프로그램분석

Code : Cu3UX85gPkyk7fGFZhioPbq2eWW2M6QR

프로세스 천국 2013. 4. 30. 22:05

[00-PROCESS]**AdobeARM -/- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[00-PROCESS]**browsemngr -/- C:\Documents and Settings\Administrator\Application Data\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
[00-PROCESS]**c2c_service -/- C:\Documents and Settings\Administrator\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
[00-PROCESS]**drwtsn32 -/- C:\WINDOWS\system32\drwtsn32.exe
[00-PROCESS]**dualboostersvc -/- C:\Program Files\dualbooster\dualboostersvc.exe
[00-PROCESS]**ez-PlusSC -/- C:\Program Files\Common Files\EZ-Plus\ez-PlusSC.exe
[00-PROCESS]**fph -/- C:\Program Files\Fasoo DRM\fph.exe
[00-PROCESS]**fService -/- C:\Program Files\Fasoo DRM\fService.exe
[00-PROCESS]**GoogleUpdate -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[00-PROCESS]**intsfsrv -/- C:\Program Files\Windows InternetSafer\intsfsrv.exe
[00-PROCESS]**jqs -/- C:\Program Files\Java\jre7\bin\jqs.exe
[00-PROCESS]**jucheck -/- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
[00-PROCESS]**jusched -/- C:\Program Files\Common Files\Java\Java Update\jusched.exe
[00-PROCESS]**McCHSvc -/- C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe
[00-PROCESS]**msfeedssync -/- C:\WINDOWS\system32\msfeedssync.exe
[00-PROCESS]**nate_as -/- C:\Program Files\nate_as\nate_as.exe
[00-PROCESS]**NaverAgent -/- C:\Program Files\naver\NaverAgent\NaverAgent.exe
[00-PROCESS]**npkcmsvc -/- C:\WINDOWS\system32\npkcmsvc.exe
[00-PROCESS]**npkfxsvc -/- C:\WINDOWS\system32\npkfxsvc.exe
[00-PROCESS]**nvsvc32 -/- C:\WINDOWS\system32\nvsvc32.exe
[00-PROCESS]**OSE -/- c:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[00-PROCESS]**PMB -/- C:\Program Files\Pando Networks\Media Booster\PMB.exe
[00-PROCESS]**Reader_sl -/- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
[00-PROCESS]**RPGSvcMan -/- C:\Documents and Settings\Administrator\Application Data\RapidGet\RPGSvcMan.exe
[00-PROCESS]**soffice -/- C:\Program Files\OpenOffice.org 3\program\soffice.exe
[00-PROCESS]**SSScheduler -/- C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
[00-PROCESS]**svcspwin -/- C:\WINDOWS\System32\svcspwin.exe
[00-PROCESS]**TCCheckAgent -/- C:\Program Files\AdvTopC\TCCheckAgent.exe
[00-PROCESS]**Updater -/- C:\Program Files\Skype\Updater\Updater.exe
[00-PROCESS]**V3LSvc -/- C:\Program Files\AhnLab\V3Lite\V3LSvc.exe
[00-PROCESS]**V3LTray -/- C:\Program Files\AhnLab\V3Lite\V3LTray.exe
[00-PROCESS]**wdrwspsvc -/- C:\WINDOWS\System32\wdrwspsvc.exe
[00-PROCESS]**webedit_svc_4_2 -/- C:\Program Files\WebEdit\webedit_svc_4_2.exe
[00-PROCESS]**wediasvc -/- C:\WINDOWS\System32\wediasvc.exe
[00-PROCESS]**winspsv -/- C:\Program Files\Windows Winerspop\winspsv.exe
[00-PROCESS]**WMPNetwk -/- C:\Program Files\Windows Media Player\WMPNetwk.exe
[01-HKCUREG]**Adobe ARM -/- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[01-HKCUREG]**Adobe Reader Speed Launcher -/- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
[01-HKCUREG]**AhnLab V3Lite Tray Process -/- C:\Program Files\AhnLab\V3Lite\V3LTray.exe /logon
[01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[01-HKCUREG]**FPH Exe -/- C:\PROGRA~1\FASOOD~1\fph.exe
[01-HKCUREG]**Nate -/- C:\Program Files\nate_as\nate_as.exe
[01-HKCUREG]**NaverAgent -/- C:\Program Files\naver\NaverAgent\NaverAgent.exe /autorun
[01-HKCUREG]**NexonPlug -/- C:\Nexon\NexonPlug\NexonPlug.exe
[01-HKCUREG]**NvCplDaemon -/- RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dllNvStartup
[01-HKCUREG]**SunJavaUpdateSched -/- C:\Program Files\Common Files\Java\Java Update\jusched.exe
[01-HKCUREG]**uTorrent -/- C:\Program Files\uTorrent\uTorrent.exe  /MINIMIZED
[02-HKLMREG]**Adobe ARM -/- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[02-HKLMREG]**Adobe Reader Speed Launcher -/- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
[02-HKLMREG]**AhnLab V3Lite Tray Process -/- C:\Program Files\AhnLab\V3Lite\V3LTray.exe /logon
[02-HKLMREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[02-HKLMREG]**FPH Exe -/- C:\PROGRA~1\FASOOD~1\fph.exe
