Code : GckRAJwERoXboc4qINaIhjwBvk0MC57H5rnFA6OUl/E=
----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Windows 7 Ultimate Service Pack 1(6.1.7601.65536)
Intel(R) Core(TM) i5-2450M CPU @ 2.50GHz / 2,047.49 MB
Intel64 Family 6 Model 42 Stepping 7
Date : 2013-05-29
----------------------------------------------------------------------
DF000 C:\Program Files (x86)\InfoSave\AddScheduler.exe
DF001 C:\Program Files (x86)\InfoSave\filter.dll
DF002 C:\Program Files (x86)\InfoSave\InfoSave.exe
DF003 C:\Program Files (x86)\InfoSave\InfoSaveMtr.exe
DF004 C:\Program Files (x86)\InfoSave\InfoSaveuck.exe
DF005 C:\Program Files (x86)\InfoSave\RCEngine.dll
DF006 C:\Program Files (x86)\InfoSave\RepairCode.exe
DF007 C:\Program Files (x86)\IProtect\anyBoad.dll
DF008 C:\Program Files (x86)\IProtect\IProtect.exe
DF009 C:\Program Files (x86)\IProtect\IProtectUpdate.exe
DF010 C:\Program Files (x86)\IProtect\nhopen.dll
DF011 C:\Program Files (x86)\openkeyword\OpenKeyword.exe
DF012 C:\Program Files (x86)\openkeyword\OpenKeywordAgent.exe
DF013 C:\Program Files (x86)\openkeyword\OpenKeywordC.exe
DF014 C:\Program Files (x86)\openkeyword\uninst.exe
DF015 C:\Program Files (x86)\PCO\PCO.exe
DF016 C:\Program Files (x86)\PCO\PCOUpdate.exe
DF017 C:\Program Files (x86)\premiumpc\premiumpc.exe
DF018 C:\Program Files (x86)\premiumpc\premiumpcse.exe
DF019 C:\Program Files (x86)\premiumpc\premiumpcU.exe
DF020 C:\Program Files (x86)\premiumpc\uninst_premiumpc.exe
DF021 C:\Program Files (x86)\VaccineSecure\db\filter.dll
DF022 C:\Program Files (x86)\VaccineSecure\db\inter.dll
DF023 C:\Program Files (x86)\VaccineSecure\etc\VSFilterDriver.SYS
DF024 C:\Program Files (x86)\VaccineSecure\etc\vsMon.exe
DF025 C:\Program Files (x86)\VaccineSecure\etc\VSmonRemote.dll
DF026 C:\Program Files (x86)\VaccineSecure\etc\vsReg.exe
DF027 C:\Program Files (x86)\VaccineSecure\VaccineSecure.exe
DF028 C:\Program Files (x86)\VaccineSecure\VSAutoUpdate.exe
DF029 C:\Program Files (x86)\VaccineSecure\VSEngine.dll
DF030 C:\Program Files (x86)\windoguide\wgbho.dll
DF031 C:\Program Files (x86)\windoguide\windgdo.dll
DF032 C:\Program Files (x86)\windoguide\windoguide.exe
DF033 C:\Program Files (x86)\windoguide\windoguideagent.exe
DF034 C:\Program Files (x86)\Window Network Manager\cCommon.ocx
DF035 C:\Program Files (x86)\Window Network Manager\uninst.exe
DF036 C:\Program Files (x86)\Window Network Manager\WindowNetworkManager.exe
DF037 C:\Program Files (x86)\Windows Utility Update\pidadd.dll
DF038 C:\Program Files (x86)\Windows Utility Update\wuu.exe
DF039 C:\ProgramData\iniweblink\INIWebCleaner.exe
DF040 C:\ProgramData\iniweblink\weblink.exe
DF041 C:\ProgramData\iniweblink\weblinkup.exe
DF042 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\백신시큐어\백신시큐어 제거.lnk
DF043 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\백신시큐어\백신시큐어.lnk
DF044 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\인포세이브\인포세이브 제거.lnk
DF045 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\인포세이브\인포세이브.lnk
DF046 C:\ProgramData\Microsoft\Windows\Templates\VirtualBox-4_.1_.6-74713-Win[1]_.exe
DF047 C:\ProgramData\WindowsTab\trash\windowstab_move.exe
DF048 C:\ProgramData\WindowsTab\windowstab.exe
DF049 C:\ProgramData\WindowsTab\windowstab_move.exe
