 쓰고 있는데 여기서 관리자님이 제작하신 Windowexe_Grid_delete.bat의 프로그램을 사람들에게 소개하고 다운로드를 제공해도 될지 여쭈어 보고자 글 남깁니다
    허락해주신다면 글을 작성할 계획이구요. 출처는 당연히 기본적으로 반드시 남겨드립니다. 원하시는 내용이나 그런부분도 넣어드릴 수 있습니다.
    불펌은 당연히 금지시킬거구요
    저는 기업도 아니구요 단지 컴퓨터 카페에서 컴퓨터 초보분들에게 도움을 주기위해
    글을 작성하는 하나의 회원일 뿐입니다
    절대 상업적으로 이용하지도 않고요
    요새 컴퓨터A/S로 사기를 치고다니는 회사도 있고, 돈주고 컴퓨터를 고치는것보다
    자기가 직접 컴퓨터를 관리하고 배우자는 그런 취지에서 제작하는 것입니다
    관리자님이 허락해주신다면 많은분들에게 도움이 되실거라 생각합니다
    답변 부탁드립니다. 감사합니다

  6. ... 2014.03.24 17:22  수정/삭제  댓글쓰기

    Boot mode : Normal
    ----------------------------------------------------------------------

    [00-PROCESS]**explorer -/- C:\WINDOWS.0\explorer.exe
    [00-PROCESS]**ctfmon -/- C:\WINDOWS.0\system32\ctfmon.exe
    [00-PROCESS]**dbisqlg -/- C:\Program Files\Sybase\SQL Anywhere 9\win32\dbisqlg.exe
    [00-PROCESS]**dbsrv8 -/- C:\Program Files\Sybase\SQL Anywhere 8\win32\dbsrv8.exe
    [00-PROCESS]**inetinfo -/- C:\WINDOWS.0\system32\inetsrv\inetinfo.exe
    [00-PROCESS]**msfeedssync -/- C:\WINDOWS.0\system32\msfeedssync.exe
    [00-PROCESS]**rdpclip -/- C:\WINDOWS.0\system32\rdpclip.exe
    [00-PROCESS]**scjview -/- C:\Program Files\Sybase\Shared9\Sybase Central 4.3\win32\scjview.exe
    [00-PROCESS]**w3wp -/- c:\WINDOWS.0\system32\inetsrv\w3wp.exe
    [00-PROCESS]**winvnc -/- C:\Program Files\UltraVNC\winvnc.exe
    [01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS.0\system32\ctfmon.exe
    [01-HKCUREG]**DBISQL9 -/- C:\Program Files\Sybase\SQL Anywhere 9\win32\dbisqlg.exe -preload
    [01-HKCUREG]**SybaseCentral43 -/- C:\Program Files\Sybase\Shared9\Sybase Central 4.3\win32\scjview.exe -preload
    [02-HKLMREG]**IMEKRMIG6.1 -/- C:\WINDOWS.0\ime\IMKR6_1\imekrmig.exe
    [02-HKLMREG]**IMJPMIG8.1 -/- C:\WINDOWS.0\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
    [02-HKLMREG]**PHIME2002A -/- C:\WINDOWS.0\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    [02-HKLMREG]**PHIME2002ASync -/- C:\WINDOWS.0\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    [02-HKLMREG]**WinVNC -/- C:\Program Files\UltraVNC\winvnc.exe -servicehelper
    [05-SERVICE]**AeLookupSvc -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\aelupsvc.dll
    [05-SERVICE]**Alerter -/- C:\WINDOWS.0\system32\svchost.exe -k LocalService -/- C:\WINDOWS.0\system32\alrsvc.dll
    [05-SERVICE]**ALG -/- C:\WINDOWS.0\system32\alg.exe
    [05-SERVICE]**AppMgmt -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\appmgmts.dll
    [05-SERVICE]**aspnet_state -/- C:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
    [05-SERVICE]**AudioSrv -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\audiosrv.dll
    [05-SERVICE]**BITS -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\system32\qmgr.dll
    [05-SERVICE]**Browser -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\browser.dll
    [05-SERVICE]**CiSvc -/- C:\WINDOWS.0\system32\cisvc.exe
    [05-SERVICE]**ClipSrv -/- C:\WINDOWS.0\system32\clipsrv.exe
    [05-SERVICE]**clr_optimization_v2.0.50727_32 -/- C:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    [05-SERVICE]**COMSysApp -/- C:\WINDOWS.0\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
    [05-SERVICE]**CryptSvc -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\cryptsvc.dll
    [05-SERVICE]**DcomLaunch -/- C:\WINDOWS.0\system32\svchost.exe -k DcomLaunch -/- C:\WINDOWS.0\system32\rpcss.dll
    [05-SERVICE]**Dfs -/- C:\WINDOWS.0\system32\dfssvc.exe
