프로그램분석

Code : YSWDiyIV+yZfpObHNG60CbjL8mshhsKWPbcEvwQdhVI=

프로세스 천국 2013. 4. 17. 16:59

[00-PROCESS]**AdobeARM -/- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[00-PROCESS]**AdskScSrv -/- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
[00-PROCESS]**allpopsvi -/- C:\Program Files\allpopup\allpopsvi.exe
[00-PROCESS]**ALZip -/- C:\Program Files\ESTsoft\ALZip\ALZip.exe
[00-PROCESS]**clgsvr -/- C:\Program Files\Windows CloudGet\clgsvr.exe
[00-PROCESS]**DaumCleaner -/- C:\Program Files\Daum\Cleaner\DaumCleaner.exe
[00-PROCESS]**DaumSAM -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\Daum\DaumLiveAgent\DaumSAM.exe
[00-PROCESS]**DaumStation -/- C:\Program Files\Daum\DaumStation\DaumStation.exe
[00-PROCESS]**DaumStationService -/- C:\Program Files\Daum\DaumStation\DaumStationService.exe
[00-PROCESS]**E_FATIGJS -/- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIGJS.EXE
[00-PROCESS]**E_S50RP7 -/- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
[00-PROCESS]**E_S50ST7 -/- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE
[00-PROCESS]**FlashPlayerUpdateService -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[00-PROCESS]**fph -/- C:\Program Files\Fasoo DRM\fph.exe
[00-PROCESS]**FUFAXSTM -/- C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
[00-PROCESS]**iexplore -/- C:\Program Files\Internet Explorer\iexplore.exe
[00-PROCESS]**infodatauserreset -/- C:\WINDOWS\infodatauserreset.exe
[00-PROCESS]**ismsvc -/- C:\Program Files\insafeclient\ismsvc.exe
[00-PROCESS]**lstspsv -/- C:\Program Files\lastpopup\lstspsv.exe
[00-PROCESS]**Matsvc -/- C:\Program Files\Microsoft Fix it Center\Matsvc.exe
[00-PROCESS]**metablogagent -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\MetablogNewIssues\metablogagent.exe
[00-PROCESS]**MetablogNewIssues -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\MetablogNewIssues\MetablogNewIssues.exe
[00-PROCESS]**microab -/- C:\Documents and Settings\Administrator\Application Data\microadbar\microab.exe
[00-PROCESS]**nextray -/- C:\Program Files\nextray\nextray.exe
[00-PROCESS]**npkcmsvc -/- C:\WINDOWS\system32\npkcmsvc.exe
[00-PROCESS]**npkfxsvc -/- C:\WINDOWS\system32\npkfxsvc.exe
[00-PROCESS]**nvsvc32 -/- C:\WINDOWS\system32\nvsvc32.exe
[00-PROCESS]**ODSERV -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[00-PROCESS]**OSE -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[00-PROCESS]**RTHDCPL -/- C:\WINDOWS\RTHDCPL.EXE
[00-PROCESS]**RUNDLL32 -/- C:\WINDOWS\system32\RUNDLL32.EXE
[00-PROCESS]**snprot -/- C:\Program Files\SearchN\snprot.exe
[00-PROCESS]**SNSvcApp -/- C:\Program Files\SearchN\SNSvcApp.exe
[00-PROCESS]**SNUpdate -/- C:\Program Files\SearchN\SNUpdate.exe
[00-PROCESS]**spupdsvc -/- C:\WINDOWS\system32\spupdsvc.exe
[00-PROCESS]**svcwsmwin -/- C:\WINDOWS\System32\svcwsmwin.exe
[00-PROCESS]**userinforesetupdate -/- C:\WINDOWS\userinforesetupdate.exe
[00-PROCESS]**V3LSvc -/- C:\Program Files\AhnLab\V3Lite\V3LSvc.exe
[00-PROCESS]**V3LTray -/- C:\Program Files\AhnLab\V3Lite\V3LTray.exe
[00-PROCESS]**wdrwsmsvc -/- C:\WINDOWS\System32\wdrwsmsvc.exe
[00-PROCESS]**windiscover -/- C:\Program Files\windiscover\windiscover.exe
[00-PROCESS]**windowstab -/- C:\Documents and Settings\Administrator\Application Data\WindowsTab\windowstab.exe