DF050 C:\ProgramData\WindowsTab\windowstabup.exe
DF051 C:\Users\Administrator\AppData\Local\signkey\e_signkey.exe
DF052 C:\Users\Administrator\AppData\Local\signkey\signkey.exe
DF053 C:\Users\Administrator\AppData\Local\signkey\skun.exe
DF054 C:\Users\Administrator\AppData\Local\Temp\321408.exe
DF055 C:\Users\Administrator\AppData\Local\windowstab\windowstab.exe
DF056 C:\Users\Administrator\AppData\Local\windowstab\windowstab_mon.exe
DF057 C:\Users\Administrator\AppData\Local\windowstab\windowstab_uc.exe
DF058 C:\Users\Administrator\AppData\Local\windowstab\windowstab_unins.exe
DF059 C:\Users\Administrator\AppData\Roaming\11번가.lnk
DF060 C:\Users\Administrator\AppData\Roaming\G마켓.lnk
DF061 C:\Users\Administrator\AppData\Roaming\loa7\loa7.exe
DF062 C:\Users\Administrator\AppData\Roaming\loa7\loa7agent.exe
DF063 C:\Users\Administrator\AppData\Roaming\loa7\uninst.exe
DF064 C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\11번가.lnk
DF065 C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\G마켓.lnk
DF066 C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\옥션.lnk
DF067 C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\11번가.lnk
DF068 C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\G마켓.lnk
DF069 C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\옥션.lnk
DF070 C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\백신시큐어.lnk
DF071 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\premiumpc\Homepage.url
DF072 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\premiumpc\premiumpc 삭제.lnk
DF073 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\premiumpc\premiumpc.lnk
DF074 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\windowstab_uc.lnk
DF075 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\라이브온에어\라이브온에어.lnk
DF076 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\라이브온에어\홈페이지.url
DF077 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\백신시큐어.lnk
DF078 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\IProtectInstall_9_193.exe
DF079 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\PCOInstall_4.exe
DF080 C:\Users\Administrator\AppData\Roaming\revealer\revealer.exe
DF081 C:\Users\Administrator\AppData\Roaming\revealer\revealertop.dll
DF082 C:\Users\Administrator\AppData\Roaming\revealer\revealerul.exe
DF083 C:\Users\Administrator\AppData\Roaming\옥션.lnk
DF084 C:\Users\Administrator\Desktop\ 로또 번호 30억의 비밀.url
DF085 C:\Users\Administrator\Desktop\ 무료 문자 300건 받기 문자함.url
DF086 C:\Users\Administrator\Desktop\라이브온에어.lnk
DF087 C:\Users\Administrator\Desktop\최신영화 무료다운로드.url
DF088 C:\Users\Administrator\Favorites\ 무료 문자 300건 받기 문자함.url
DF089 C:\Users\Administrator\Favorites\ 오늘만 무료 어플 다운 APPA.url
DF090 C:\Users\Administrator\Favorites\11번가.url
DF091 C:\Users\Administrator\Favorites\G마켓.url
DF092 C:\Users\Administrator\Favorites\Links\11번가.url
DF093 C:\Users\Administrator\Favorites\Links\G마켓.url
DF094 C:\Users\Administrator\Favorites\Links\옥션.url
DF095 C:\Users\Administrator\Favorites\옥션.url
DF096 C:\Users\Administrator\Favorites\최신영화 무료다운로드.url
DF097 C:\Windows\SysWOW64\cCommon.ocx
DF098 C:\Windows\SysWOW64\MSCMCKO.DLL
DF099 C:\Windows\SysWOW64\MSCOMCTL.OCX
DF100 C:\Windows\SysWOW64\MSWINSCK.OCX
DF101 C:\Windows\SysWOW64\VB6STKIT.DLL
DF102 C:\Windows\winuserdata.exe