    [05-SERVICE]**Dhcp -/- C:\WINDOWS.0\system32\svchost.exe -k NetworkService -/- C:\WINDOWS.0\System32\dhcpcsvc.dll
    [05-SERVICE]**dmadmin -/- C:\WINDOWS.0\System32\dmadmin.exe /com
    [05-SERVICE]**dmserver -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\dmserver.dll
    [05-SERVICE]**Dnscache -/- C:\WINDOWS.0\system32\svchost.exe -k NetworkService -/- C:\WINDOWS.0\System32\dnsrslvr.dll
    [05-SERVICE]**ERSvc -/- C:\WINDOWS.0\System32\svchost.exe -k WinErr -/- C:\WINDOWS.0\System32\ersvc.dll
    [05-SERVICE]**Eventlog -/- C:\WINDOWS.0\system32\services.exe
    [05-SERVICE]**EventSystem -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\system32\es.dll
    [05-SERVICE]**FontCache3.0.0.0 -/- C:\WINDOWS.0\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
    [05-SERVICE]**helpsvc -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\PCHealth\HelpCtr\Binaries\pchsvc.dll
    [05-SERVICE]**HidServ -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\hidserv.dll
    [05-SERVICE]**HTTPFilter -/- C:\WINDOWS.0\system32\lsass.exe -/- C:\WINDOWS.0\System32\w3ssl.dll
    [05-SERVICE]**idsvc -/- C:\WINDOWS.0\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
    [05-SERVICE]**IISADMIN -/- C:\WINDOWS.0\system32\inetsrv\inetinfo.exe
    [05-SERVICE]**ImapiService -/- C:\WINDOWS.0\system32\imapi.exe
    [05-SERVICE]**IsmServ -/- C:\WINDOWS.0\system32\ismserv.exe
    [05-SERVICE]**kdc -/- C:\WINDOWS.0\system32\lsass.exe
    [05-SERVICE]**lanmanserver -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\srvsvc.dll
    [05-SERVICE]**lanmanworkstation -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\wkssvc.dll
    [05-SERVICE]**LicenseService -/- C:\WINDOWS.0\system32\llssrv.exe
    [05-SERVICE]**LmHosts -/- C:\WINDOWS.0\system32\svchost.exe -k LocalService -/- C:\WINDOWS.0\System32\lmhsvc.dll
    [05-SERVICE]**Messenger -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\msgsvc.dll
    [05-SERVICE]**mnmsrvc -/- C:\WINDOWS.0\system32\mnmsrvc.exe
    [05-SERVICE]**MSDTC -/- C:\WINDOWS.0\system32\msdtc.exe
    [05-SERVICE]**MSFtpsvc -/- C:\WINDOWS.0\system32\inetsrv\inetinfo.exe
    [05-SERVICE]**MSIServer -/- C:\WINDOWS.0\system32\msiexec.exe /V
    [05-SERVICE]**Netlogon -/- C:\WINDOWS.0\system32\lsass.exe
    [05-SERVICE]**Netman -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\netman.dll
    [05-SERVICE]**NetTcpPortSharing -/- C:\WINDOWS.0\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
    [05-SERVICE]**Nla -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\mswsock.dll
    [05-SERVICE]**NtFrs -/- C:\WINDOWS.0\system32\ntfrs.exe
    [05-SERVICE]**NtLmSsp -/- C:\WINDOWS.0\system32\lsass.exe
    [05-SERVICE]**NtmsSvc -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\system32\ntmssvc.dll
    [05-SERVICE]**PlugPlay -/- C:\WINDOWS.0\system32\services.exe
    [05-SERVICE]**PolicyAgent -/- C:\WINDOWS.0\system32\lsass.exe
    [05-SERVICE]**RasAuto -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\rasauto.dll
    [05-SERVICE]**RasMan -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\rasmans.dll
    [05-SERVICE]**RDSessMgr -/- C:\WINDOWS.0\system32\sessmgr.exe
    [05-SERVICE]**RemoteRegistry -/- C:\WINDOWS.0\system32\svchost.exe -k regsvc -/- C:\WINDOWS.0\system32\regsvc.dll
    [05-SERVICE]**RpcLocator -/- C:\WINDOWS.0\system32\locator.exe
    [05-SERVICE]**RpcSs -/- C:\WINDOWS.0\system32\svchost.exe -k rpcss -/- C:\WINDOWS.0\system32\rpcss.dll