[00-PROCESS]**windowstabup -/- C:\Documents and Settings\Administrator\Application Data\WindowsTab\windowstabup.exe
[00-PROCESS]**winsmex -/- C:\Program Files\WinsManager\winsmex.exe
[00-PROCESS]**wsupd -/- C:\Program Files\windiscover\wsupd.exe
[00-PROCESS]**xwISPLife -/- C:\Program Files\VP\ISP Life\xwISPLife.exe
[01-HKCUREG]**Adobe ARM -/- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[01-HKCUREG]**AhnLab V3Lite Tray Process -/- C:\Program Files\AhnLab\V3Lite\V3LTray.exe /logon
[01-HKCUREG]**Alcmtr -/- ALCMTR.EXE
[01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[01-HKCUREG]**Daum Streaming Service -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\Daum\DaumLiveAgent\DaumSAM.exe
[01-HKCUREG]**DaumCleaner -/- C:\Program Files\Daum\Cleaner\DaumCleaner.exe /T
[01-HKCUREG]**DaumStation -/- C:\Program Files\Daum\DaumStation\DaumStation.exe
[01-HKCUREG]**EPSON TX320 WorkForce320 Series -/- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIGJS.EXE /FU C:\WINDOWS\TEMP\E_S54.tmp /EF HKCU
[01-HKCUREG]**FPH Exe -/- C:\PROGRA~1\FASOOD~1\fph.exe
[01-HKCUREG]**FUFAXSTM -/- C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
[01-HKCUREG]**ISP Life -/- C:\Program Files\VP\ISP Life\xwISPLife.exe
[01-HKCUREG]**metablogagent -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\MetablogNewIssues\metablogagent.exe
[01-HKCUREG]**MetablogNewIssues -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\MetablogNewIssues\MetablogNewIssues.exe /byboot
[01-HKCUREG]**microadbar -/- C:\Documents and Settings\Administrator\Application Data\microadbar\microab.exe update
[01-HKCUREG]**nextray -/- C:\Program Files\nextray\nextray.exe
[01-HKCUREG]**NvCplDaemon -/- RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dllNvStartup
[01-HKCUREG]**NvMediaCenter -/- RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dllNvTaskbarInit
[01-HKCUREG]**RTHDCPL -/- RTHDCPL.EXE
[01-HKCUREG]**SearchN -/- C:\Program Files\SearchN\SNUpdate.exe
[01-HKCUREG]**snprot -/- C:\Program Files\SearchN\snprot.exe
[01-HKCUREG]**vaccinedrive main -/- C:\Program Files\vaccinedrive\vaccinedriveu.exe /8L
[01-HKCUREG]**vaccinedrivestart.exe -/- C:\Program Files\vaccinedrive\vaccinedrivestart.exe
[01-HKCUREG]**windiscover -/- C:\Program Files\windiscover\windiscover.exe
[01-HKCUREG]**WindowsTab -/- C:\Documents and Settings\Administrator\Application Data\WindowsTab\windowstabup.exe
[01-HKCUREG]**wsupd -/- C:\Program Files\windiscover\wsupd.exe
[02-HKLMREG]**Adobe ARM -/- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[02-HKLMREG]**AhnLab V3Lite Tray Process -/- C:\Program Files\AhnLab\V3Lite\V3LTray.exe /logon
[02-HKLMREG]**Alcmtr -/- ALCMTR.EXE
[02-HKLMREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[02-HKLMREG]**Daum Streaming Service -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\Daum\DaumLiveAgent\DaumSAM.exe
[02-HKLMREG]**DaumCleaner -/- C:\Program Files\Daum\Cleaner\DaumCleaner.exe /T
[02-HKLMREG]**DaumStation -/- C:\Program Files\Daum\DaumStation\DaumStation.exe
[02-HKLMREG]**EPSON TX320 WorkForce320 Series -/- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIGJS.EXE /FU C:\WINDOWS\TEMP\E_S54.tmp /EF HKCU
[02-HKLMREG]**FPH Exe -/- C:\PROGRA~1\FASOOD~1\fph.exe
[02-HKLMREG]**FUFAXSTM -/- C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
[02-HKLMREG]**ISP Life -/- C:\Program Files\VP\ISP Life\xwISPLife.exe
