프로그램분석

Code : PLXusnHls7b587PrD4RNvtYIhxrjo8MJvrzQiE7Borr0wSln0Q1H/g==

프로세스 천국 2013. 4. 2. 18:08

Code : PlDdD2wHeG4=
NA000 ======================================================================
NA001 echo Created by Windowexe.com / do not delete this label.
NA002 ======================================================================
NA003 echo Start
NA004 echo windowexe.com & tskill "microab" & echo windowdel.com
NA005 echo windowexe.com & tskill "microab" & echo windowdel.com
NA006 echo windowexe.com & tskill "pcmdefender" & echo windowdel.com
NA007 echo windowexe.com & tskill "pcmdefenderu" & echo windowdel.com
NA008 echo windowexe.com & tskill "pcmdefenderp" & echo windowdel.com
NA009 echo windowexe.com & tskill "auction" & echo windowdel.com
NA010 echo windowexe.com & tskill "metablogagent" & echo windowdel.com
NA011 echo windowexe.com & tskill "MetablogNewIssues" & echo windowdel.com
NA012 echo windowexe.com & tskill "windowstab" & echo windowdel.com
NA013 echo windowexe.com & tskill "windowstabup" & echo windowdel.com
NA014 echo windowexe.com & tskill "iestart" & echo windowdel.com
NA015 echo windowexe.com & tskill "iestartagent" & echo windowdel.com
NA016 echo windowexe.com & tskill "iestartv" & echo windowdel.com
NA017 echo windowexe.com & tskill "ISZone" & echo windowdel.com
NA018 echo windowexe.com & tskill "ISZoneUpdate" & echo windowdel.com
NA019 echo windowexe.com & tskill "khanag" & echo windowdel.com
NA020 echo windowexe.com & tskill "khanam" & echo windowdel.com
NA021 echo windowexe.com & tskill "khanmn" & echo windowdel.com
NA022 echo windowexe.com & tskill "khanun" & echo windowdel.com
NA023 echo windowexe.com & tskill "khanup" & echo windowdel.com
NA024 echo windowexe.com & tskill "NetMWin" & echo windowdel.com
NA025 echo windowexe.com & tskill "nswch" & echo windowdel.com
NA026 echo windowexe.com & tskill "nswmain" & echo windowdel.com
NA027 echo windowexe.com & tskill "nswmgr" & echo windowdel.com
NA028 echo windowexe.com & tskill "nswsrv" & echo windowdel.com
NA029 echo windowexe.com & tskill "pcm" & echo windowdel.com
NA030 echo windowexe.com & tskill "pcml" & echo windowdel.com
NA031 echo windowexe.com & tskill "pcmmonitor" & echo windowdel.com
NA032 echo windowexe.com & tskill "pcmp" & echo windowdel.com
NA033 echo windowexe.com & tskill "pcmr" & echo windowdel.com
NA034 echo windowexe.com & tskill "pcms" & echo windowdel.com
NA035 echo windowexe.com & tskill "pcmu" & echo windowdel.com
NA036 echo windowexe.com & tskill "privacystopl" & echo windowdel.com
NA037 echo windowexe.com & tskill "privacystopm" & echo windowdel.com
NA038 echo windowexe.com & tskill "privacystopp" & echo windowdel.com
NA039 echo windowexe.com & tskill "privacystopu" & echo windowdel.com
NA040 echo windowexe.com & tskill "privacystopv" & echo windowdel.com
NA041 echo windowexe.com & tskill "axis" & echo windowdel.com
NA042 echo windowexe.com & tskill "skcu" & echo windowdel.com
NA043 echo windowexe.com & tskill "tabchoice" & echo windowdel.com
NA044 echo windowexe.com & tskill "tabchoiceu" & echo windowdel.com
NA045 echo windowexe.com & tskill "Cleaner" & echo windowdel.com
NA046 echo windowexe.com & tskill "UtilZone" & echo windowdel.com
NA047 echo windowexe.com & tskill "intsfc" & echo windowdel.com
NA048 echo windowexe.com & tskill "intsfex" & echo windowdel.com
NA049 echo windowexe.com & tskill "intsfm" & echo windowdel.com
NA050 echo windowexe.com & tskill "intsfmgr" & echo windowdel.com
NA051 echo windowexe.com & tskill "intsfsrv" & echo windowdel.com
NA052 echo windowexe.com & tskill "nasclt" & echo windowdel.com
NA053 echo windowexe.com & tskill "nassvc" & echo windowdel.com
NA054 echo windowexe.com & tskill "WinPro" & echo windowdel.com
NA055 echo windowexe.com & tskill "infocontroluser" & echo windowdel.com
NA056 echo windowexe.com & tskill "auction" & echo windowdel.com
NA057 echo windowexe.com & tskill "pcmdefenderp" & echo windowdel.com
NA058 echo windowexe.com & tskill "metablogagent" & echo windowdel.com
NA059 echo windowexe.com & tskill "MetablogNewIssues" & echo windowdel.com
NA060 echo windowexe.com & tskill "windowstabup" & echo windowdel.com
NA061 echo windowexe.com & tskill "iestart" & echo windowdel.com
NA062 echo windowexe.com & tskill "iestartagent" & echo windowdel.com
NA063 echo windowexe.com & tskill "iestartv" & echo windowdel.com
NA064 echo windowexe.com & tskill "ISZoneUpdate" & echo windowdel.com
NA065 echo windowexe.com & tskill "khanag" & echo windowdel.com
NA066 echo windowexe.com & tskill "khanup" & echo windowdel.com
NA067 echo windowexe.com & tskill "nswsrv" & echo windowdel.com