----------------------------------------------------------------------
SC103 premiumpc Update Service -/- premiumpc Support Service -/- "C:\Windows\winuserdata.exe" /update
SC104 premiumpcService -/- premiumpc Service -/- C:\Program Files (x86)\premiumpc\premiumpcse.exe
SC105 windowstab_mon -/- Windows Tab Manager -/- C:\Users\Administrator\AppData\Local\windowstab\windowstab_mon.exe
----------------------------------------------------------------------
UN106 인포세이브 -/- InfoSave -/- C:\Program Files (x86)\InfoSave\Uninstall.exe
UN107 라이브온에어 -/- Purelab -/- loa7 -/- C:\Users\Administrator\AppData\Roaming\loa7\uninst.exe -/- hxxp://ww*.liveonair.net -/- hxxp://ww*.liveonair.net
UN108 OpenKeyword -/- Maroin -/- OpenKeyword -/- C:\Program Files (x86)\OpenKeyword\uninst.exe -/- hxxp://ww*.openkeyword.co.kr -/- hxxp://ww*.openkeyword.co.kr
UN109 premiumpc -/- AKorea -/- premiumpc -/- C:\Program Files (x86)\premiumpc\uninst_premiumpc.exe -/- hxxp://ww*.premiumpc.co.kr -/- hxxp://ww*.premiumpc.co.kr
UN110 Revealing Top Search App -/- revealerApp_uninstall -/- C:\Users\Administrator\AppData\Roaming\revealer\uninstall.exe
UN111 백신시큐어 -/- VaccineSecureMain -/- C:\Program Files (x86)\VaccineSecure\Uninstall.exe
UN112 Window Guide -/- Window Guide -/- C:\Program Files (x86)\windoguide\uninstall.exe
UN113 Window Network Manager -/- Window Network Manager -/- Window Network Manager Install -/- C:\Program Files (x86)\Window Network Manager\uninst.exe -/- Window Network Manager Group
UN114 Windows Utility Update -/- Windows Utility Update -/- C:\Program Files (x86)\Windows Utility Update\uninstall.exe
UN115 winuserdata -/- winuserdata -/- C:\Windows\winuserdata.exe /delete -/- hxxp://premiumpc.co.kr -/- hxxp://premiumpc.co.kr
UN116 IProtect -/- JNC -/- {3ED12C21-18E3-4401-B4DA-4D96F0565CFA}_is1 -/- C:\Program Files (x86)\IProtect\unins000.exe
UN117 PC Clean Optimizer -/- 애드윌커뮤니케이션즈 -/- {5273F545-7D19-4ABA-8208-E9BF1AE38C30}_is1 -/- C:\Program Files (x86)\PCO\unins000.exe
----------------------------------------------------------------------
TS118 InfoSave -/- "C:\Program Files (x86)\InfoSave\InfoSaveuck.exe" /run2 -/- N/A
TS119 InfoSaveA -/- "C:\Program Files (x86)\InfoSave\InfoSave.exe" /run0 -/- N/A
TS120 IProtect -/- "C:\Program Files (x86)\IProtect\IProtectUpdate.exe" -/- N/A
TS121 OKSTART -/- "C:\Program Files (x86)\OpenKeyword\OpenKeywordAgent.exe" "/RUN" -/- N/A
TS122 PC_Clean_Optimizer -/- "C:\Program Files (x86)\PCO\PCOUpdate.exe" -/- N/A
TS123 Window_Network_Manager -/- "C:\Program Files (x86)\Window Network Manager\WindowNetworkManager.exe" -/- N/A
TS124 백신시큐어 실행 -/- C:\Program Files (x86)\VaccineSecure\VaccineSecure.exe /Boot -/- 코드클리닉 실행
----------------------------------------------------------------------
US125 iniweblink -/- C:\ProgramData\iniweblink\weblinkup.exe
US126 InfoSave -/- C:\Program Files (x86)\InfoSave\InfoSave.exe /run1
US127 signkey -/- C:\Users\Administrator\AppData\Local\signkey\signkey.exe
US128 revealerApp -/- C:\Users\Administrator\AppData\Roaming\revealer\revealer.exe Runcmd
US129 revealerApps -/- C:\Users\Administrator\AppData\Roaming\revealer\revealerul.exe
US130 WINDOWSTAB_UC -/- C:\Users\Administrator\AppData\Local\windowstab\windowstab_uc.exe /run