    [05-SERVICE]**RSoPProv -/- C:\WINDOWS.0\system32\rsopprov.exe
    [05-SERVICE]**sacsvr -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\system32\sacsvr.dll
    [05-SERVICE]**SamSs -/- C:\WINDOWS.0\system32\lsass.exe
    [05-SERVICE]**SCardSvr -/- C:\WINDOWS.0\system32\scardsvr.exe
    [05-SERVICE]**Schedule -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\system32\schedsvc.dll
    [05-SERVICE]**seclogon -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\seclogon.dll
    [05-SERVICE]**SENS -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\system32\sens.dll
    [05-SERVICE]**SharedAccess -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\system32\ipnathlp.dll
    [05-SERVICE]**ShellHWDetection -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\shsvcs.dll
    [05-SERVICE]**Spooler -/- C:\WINDOWS.0\system32\spoolsv.exe
    [05-SERVICE]**stisvc -/- C:\WINDOWS.0\system32\svchost.exe -k imgsvc -/- C:\WINDOWS.0\system32\wiaservc.dll
    [05-SERVICE]**swprv -/- C:\WINDOWS.0\System32\svchost.exe -k swprv -/- C:\WINDOWS.0\System32\swprv.dll
    [05-SERVICE]**SysmonLog -/- C:\WINDOWS.0\system32\smlogsvc.exe
    [05-SERVICE]**TapiSrv -/- C:\WINDOWS.0\System32\svchost.exe -k tapisrv -/- C:\WINDOWS.0\System32\tapisrv.dll
    [05-SERVICE]**TermService -/- C:\WINDOWS.0\System32\svchost.exe -k termsvcs -/- C:\WINDOWS.0\System32\termsrv.dll
    [05-SERVICE]**Themes -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\shsvcs.dll
    [05-SERVICE]**TrkSvr -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\system32\trksvr.dll
    [05-SERVICE]**TrkWks -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\system32\trkwks.dll
    [05-SERVICE]**Tssdis -/- C:\WINDOWS.0\system32\tssdis.exe
    [05-SERVICE]**UMWdf -/- C:\WINDOWS.0\system32\wdfmgr.exe
    [05-SERVICE]**UPS -/- C:\WINDOWS.0\system32\ups.exe
    [05-SERVICE]**vds -/- C:\WINDOWS.0\system32\vds.exe
    [05-SERVICE]**VSS -/- C:\WINDOWS.0\system32\vssvc.exe
    [05-SERVICE]**W32Time -/- C:\WINDOWS.0\system32\svchost.exe -k LocalService -/- C:\WINDOWS.0\system32\w32time.dll
    [05-SERVICE]**W3SVC -/- C:\WINDOWS.0\System32\svchost.exe -k iissvcs -/- C:\WINDOWS.0\system32\inetsrv\iisw3adm.dll
    [05-SERVICE]**WebClient -/- C:\WINDOWS.0\system32\svchost.exe -k LocalService -/- C:\WINDOWS.0\System32\webclnt.dll
    [05-SERVICE]**WinHttpAutoProxySvc -/- C:\WINDOWS.0\system32\svchost.exe -k LocalService -/- winhttp.dll
    [05-SERVICE]**winmgmt -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\system32\wbem\WMIsvc.dll
    [05-SERVICE]**winvnc -/- C:\Program Files\UltraVNC\winvnc.exe -service
    [05-SERVICE]**WmdmPmSN -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\system32\mspmsnsv.dll
    [05-SERVICE]**Wmi -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\advapi32.dll
    [05-SERVICE]**WmiApSrv -/- C:\WINDOWS.0\system32\wbem\wmiapsrv.exe
    [05-SERVICE]**wuauserv -/- C:\WINDOWS.0\system32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\system32\wuauserv.dll
    [05-SERVICE]**WZCSVC -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\wzcsvc.dll
    [05-SERVICE]**xmlprov -/- C:\WINDOWS.0\System32\svchost.exe -k netsvcs -/- C:\WINDOWS.0\System32\xmlprov.dll
    [06-TASKLST]**User_Feed_Synchronization-{54DAC94E-DB76-4097-B7AC-17C664DE744B} -/- 2014-03-24 417 분 동안 오후 5:03부터 매 5 분
    [06-TASKLST]**User_Feed_Synchronization-{54DAC94E-DB76-4097-B7AC-17C664DE744B} -/- 2014-03-25부터 매일 24 시간 동안 오전 12:00부터 매 5 분 시작

