프로그램분석

Code : 8ZXzPjN1JMoWXL2VgTDPMZs131DfgyJOKlerfOXaeWA=

프로세스 천국 2013. 5. 4. 18:55

----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Windows 7 Ultimate Service Pack 1(6.1.7601.65536)
Intel(R) Core(TM) i5-2450M CPU @ 2.50GHz / 1,023.55 MB
Intel64 Family 6 Model 42 Stepping 7
Date : 2013-05-04
----------------------------------------------------------------------
DF000 C:\Program Files (x86)\FreeListen\bass.dll
DF001 C:\Program Files (x86)\FreeListen\FreeListen.exe
DF002 C:\Program Files (x86)\FreeListen\FreeListenManager.exe
DF003 C:\Program Files (x86)\FreeListen\FreeListenUpdate.exe
DF004 C:\Program Files (x86)\FreeListen\nhopen.dll
DF005 C:\Program Files (x86)\FreeListen\timeAdd.dll
DF006 C:\Program Files (x86)\KeywordYac\KeywordYac.exe
DF007 C:\Program Files (x86)\KeywordYac\KeywordYacUpdate.exe
DF008 C:\Program Files (x86)\KeywordYac\nhopen.dll
DF009 C:\ProgramData\WindowsTab\windowstab.exe
DF010 C:\ProgramData\WindowsTab\windowstabup.exe
DF011 C:\Users\Administrator\AppData\Local\Temp\4734\windiscover.exe
DF012 C:\Users\Administrator\AppData\Local\Temp\FreeListen_Setup_127.exe
DF013 C:\Users\Administrator\AppData\Local\windiscover\c_updater.exe
DF014 C:\Users\Administrator\AppData\Local\windiscover\wdc_uninstaller.exe
DF015 C:\Users\Administrator\AppData\Local\windiscover\windiscover.exe
DF016 C:\Users\Administrator\AppData\Local\windiscover\wsupd.exe
DF017 C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\11번가.url
DF018 C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\G마켓.url
DF019 C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\옥션.url
DF020 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\11번가.url
DF021 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\G마켓.url
DF022 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\옥션.url
DF023 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\KeywordYacInstall_168_177.exe
DF024 C:\Users\Administrator\AppData\Roaming\utilking\FreeListenSetup.exe
DF025 C:\Users\Administrator\AppData\Roaming\utilking\KeywordYacSetup_168_Hide.exe
DF026 C:\Users\Administrator\AppData\Roaming\utilking\signkey.exe
DF027 C:\Users\Administrator\AppData\Roaming\utilking\TC2_Channel132.exe
DF028 C:\Users\Administrator\AppData\Roaming\utilking\windiscover6.exe
DF029 C:\Users\Administrator\AppData\Roaming\utilking\WindowsTabSetup_utilking.exe
DF030 C:\Users\Administrator\Desktop\11번가.url
DF031 C:\Users\Administrator\Desktop\G마켓.url
DF032 C:\Users\Administrator\Desktop\옥션.url
DF033 C:\Users\Administrator\Favorites\11번가.url
DF034 C:\Users\Administrator\Favorites\G마켓.url
DF035 C:\Users\Administrator\Favorites\Links\11번가.url
DF036 C:\Users\Administrator\Favorites\Links\G마켓.url
DF037 C:\Users\Administrator\Favorites\Links\옥션.url
DF038 C:\Users\Administrator\Favorites\연결\11번가.url
DF039 C:\Users\Administrator\Favorites\연결\G마켓.url
DF040 C:\Users\Administrator\Favorites\연결\옥션.url
DF041 C:\Users\Administrator\Favorites\옥션.url
DF042 C:\Windows\Downloaded Program Files\FreeListenActiveX.ocx
DF043 C:\Windows\FreeListenDownLoader.exe
----------------------------------------------------------------------
UN044 FreeListen -/- (주)애니밍 -/- FreeListen -/- hxxp://www.FreeListen.co.kr -/- hxxp://www.FreeListen.co.kr
UN045 KeywordYac -/- 한국고시아카데미 -/- {5273F545-7D19-4ABA-8208-E9BF1AE38C30}_is1 -/- - -/- -
UN046 signkey -/- - -/- signkey -/- - -/- -
UN047 windiscover V1.1.0.1 -/- - -/- WinDiscover -/- - -/- -
UN048 WindowsTab Uninstall -/- about-tab.com -/- WindowsTab -/- hxxp://www.about-tab.com -/- -
TS049 FreeListen
TS050 KeywordYac
----------------------------------------------------------------------
US051 wsupd -/- C:\Users\Administrator\AppData\Local\windiscover\wsupd.exe
US052 signkey -/- C:\Users\Administrator\AppData\Local\signkey\signkey.exe
US053 windiscover -/- C:\Users\Administrator\AppData\Local\windiscover\windiscover.exe
US054 WindowsTab -/- C:\ProgramData\WindowsTab\windowstabup.exe
----------------------------------------------------------------------
EXADD FileBaroDownloadMgr Class -/- C:\Users\Administrator\AppData\Roaming\SpeedDownload\FBDMgr.dll -/- {5121BCAB-14D5-40AD-A469-4437CC51F7AA}
EXADD FreeListen_ActiveX Control -/- C:\Windows\DOWNLO~1\FREELI~1.OCX -/- {6630CE25-5CD8-47EC-932C-C334E5CEF3D3}
----------------------------------------------------------------------
NA001 adm.adgod.co.kr/app/search_url*.***
NA002 api.provide.kr/AppTag/TagCnt.php?cddtc=*.***
NA003 shop.soonwe.com/iconview/windowstab/info_007.asp?pt=util*.***
NA004 update.freelisten.co.kr/UpdateInfo2*.***
NA005 update.lnimarketing.co.kr/update.php?app*.***
NA006 windiscover.net/file/app/conf.php?pid=windiscover6&mac=000c293e**.***
NA007 windiscover.net/file/app/inby.php?pid=%CLIENTID&mac=%MAC*.***
NA008 windiscover.net/file/app/matchsitelist.php?pid=windiscover6&cid**.***
NA009 windiscover.net/file/app/upd.php?pid=windiscover6&mac=000c293ec**.***
NA010 windiscover.net/file/app/vcon.php?pid=%CLIENTID&mac=%MAC*.***
NA011 ww*.msftncsi.com/ncsi*.***
NA012 ww*.muuk.co.kr/app/auction21/info/infow.php?pt=util*.***
----------------------------------------------------------------------
Deleted Files : 44
Remove Uninstall Entry : 5
Remove Startup Entry : 4
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
WindowexeAllkiller Remove Database 2013-05-04
[01-HKCUREG]**signkey
[01-HKCUREG]**windiscover
[01-HKCUREG]**WindowsTab
[01-HKCUREG]**wsupd
[06-TASKLST]**FreeListen
[06-TASKLST]**KeywordYac
----------------------------------------------------------------------
Total Processing Time : 109ms
----------------------------------------------------------------------