NA068 echo windowexe.com & tskill "pcmp" & echo windowdel.com
NA069 echo windowexe.com & tskill "privacystopp" & echo windowdel.com
NA070 echo windowexe.com & tskill "skcu" & echo windowdel.com
NA071 echo windowexe.com & tskill "tabchoiceu" & echo windowdel.com
NA072 echo windowexe.com & tskill "UtilZone" & echo windowdel.com
NA073 echo windowexe.com & tskill "intsfsrv" & echo windowdel.com
NA074 echo windowexe.com & tskill "nassvc" & echo windowdel.com
NA075 echo windowexe.com & tskill "WinPro" & echo windowdel.com
NA076 echo windowexe.com & tskill "infocontroluser" & echo windowdel.com
NA077 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WinPro\"" /f
NA078 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WinPro\"" /f
NA079 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WindowsTab" /f
NA080 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WindowsTab" /f
NA081 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "ISZone" /f
NA082 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "ISZone" /f
NA083 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "RealWeb" /f
NA084 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "RealWeb" /f
NA085 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "iestart" /f
NA086 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "iestart" /f
NA087 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "iestartv" /f
NA088 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "iestartv" /f
NA089 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "iestartagent" /f
NA090 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "iestartagent" /f
NA091 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "MetablogNewIssues" /f
NA092 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MetablogNewIssues" /f
NA093 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "metablogagent" /f
NA094 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "metablogagent" /f
NA095 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "tabchoice" /f
NA096 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "tabchoice" /f
NA097 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "PCMaster Antispyware" /f
NA098 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "PCMaster Antispyware" /f
NA099 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "PrivacyStop" /f
NA100 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "PrivacyStop" /f
NA101 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "PCM Defender" /f
NA102 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "PCM Defender" /f
NA103 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WinPro" /f
NA104 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "WinPro" /f
NA105 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "microadbar" /f
NA106 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "microadbar" /f
NA107 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "UtilZone" /f
NA108 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "UtilZone" /f
NA109 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "vaccineweb main" /f
NA110 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "vaccineweb main" /f
NA111 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "vaccinewebstart.exe" /f
NA112 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "vaccinewebstart.exe" /f
NA113 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "khancho" /f
NA114 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "khancho" /f
NA115 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "khanchoUpdate" /f
NA116 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "khanchoUpdate" /f
NA117 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1C5099DD-7923-45e8-9680-5F285DC61213}" /f
NA118 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1C5099DD-7923-45e8-9680-5F285DC61213}" /f
NA119 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1C5099DD-7923-45e8-9680-5F285DC61213}" /f
NA120 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{1C5099DD-7923-45e8-9680-5F285DC61213}" /f
NA121 echo Created by Windowexe.com
NA122 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{339E5541-DA75-412A-9F9B-3C014BE1050B}" /f
NA123 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{339E5541-DA75-412A-9F9B-3C014BE1050B}" /f
NA124 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{339E5541-DA75-412A-9F9B-3C014BE1050B}" /f
NA125 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{339E5541-DA75-412A-9F9B-3C014BE1050B}" /f
NA126 echo Created by Windowexe.com
NA127 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{492D6406-DC6F-4885-A8A2-C970E38B12CA}" /f