    이게 제로그고요. 현재 문제점이 카스퍼스키 백신을 설치하는 도중에 롤백이 일어나서 지원을 받아도 해결이 안됩니다.
    루트킷으로 의심된다고 하고 그쪽 프로그램을 사용해도 나오는게 거의 없네요.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services 그리고 이 경로에 보면 키 열기 오류라고 해서
    약 250개정도가 똑같은 방식으로 안 열립니다. 삭제도 안되고요. 이거때문에 그런가 의심을 하더라고요.
    몇개의 정보를 찾아보니 백신파일(노턴등), 그냥 돌아다니는 제거툴들 이런것들이 다 등록이 되어있던데 실제로 서비스는 실행이 안된걸로 보여지고요. 찾다가 찾다가 여기까지 왔는데.. 다른 프로그램도 있긴 있는데 테스트를 아직 진행을 못했고요. 어떤식으로 해결할수 있을까요?
    서버2003 sp2이고 포맷을 하면 안되는 상황입니다.. ㅠㅠ
    사용자가 쓰고 있는상태라서 저녁늦게만 또 작업이 됩니다.
    차단이라고 글이 안써지네요..

    • windowexe.com 2014.03.24 17:57 신고  수정/삭제

      로그에는 별다른 특이사항은 없는데 왜 그런지는 모르겠네요.

    • ... 2014.03.24 18:27  수정/삭제

      혹시 어떻게 처리방법이 없을까요? 오늘 작업할 예정인데 ..
      gmer라는 프로그램으로 작업도 할 예정인데 그게 실행이 될지 여부와 레지스트리 값 강제 삭제시 문제가 있을거 같기도 하고 ..
      우선은 레지스트리가 안 열리는 이유를 모르겠네요..
      노턴값도 있어서 norton removal tool 을 이용해서 지워보려 했는데 프로그램을 실행하면 실행이 안되네요 . . .

