Code : J96EqBmHY9MSvZksYDxRqX+4etyl/yy8R2TnzIZjv9M=
[00-PROCESS]**adInstall_ad035 -/- C:\Windows\system32\adInstall_ad035.exe
[00-PROCESS]**adpaper -/- C:\Program Files\adpaper\adpaper.exe
[00-PROCESS]**adpaper_ -/- C:\Program Files\adpaper\adpaper_.exe
[00-PROCESS]**allpopsvi -/- C:\Program Files\allpopup\allpopsvi.exe
[00-PROCESS]**allpopup -/- C:\Program Files\allpopup\allpopup.exe
[00-PROCESS]**Allpopup_1010_H -/- C:\Windows\system32\Allpopup_1010_H.exe
[00-PROCESS]**clickpang -/- C:\Program Files\clickpang\clickpang.exe
[00-PROCESS]**clickpang_jabazone -/- C:\Windows\system32\clickpang_jabazone.exe
[00-PROCESS]**hcpms -/- C:\Program Files\hcpop\hcpms.exe
[00-PROCESS]**hcpop -/- C:\Program Files\hcpop\hcpop.exe
[00-PROCESS]**I_L -/- C:\Windows\system32\I_L.exe
[00-PROCESS]**infocard -/- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
[00-PROCESS]**inst_launcher_wmg008 -/- C:\Windows\system32\inst_launcher_wmg008.exe
[00-PROCESS]**jjanglotto_livepot -/- C:\Program Files\LivePOT\ad\jjanglotto_livepot.exe
[00-PROCESS]**keywordpop -/- C:\Program Files\keywordpop\keywordpop.exe
[00-PROCESS]**keywordpop_livepot -/- C:\Windows\system32\keywordpop_livepot.exe
[00-PROCESS]**LivePot -/- C:\Program Files\LivePOT\LivePot.exe
[00-PROCESS]**livepot -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\livepot.exe
[00-PROCESS]**LivePotBoot -/- C:\Program Files\LivePOT\LivePotBoot.exe
[00-PROCESS]**LivePotUpdate -/- C:\Program Files\LivePOT\LivePotUpdate.exe
[00-PROCESS]**Lotto -/- C:\Program Files\JJANGLotto\Lotto.exe
[00-PROCESS]**LottoSearch -/- C:\Program Files\JJANGLotto\LottoSearch.exe
[00-PROCESS]**LottoUpdate -/- C:\Program Files\JJANGLotto\LottoUpdate.exe
[00-PROCESS]**metablogagent -/- C:\Users\Administrator\AppData\Local\MetablogNewIssues\metablogagent.exe
[00-PROCESS]**MetablogNewIssues -/- C:\Users\Administrator\AppData\Local\MetablogNewIssues\MetablogNewIssues.exe
[00-PROCESS]**msxml4-KB973685-kor -/- C:\Program Files\LivePOT\msxml4-KB973685-kor.exe
[00-PROCESS]**PresentationFontCache -/- C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
[00-PROCESS]**svcwsmwin -/- C:\Windows\system32\svcwsmwin.exe
[00-PROCESS]**TPAutoConnSvc -/- C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe
[00-PROCESS]**U_L -/- C:\Windows\system32\U_L.exe
[00-PROCESS]**UD_L -/- C:\Windows\system32\UD_L.exe
[00-PROCESS]**VMwareService -/- C:\Program Files\VMware\VMware Tools\VMwareService.exe
[00-PROCESS]**VMwareTray -/- C:\Program Files\VMware\VMware Tools\VMwareTray.exe
[00-PROCESS]**VMwareUser -/- C:\Program Files\VMware\VMware Tools\VMwareUser.exe
[00-PROCESS]**wdrwsmsvc -/- C:\Windows\system32\wdrwsmsvc.exe
[00-PROCESS]**winsmex -/- C:\Program Files\WinsManager\winsmex.exe