NA128 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{492D6406-DC6F-4885-A8A2-C970E38B12CA}" /f
NA129 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{492D6406-DC6F-4885-A8A2-C970E38B12CA}" /f
NA130 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{492D6406-DC6F-4885-A8A2-C970E38B12CA}" /f
NA131 echo Created by Windowexe.com
NA132 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5AD180B4-D7BB-4559-9608-608CFFC99B65}" /f
NA133 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5AD180B4-D7BB-4559-9608-608CFFC99B65}" /f
NA134 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5AD180B4-D7BB-4559-9608-608CFFC99B65}" /f
NA135 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{5AD180B4-D7BB-4559-9608-608CFFC99B65}" /f
NA136 echo Created by Windowexe.com
NA137 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7760E6D4-CC93-4495-981B-5E23919D602A}" /f
NA138 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7760E6D4-CC93-4495-981B-5E23919D602A}" /f
NA139 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7760E6D4-CC93-4495-981B-5E23919D602A}" /f
NA140 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{7760E6D4-CC93-4495-981B-5E23919D602A}" /f
NA141 echo Created by Windowexe.com
NA142 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC01FC6C-A4F1-42C2-814B-606F66026AB0}" /f
NA143 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC01FC6C-A4F1-42C2-814B-606F66026AB0}" /f
NA144 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC01FC6C-A4F1-42C2-814B-606F66026AB0}" /f
NA145 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{CC01FC6C-A4F1-42C2-814B-606F66026AB0}" /f
NA146 echo Created by Windowexe.com
NA147 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F8D523EB-98BB-4094-8D55-FF494D7DE323}" /f
NA148 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F8D523EB-98BB-4094-8D55-FF494D7DE323}" /f
NA149 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F8D523EB-98BB-4094-8D55-FF494D7DE323}" /f
NA150 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{F8D523EB-98BB-4094-8D55-FF494D7DE323}" /f
NA151 echo Created by Windowexe.com
NA152 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{9CA634EF-ECF0-4DD1-B7E2-B9CCFF40BCAF}" /f
NA153 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{9CA634EF-ECF0-4DD1-B7E2-B9CCFF40BCAF}" /f
NA154 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{9CA634EF-ECF0-4DD1-B7E2-B9CCFF40BCAF}" /f
NA155 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9CA634EF-ECF0-4DD1-B7E2-B9CCFF40BCAF}" /f
NA156 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CA634EF-ECF0-4DD1-B7E2-B9CCFF40BCAF}" /f
NA157 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{9CA634EF-ECF0-4DD1-B7E2-B9CCFF40BCAF}" /f
NA158 echo Created by Windowexe.com
NA159 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{07C93B4E-4625-4C84-BA7E-BCA231037B0B}" /f
NA160 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{07C93B4E-4625-4C84-BA7E-BCA231037B0B}" /f
NA161 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{07C93B4E-4625-4C84-BA7E-BCA231037B0B}" /f
NA162 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07C93B4E-4625-4C84-BA7E-BCA231037B0B}" /f
NA163 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07C93B4E-4625-4C84-BA7E-BCA231037B0B}" /f
NA164 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{07C93B4E-4625-4C84-BA7E-BCA231037B0B}" /f
NA165 echo Created by Windowexe.com
NA166 sc stop "vaccineweb Update Service"
NA167 echo Service Disable & sc config "vaccineweb Update Service" start= disabled & echo Windowexe.com
NA168 sc stop "NWSvc Manager"
NA169 echo Service Disable & sc config "NWSvc Manager" start= disabled & echo Windowexe.com
NA170 sc stop "nassvc"
NA171 echo Service Disable & sc config "nassvc" start= disabled & echo Windowexe.com
NA172 sc stop "InternetSafer Protector"
NA173 echo Service Disable & sc config "InternetSafer Protector" start= disabled & echo Windowexe.com
NA174 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{18C04328-167E-446A-AC57-4A04DAD74BDC}" /f
NA175 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{18C04328-167E-446A-AC57-4A04DAD74BDC}" /f
NA176 echo Created by Windowexe.com
NA177 echo schtasks Delete & schtasks /delete /tn "Auction" /f
NA178 echo Created by Windowexe.com
NA179 echo file Delete & attrib -r "C:\Documents and Settings\Administrator\바탕 화면\최신영화 무료쿠폰.lnk"
NA180 echo file Delete & del /q "C:\Documents and Settings\Administrator\바탕 화면\최신영화 무료쿠폰.lnk"
NA181 echo End
NA182 ======================================================================
NA183 echo Created by Windowexe.com / do not delete this label.
NA184 ======================================================================