      aasw2_service, abtrusiondriver, abtrusionsecurityservice,
      acshield,aeserv,ambrapp,ambrim,antivirfirewallservice,antivirservice,
      apftrans,avas_service,avfwot,avg anti-rootkit,avg anti-spyware.priver,
      avg anti-spyware.guard,avg7core,avg7rsnt,avg7vpdsvc,avg8wd,avgarcln,
      avgclean,avgcore,avgcoresvc,avgfsh,avgfws8,avgfwsrv,avgmfx86,avgrkx86,
      avgserv,avipbb,avkwctl,avp,avzsg,baserand,bc_filter,bc_ip-f,bdftdif,
      blackice,blinksvc,bocore,bufferzonesrv,bzdcomlaunch,bzrpcss,calsafe,
      cavasm,ccevtmgr,cmdagent,cmdguard,
      comodo anti-virus and anti-spyware service,
      drivesentryfilterdriver2lite, drivesentry/keeperdriver,
      drivesentryreghookdriver,drvfltlp,ds2kdrv,dwall,econceal,econservice,
      ekrn,easervice,eqspywatch,escanmonitorservice,escanmx,esiasdrv,fgccow
      fgccsrt,fgcrepl,filehook,filemon701,filesvc,fortipfw,fortknox,
      fortknox_drv,fsdfwd,f-secure gatekeeper handler strater,f-secure hips,
      fsfltdrv,fsfw,fsrt,fwdrv,gdfwsrv,geswall,ghostsec,ghstwall,gmer,
      gswstrv,guardx,hipservice,iamserv,icsal,immdrv,inort,ipcsvc,ipfrwl,
      isdrvll8,isprbdrv,lsrservice,lswsvc,itmrtsvc,
      jeticopersonalfirewallserver,kavmonitor service,kavsvc,
      kerioserverfirewwall,khips,klblmain,klif,klpf,klpid,kpf4,kpfwsvc,
      kpguard,kregex,ksxscall,ksysfilter,ksxsmon,kvdp,kuredir,kusvvxp,
      kuwsc,kwatchsvc,lnsfwl,mcods,mcredirector,mcshiled,mksfwall,mksfwallf,
      mksfwallt,mpfp,mpfservice,mpsvcservice,msfwhlr,navapel,navapsvc,naveng,navex15,ncdssvc,neoava_drv,neosvc,netfltdi,nis,nk4seem,nod32drv,
      nod32krn,norman zanda,norton antivirus server,norton internet security,nvcoas,onecoremp,onlinent,outpostfirewall,pavfires,
      pavkre,pavprot,pavsrv,pcctlcom,pcscnsrv,pctavsrv,pctoolsfirewallplus,
      persfw,pfnet,pldriver,portscoclc,ppctlpriv,prevxaagent,prismandis,
      prismandisfilter,procexp100,proexp90,procmon10,procmon11,prosecur,
      protectedstorage,psexesuv,psh_svc,pshost,psimsvc,psmantispy,pwipf2,
      pwipf6,quickhealfirewall,rapapp,reghook,regmonnol,remoteaccess,
      rfw,rfwservice,rgsvc,rkd,rkhdrv10,rkdrv31,rkdrv40,rusdisk,safemon,
      safensec,safesystem,sanasafeconnectagent,savant,savantnetagent,
      savrt,savrtpel,savservice,sbapifs,sbcssvc,sbhr,sdauxservice,
      sdcoreservice,sensiveguardsvc,sfcorevt,sfctlcom,shadow,
      shadowsystemservice,smcservice,snoopfree,snoopfreesvc,
      sophosclientfirewall,spf4,spider,spiderctl,spidernt,srescan,superkill,
      svconlinearmor,symantec antivirus,symantec antibotagent,symevent,
      symtdi,sysprotservice,tahi,tavm_service,tdi-rd,teefer,threatfire,
      tmbmserver,tmntsrv,tmpfw,tmproxy,tppfdmn,tpsrv,umxcfg,umxpol,
      uha32ldr,ucfsvc,vetmonnt,vfilt,vrfwsvc,vsdatant,vsmon,wehnserv,
      windefend,windows steadystate,winrollbacksvc,winroute,
      wrdrv,xcomm,xpcket,zeroprotect,zvregmon
      이게 안열리는 키값들입니다.... ㅠ

  7. ㅠㅜ 2014.02.10 17:49  수정/삭제  댓글쓰기

    연락 좀 주세요~ㅠ

    • windowexe.com 2014.02.10 17:51 신고  수정/삭제

      뭐가 안된다는 건지 정확히 알려주세요.

      Backup 폴더에 보면 삭제된 .reg 파일들이 있을겁니다. 모두 더블클릭해서 확인을 누르세요. 재부팅하면 원래대로 복구될겁니다.

    • ㅠㅜ 2014.02.10 17:59  수정/삭제

      백업된 게 123개인데 하나하나 다 클릭해서 추가했는데도 상태가 이상해요 일곱개를 제외하곤 다 추가했어요

    • windowexe.com 2014.02.10 18:19 신고  수정/삭제

      안전모드로 부팅해서 작업해보세요.

      안전모드로도 안되면 명령프롬프트모드로 부팅하세요.
      실행폴더로 이동해서 삭제된 서비스를 명령프롬프트로 모두 등록해야 되는데 이건 좀 어려운 작업이긴 합니다.
      -명령프롬프트 창에서 실행폴더로 이동
      cd 다운받아서 실행한 폴더의 이름
      cd backup
      -삭제된 서비스파일의 목록을 나열
      dir

      -삭제된 서비스를 하나하나 모두 등록
      regedit /s 아무개1.reg
      regedit /s 아무개2.reg
      regedit /s 아무개3.reg
      이런식으로 모두 등록하고 재부팅하세요.

      윈도우 핵심서비스들은 삭제해도 복구가 안되는 경우가 있기는 한데 이 방법으로도 안되면 윈도우 재설치해야 될거 같습니다.