[02-HKLMREG]**Nate -/- C:\Program Files\nate_as\nate_as.exe
[02-HKLMREG]**NaverAgent -/- C:\Program Files\naver\NaverAgent\NaverAgent.exe /autorun
[02-HKLMREG]**NexonPlug -/- C:\Nexon\NexonPlug\NexonPlug.exe
[02-HKLMREG]**NvCplDaemon -/- RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dllNvStartup
[02-HKLMREG]**SunJavaUpdateSched -/- C:\Program Files\Common Files\Java\Java Update\jusched.exe
[02-HKLMREG]**uTorrent -/- C:\Program Files\uTorrent\uTorrent.exe  /MINIMIZED
[03-BHOCLSD]**{000011A1-74C9-4c7e-9B4E-59B5765CF409} -/- c:\program files\naver\navertoolbar\naversafeguard\nsafeguard_2012_9_24_1.dll
[03-BHOCLSD]**{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -/- C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll
[03-BHOCLSD]**{18DF081C-E8AD-4283-A596-FA578C2EBDC3} -/- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
[03-BHOCLSD]**{67C41E9E-2EBF-4F2B-AF74-314F0D793172} -/- C:\Program Files\naver\NaverToolbar\NaverTB_4_0_15_232.dll
[03-BHOCLSD]**{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -/- C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
[03-BHOCLSD]**{DBC80044-A445-435b-BC74-9C25C1C588A9} -/- C:\Program Files\Java\jre7\bin\jp2ssv.dll
[03-BHOCLSD]**{E77FA0B2-C931-411C-82A2-FF672456B730} -/- C:\Program Files\nate_as\nate_as.dll
[03-BHOCLSD]**{E81E1598-BCE6-40B9-8B68-AE57DAA04452} -/- C:\Program Files\nate_as\nate_as.dll
[04-TOOLBAR]**{D09CFF09-A42A-4EDC-9804-E61224F59CA1} -/- C:\Program Files\naver\NaverToolbar\NaverTB_4_0_15_232.dll
[05-SERVICE]**barocn -/- C:\Program Files\barocn\barosvc.exe
[05-SERVICE]**Browser Manager -/- C:\Documents and Settings\Administrator\Application Data\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
[05-SERVICE]**dualbooster -/- C:\Program Files\dualbooster\dualboostersvc.exe
[05-SERVICE]**EasyPop_Service -/- C:\Documents and Settings\Administrator\Application Data\EasyPop\EasyPop_S.exe iconmania1
[05-SERVICE]**ez-Plus -/- C:\Program Files\Common Files\EZ-Plus\ez-PlusSC.exe
[05-SERVICE]**f_WatchDog -/- C:\Program Files\Fasoo DRM\fService.exe
[05-SERVICE]**fService -/- C:\Program Files\Fasoo DRM\fService.exe
[05-SERVICE]**gupdate -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[05-SERVICE]**gupdatem -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[05-SERVICE]**InfoSvc -/- C:\KMC\Svc\InfoSvc.exe
[05-SERVICE]**InternetSafer Protector -/- C:\Program Files\Windows InternetSafer\intsfsrv.exe
[05-SERVICE]**JavaQuickStarterService -/- C:\Program Files\Java\jre7\bin\jqs.exe -service -config C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf
[05-SERVICE]**McComponentHostService -/- C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe
[05-SERVICE]**napagent -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\System32\qagentrt.dll
[05-SERVICE]**npggsvc -/- C:\WINDOWS\system32\GameMon.des -service
[05-SERVICE]**npkcmsvc -/- C:\WINDOWS\system32\npkcmsvc.exe
[05-SERVICE]**npkfxsvc -/- C:\WINDOWS\system32\npkfxsvc.exe
[05-SERVICE]**NVSvc -/- C:\WINDOWS\system32\nvsvc32.exe
[05-SERVICE]**NWCWorkstation -/- C:\WINDOWS\system32\svchost.exe -/- C:\WINDOWS\System32\nwwks.dll
[05-SERVICE]**ose -/- c:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[05-SERVICE]**RPGSvcman -/- C:\Documents and Settings\Administrator\Application Data\RapidGet\RPGSvcMan.exe
[05-SERVICE]**Skype C2C Service -/- C:\Documents and Settings\Administrator\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
[05-SERVICE]**SkypeUpdate -/- C:\Program Files\Skype\Updater\Updater.exe
[05-SERVICE]**TCCheckAgent -/- C:\Program Files\AdvTopC\TCCheckAgent.exe
[05-SERVICE]**V3 Lite Service -/- C:\Program Files\AhnLab\V3Lite\V3LSvc.exe
[05-SERVICE]**Windows WebEdit Diagnostics Service -/- C:\WINDOWS\System32\wediasvc.exe
[05-SERVICE]**Windows WebEdit Update Class -/- C:\Program Files\WebEdit\webedit_svc_4_2.exe
[05-SERVICE]**Windows WinsPop Diagnostics Service -/- C:\WINDOWS\System32\wdrwspsvc.exe
[05-SERVICE]**WinsPop Service -/- C:\WINDOWS\System32\svcspwin.exe
[05-SERVICE]**winspsv32 -/- C:\Program Files\Windows Winerspop\winspsv.exe
[05-SERVICE]**xsherlock -/- C:\WINDOWS\system32\xsherlock.xem