프로그램분석

Code : BtyaK274X4uYLFVwrGDBYLMiegcbGHXLO1U4MkTyS/g=

프로세스 천국 2013. 3. 16. 17:05

System Analyzer Report 2013, 03, 16

NA001 ======================================================================
NA002 echo Created by Windowexe.com / do not delete this label.
NA003 ======================================================================
NA004 echo Start
NA005 echo windowexe.com & tskill "WindowServiceNT" & echo windowdel.com
NA006 echo windowexe.com & tskill "MicrowindowSearch" & echo windowdel.com
NA007 echo windowexe.com & tskill "minimp3_uc" & echo windowdel.com
NA008 echo windowexe.com & tskill "TCSearch" & echo windowdel.com
NA009 echo windowexe.com & tskill "utilspae" & echo windowdel.com
NA010 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicroProCon" /f
NA011 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicroProCon" /f
NA012 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "utilspae" /f
NA013 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "utilspae" /f
NA014 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "catroot" /f
NA015 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "catroot" /f
NA016 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicrowindowSearch" /f
NA017 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicrowindowSearch" /f
NA018 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "minimp3" /f
NA019 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "minimp3" /f
NA020 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Helpsys" /f
NA021 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Helpsys" /f
NA022 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "windowstatus" /f
NA023 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "windowstatus" /f
NA024 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Adv_TopC" /f
NA025 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Adv_TopC" /f
NA026 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MicrowindowSearch" /f
NA027 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicrowindowSearch" /f
NA028 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA029 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA030 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA031 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA032 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA033 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}" /f
NA034 echo Created by Windowexe.com
NA035 sc stop "WindowSearch Service Manager"
NA036 echo Service Disable & sc config "WindowSearch Service Manager" start= disabled & echo Windowexe.com
NA037 sc stop "vvxtklvbudjkkld"
NA038 echo Service Disable & sc config "vvxtklvbudjkkld" start= disabled & echo Windowexe.com
NA039 sc stop "tyzrtmm3"
NA040 echo Service Disable & sc config "tyzrtmm3" start= disabled & echo Windowexe.com
NA041 sc stop "TCCheckAgent"
NA042 echo Service Disable & sc config "TCCheckAgent" start= disabled & echo Windowexe.com
NA043 sc stop "SmartPopService"
NA044 echo Service Disable & sc config "SmartPopService" start= disabled & echo Windowexe.com
NA045 sc stop "SmartKeyService"
NA046 echo Service Disable & sc config "SmartKeyService" start= disabled & echo Windowexe.com
NA047 sc stop "RunS"
NA048 echo Service Disable & sc config "RunS" start= disabled & echo Windowexe.com
NA049 sc stop "RPGSvcman"
NA050 echo Service Disable & sc config "RPGSvcman" start= disabled & echo Windowexe.com
NA051 sc stop "qfskyebnlbl"
NA052 echo Service Disable & sc config "qfskyebnlbl" start= disabled & echo Windowexe.com
NA053 sc stop "pqqwgaegre"
NA054 echo Service Disable & sc config "pqqwgaegre" start= disabled & echo Windowexe.com
NA055 sc stop "NameCleanSvc"
NA056 echo Service Disable & sc config "NameCleanSvc" start= disabled & echo Windowexe.com
NA057 sc stop "mspoenum SVC"
NA058 echo Service Disable & sc config "mspoenum SVC" start= disabled & echo Windowexe.com
NA059 sc stop "jonaodf"
NA060 echo Service Disable & sc config "jonaodf" start= disabled & echo Windowexe.com
NA061 sc stop "ipjdpig"
NA062 echo Service Disable & sc config "ipjdpig" start= disabled & echo Windowexe.com
NA063 sc stop "ImageCodecPlus Service"
NA064 echo Service Disable & sc config "ImageCodecPlus Service" start= disabled & echo Windowexe.com
NA065 sc stop "HwRunS"
NA066 echo Service Disable & sc config "HwRunS" start= disabled & echo Windowexe.com
NA067 sc stop "euipclwumgt"
NA068 echo Service Disable & sc config "euipclwumgt" start= disabled & echo Windowexe.com
NA069 sc stop "cqteuhm"
NA070 echo Service Disable & sc config "cqteuhm" start= disabled & echo Windowexe.com
NA071 sc stop "ApplicationSpecialManagement"
NA072 echo Service Disable & sc config "ApplicationSpecialManagement" start= disabled & echo Windowexe.com
NA073 sc stop "AppCatroots"
NA074 echo Service Disable & sc config "AppCatroots" start= disabled & echo Windowexe.com
NA075 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FA214B13-1A9F-480B-B749-94A566FC59D9}" /f
NA076 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{FA214B13-1A9F-480B-B749-94A566FC59D9}" /f
NA077 echo Created by Windowexe.com
NA078 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D64A7743-7E62-4002-90EA-80E0671F9902}" /f
NA079 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{D64A7743-7E62-4002-90EA-80E0671F9902}" /f
NA080 echo Created by Windowexe.com
NA081 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8605E9B4-68C1-4ED9-B282-74C1AA3C312E}" /f
NA082 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{8605E9B4-68C1-4ED9-B282-74C1AA3C312E}" /f
NA083 echo Created by Windowexe.com
NA084 echo HKEY_LOCAL_MACHINE DSREG Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{FC23FA59-2754-4FD6-9ADA-20C5758D7F66}" /f
NA085 echo HKEY_LOCAL_MACHINE DSREG Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{FB631360-CC3F-4CF7-AFA8-1CF8D077A886}" /f
NA086 echo HKEY_LOCAL_MACHINE DSREG Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{9355B0DA-2A80-40cb-8E0E-C4A152467E18}" /f
NA087 echo HKEY_LOCAL_MACHINE DSREG Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{8E8CBB75-9532-4cc9-B5E3-6D282E92151A}" /f
NA088 echo HKEY_LOCAL_MACHINE DSREG Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{42767D19-9D08-4638-8768-D342BA400E36}" /f
NA089 echo HKEY_LOCAL_MACHINE DSREG Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{09B77220-D441-471f-9896-DE86FF77E65E}" /f
NA090 echo End
NA091 ======================================================================
NA092 echo Created by Windowexe.com / do not delete this label.
NA093 ======================================================================