    • ㅠㅜ 2014.02.10 18:43  수정/삭제

      저 지금 명령프롬프토로 들어왔는데 써주신 설명을 봐도 어떻게 해야할지 모르겠어요 글고 지금 본컴은 거의 돌아왔는데 눈에 띄게 가장 문제인 건 인터넷이 안되고 소리가 전혀 안나와요 혹시 원격조종 가능한가요?

    • windowexe.com 2014.02.10 19:02 신고  수정/삭제

      윈도우 재설치하는 거 말고는 답이 없을거 같네요.

    • ㅠㅜ 2014.02.10 19:08  수정/삭제

      근데 이게 내손으로 직접 삭제한 게 아니라 님이 만든 프로그램을 실행시켰을 뿐인데 프로그램은 실행되지도 않고 갑자기 모든 자료가 삭제된 겁니다. 뭘 해볼 틈도 없었어요. 그리고 포맷한지 수 년째라서 그만큼 자료가 많아요. 포맷하기가 쉬운 상황이 아니에요. 그동안 아무 문제없이 컴 잘 썼는데 퇴근하고 오늘 갑자기 이러네요. 크롬 확장프로그램 하나 삭제하려다가 이 사단이 난겁니다. 전화통화라든지 원격조종이라든지 도움 부탁드립니다.

    • windowexe.com 2014.02.10 19:20 신고  수정/삭제

      파일을 다운받아서 실행하는 것만으로는 아무것도 삭제하지 않습니다.
      서비스항목을 잘못 건드렸으니 그런현상이 생기는 거죠.

      해당 게시글에도 경고문이 빨간색으로 표시되어 있습니다.
      프로그램이 어떤방식으로 돌아가는지 확실히 이해한 후에 사용하세요.
      검정색/보라색으로 표시된 [05-SERVICE] 항목을 잘못 체크해제하면 컴퓨터가 먹통될 수도 있으니 주의하세요.

      하드디스크를 다른 컴퓨터에 연결해서 데이타를 백업받고 재설치하세요. 그것말고는 방법이 없을거 같습니다.

    • 2014.02.10 19:29  수정/삭제

      저도 예전에 이 프로그램을 잠깐 써봤기 때문에 위험한 프로그램이라는 건 인식하고 있었습니다. 그러다가 최근에 크롬 확장프로그램 때문에 골치가 아파서 검색해보니 이 프로그램으로 삭제가 된다길래 예전에 받아놓은 파일을 오랜만에 실행시켰는데 뭘 건들고 체크하고 할 것도 없이 갑자기 이렇게 된 겁니다. 거짓말처럼 들릴 수도 있다는 거 알고 있습니다. 근데 한치의 거짓말도 없습니다. 제가 뭐가 이득이라고 거짓말을 하겠습니까. 원격조종으로 님이 말한 방법으로 한 번만 시도해주세요. 그렇게 해도 안되면 재설치하겠습니다.

    • windowexe.com 2014.02.10 19:48 신고  수정/삭제

      안전모드(명령프롬프트)에서는 인터넷이 안됩니다.

      http://windowexe.tistory.com/2794

  8. 2014.02.10 17:24  수정/삭제  댓글쓰기

    비밀댓글입니다

  9. 1234 2014.01.26 22:29  수정/삭제  댓글쓰기

    질문좀 하겠습니다.

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0에있는
    armsvc.exe가 무엇인지 검색해볼려고 했으나
    [부팅할 때마다 자동실행되는 armsvc.exe 서비스 중지하기까]진 있어도
    사이트가 안들어가진다네요.
    혹시 사이트 문 닫았나요.
    아니면 혹시 인터넷 회선에 따라 접속이 제한되어 있나요.

    • windowexe.com 2014.01.26 22:48 신고  수정/삭제

      동일아이피에서 엑세스횟수가 많으면 자동으로 차단이 되기도 하는데 익일 접속했는데도 접속이 안되면 차단아이피로 등록되어있을겁니다.

      아아피를 주소 알려주세요. 확인해보겠습니다.

  10. 차형국 2013.12.26 10:19  수정/삭제  댓글쓰기

    관리자님! 인터넷 쓰레기들 박멸에 늘 이리 신경써주셔 감사드립니다.

    어디다 고마움 전할 곳 찿다가 여기에 글드립니다.

    60년만에 돌아오는 갑자년 새해 댁내 항상 화목하시고 늘 건강하시길, 복많이 받으십쇼 !.