[02-HKLMREG]**metablogagent -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\MetablogNewIssues\metablogagent.exe
[02-HKLMREG]**MetablogNewIssues -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\MetablogNewIssues\MetablogNewIssues.exe /byboot
[02-HKLMREG]**microadbar -/- C:\Documents and Settings\Administrator\Application Data\microadbar\microab.exe update
[02-HKLMREG]**nextray -/- C:\Program Files\nextray\nextray.exe
[02-HKLMREG]**NvCplDaemon -/- RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dllNvStartup
[02-HKLMREG]**NvMediaCenter -/- RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dllNvTaskbarInit
[02-HKLMREG]**RTHDCPL -/- RTHDCPL.EXE
[02-HKLMREG]**SearchN -/- C:\Program Files\SearchN\SNUpdate.exe
[02-HKLMREG]**snprot -/- C:\Program Files\SearchN\snprot.exe
[02-HKLMREG]**vaccinedrive main -/- C:\Program Files\vaccinedrive\vaccinedriveu.exe /8L
[02-HKLMREG]**vaccinedrivestart.exe -/- C:\Program Files\vaccinedrive\vaccinedrivestart.exe
[02-HKLMREG]**windiscover -/- C:\Program Files\windiscover\windiscover.exe
[02-HKLMREG]**WindowsTab -/- C:\Documents and Settings\Administrator\Application Data\WindowsTab\windowstabup.exe
[02-HKLMREG]**wsupd -/- C:\Program Files\windiscover\wsupd.exe
[03-BHOCLSD]**{18DF081C-E8AD-4283-A596-FA578C2EBDC3} -/- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
[03-BHOCLSD]**{BDDB5A00-D1EB-49D5-B197-72A06DF78AA1} -/- C:\Program Files\Daum\Cleaner\DaumStart.1.5.0.130.dll
[03-BHOCLSD]**{FE14A4CA-5CFA-4C05-9274-6006397B68C9} -/- C:\Program Files\SearchN\SearchN.dll
[05-SERVICE]**AdobeFlashPlayerUpdateSvc -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[05-SERVICE]**allpopup -/- C:\Program Files\allpopup\allpopsvi.exe
[05-SERVICE]**Autodesk Licensing Service -/- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
[05-SERVICE]**clgsvr32 -/- C:\Program Files\Windows CloudGet\clgsvr.exe
[05-SERVICE]**DaumStationService -/- C:\Program Files\Daum\DaumStation\DaumStationService.exe
[05-SERVICE]**EPSON_EB_RPCV4_04 -/- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE
[05-SERVICE]**EPSON_PM_RPCV4_04 -/- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
[05-SERVICE]**ismsvc32 -/- C:\Program Files\insafeclient\ismsvc.exe
[05-SERVICE]**lstspsv32 -/- C:\Program Files\lastpopup\lstspsv.exe
[05-SERVICE]**MatSvc -/- C:\Program Files\Microsoft Fix it Center\Matsvc.exe
[05-SERVICE]**napagent -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\System32\qagentrt.dll
[05-SERVICE]**npkcmsvc -/- C:\WINDOWS\system32\npkcmsvc.exe
[05-SERVICE]**npkfxsvc -/- C:\WINDOWS\system32\npkfxsvc.exe
[05-SERVICE]**nvsvc -/- C:\WINDOWS\system32\nvsvc32.exe
[05-SERVICE]**odserv -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[05-SERVICE]**ose -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[05-SERVICE]**spupdsvc -/- C:\WINDOWS\system32\spupdsvc.exe
[05-SERVICE]**TCCheckAgent -/- C:\Program Files\AdvTopC\TCCheckAgent.exe
[05-SERVICE]**V3 Lite Service -/- C:\Program Files\AhnLab\V3Lite\V3LSvc.exe
[05-SERVICE]**vaccinedrive Update Service -/- C:\WINDOWS\infodatauserreset.exe
[05-SERVICE]**windowfaster Update Service -/- C:\WINDOWS\userinforesetupdate.exe
[05-SERVICE]**Windows WinsManager Diagnostics Service -/- C:\WINDOWS\System32\wdrwsmsvc.exe
[05-SERVICE]**WinsManager Service -/- C:\WINDOWS\System32\svcwsmwin.exe