[00-PROCESS]**wmpnetwk -/- C:\Program Files\Windows Media Player\wmpnetwk.exe
[01-HKCUREG]**adpaper.exe -/- C:\Program Files\adpaper\adpaper.exe
[01-HKCUREG]**adpaper_.exe -/- C:\Program Files\adpaper\adpaper_.exe
[01-HKCUREG]**clickpang.exe -/- C:\Program Files\clickpang\clickpang.exe
[01-HKCUREG]**JJANGLotto -/- C:\Program Files\JJANGLotto\LottoSearch.exe
[01-HKCUREG]**keywordpop.exe -/- C:\Program Files\keywordpop\keywordpop.exe
[01-HKCUREG]**LivePOTUpdater -/- C:\Program Files\LivePOT\LivePotBoot.exe
[01-HKCUREG]**metablogagent -/- C:\Users\Administrator\AppData\Local\MetablogNewIssues\metablogagent.exe
[01-HKCUREG]**MetablogNewIssues -/- C:\Users\Administrator\AppData\Local\MetablogNewIssues\MetablogNewIssues.exe /byboot
[01-HKCUREG]**VMware Tools -/- C:\Program Files\VMware\VMware Tools\VMwareTray.exe
[01-HKCUREG]**VMware User Process -/- C:\Program Files\VMware\VMware Tools\VMwareUser.exe
[02-HKLMREG]**adpaper.exe -/- C:\Program Files\adpaper\adpaper.exe
[02-HKLMREG]**adpaper_.exe -/- C:\Program Files\adpaper\adpaper_.exe
[02-HKLMREG]**clickpang.exe -/- C:\Program Files\clickpang\clickpang.exe
[02-HKLMREG]**JJANGLotto -/- C:\Program Files\JJANGLotto\LottoSearch.exe
[02-HKLMREG]**keywordpop.exe -/- C:\Program Files\keywordpop\keywordpop.exe
[02-HKLMREG]**LivePOTUpdater -/- C:\Program Files\LivePOT\LivePotBoot.exe
[02-HKLMREG]**metablogagent -/- C:\Users\Administrator\AppData\Local\MetablogNewIssues\metablogagent.exe
[02-HKLMREG]**MetablogNewIssues -/- C:\Users\Administrator\AppData\Local\MetablogNewIssues\MetablogNewIssues.exe /byboot
[02-HKLMREG]**VMware Tools -/- C:\Program Files\VMware\VMware Tools\VMwareTray.exe
[02-HKLMREG]**VMware User Process -/- C:\Program Files\VMware\VMware Tools\VMwareUser.exe
[03-BHOCLSD]**IEHlprObj Class -/- C:\Windows\system32\kakutk.dll -/- {AB705622-B25B-491B-A6BF-4A46FDDBC88E}
[05-SERVICE]**allpopup -/- allpopup svc -/- C:\Program Files\allpopup\allpopsvi.exe
[05-SERVICE]**hcpopwin -/- hcpopwin svc -/- C:\Program Files\hcpop\hcpms.exe
[05-SERVICE]**NetTcpPortSharing -/- Net.Tcp Port Sharing Service -/- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
[05-SERVICE]**PerfHost -/- Performance Counter DLL Host -/- C:\Windows\system32\perfhost.exe
[05-SERVICE]**TPAutoConnSvc -/- TP AutoConnect Service -/- C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe
[05-SERVICE]**VMTools -/- VMware Tools Service -/- C:\Program Files\VMware\VMware Tools\VMwareService.exe
[05-SERVICE]**vmvss -/- VMware Snapshot Provider -/- C:\Windows\system32\dllhost.exe
[05-SERVICE]**Windows WinsManager Diagnostics Service -/- Windows WinsManager Diagnostics Service -/- C:\Windows\system32\wdrwsmsvc.exe
[05-SERVICE]**WinsManager Service -/- WinsManager Service -/- C:\Windows\system32\svcwsmwin.exe