US131 loa7 -/- C:\Users\Administrator\AppData\Roaming\loa7\loa7agent.exe
US132 wuu -/- C:\Program Files (x86)\Windows Utility Update\wuu.exe
US133 windoguide -/- C:\Program Files (x86)\windoguide\windoguide.exe
US134 windoguideagent -/- C:\Program Files (x86)\windoguide\windoguideagent.exe
US135 windoguideopt -/- C:\Program Files (x86)\windoguide\windopt.exe
LS136 Window Network Manager -/- C:\Program Files (x86)\Window Network Manager\WindowNetworkManager.exe
LS137 WINDOWSTAB_UC -/- C:\Users\Administrator\AppData\Local\windowstab\windowstab_uc.exe /run
----------------------------------------------------------------------
BH138 windoguide Class -/- C:\Program Files (x86)\windoguide\wgbho.dll -/- {46E54E77-A5AE-4AB0-B27F-22DA3F95FAD6}
BH139 Revealing Top Search App -/- C:\Users\Administrator\AppData\Roaming\revealer\revealertop.dll -/- {5DE6D47F-8805-4AB9-BD32-6D1D13F43C14}
BH140 windgdo -/- c:\PROGRA~2\WINDOG~1\windgdo.dll -/- {CC01FC6C-ED00-4E28-BCBC-F4AD5F9F0D7D}
EXADD Shockwave Flash Object -/- C:\Windows\system32\Macromed\Flash\Flash64_11_7_700_169.ocx -/- {D27CDB6E-AE6D-11CF-96B8-444553540000}
EXADD windoguide Class -/- C:\Program Files (x86)\windoguide\wgbho.dll -/- {46E54E77-A5AE-4AB0-B27F-22DA3F95FAD6}
EXADD Revealing Top Search App -/- C:\Users\Administrator\AppData\Roaming\revealer\revealertop.dll -/- {5DE6D47F-8805-4AB9-BD32-6D1D13F43C14}
EXADD windgdo -/- c:\PROGRA~2\WINDOG~1\windgdo.dll -/- {CC01FC6C-ED00-4E28-BCBC-F4AD5F9F0D7D}
EXADD Shockwave Flash Object -/- C:\Windows\SysWOW64\Macromed\Flash\Flash32_11_7_700_169.ocx -/- {D27CDB6E-AE6D-11CF-96B8-444553540000}
EXADD ISDownLoadMgr Class -/- C:\Program Files (x86)\insafeclient\ISMgr.dll -/- {E3EEE006-BDA1-462B-94FA-9E2C79EEF09A}
----------------------------------------------------------------------
NA001 api.windoguide.com/version*.***
NA002 file.muuk.co.kr/app/windowstab/utiltop/windowstab_uc_up*.***
NA003 gdata.youtube.com/feeds/api/videos?max-results=30&q=%ED%95%B8%E**.***
NA004 googleads.g.doubleclick.net/pagead/ads?client=ca-pub-6168961748**.***
NA005 openapi.naver.com/search?key=a1252f63a0d2a9e100e85a534da131d8&q**.***
NA006 pagead2.googlesyndication.com/pagead/imgad?id=CICAgIDQw-PINhCsA**.***
NA007 pagead2.googlesyndication.com/pagead/inject_object_di*.***
NA008 premiumpc.co.kr/settle.php?strID=post&strPC=00:0C:29:61:CE:E7&s**.***
NA009 qcounter.co.kr/LogReceiver/LR.log?kind=0&ist_yn=0&ptn_name=193&**.***
NA010 rank.search.naver.net/nexearch_utf8_v2.js?sm=tab_lve&callcntdum**.***
NA011 report.windoguide.comreport.windoguide.com/report_exe.ph**.***
NA012 report.windoguide.comreport.windoguide.com/report_exe_ag**.***
NA013 revealer.co.kr/cnt/index.php?pid=ulapp08&ty*.***
NA014 revealer.co.kr/revealer/update/ad/ulapp08/check_h*.***
NA015 revealer.co.kr/revealer/update/ad/ulapp08/inst*.***
NA016 search.twitter.com/search.atom?q=%ED%95%B8%EC%A6%88%EC%BD%94%ED**.***
NA017 sub.openkeyword.co.kr/opapp/postmedia1/app/update/update*.***
NA018 t.openpotservice.com/AppTag/OptionCnt*.***
NA019 ul.revealer.co.kr/check/ulapp/update/revealing*.***
NA020 update.adplatform.kr/update.php?a*.***
NA021 update.info-save.co.kr/partner/partner_info*.***
NA022 update.info-save.co.kr/update_data*.***
NA023 update.info-save.co.kr/version*.***
NA024 update.premiumpc.co.kr*.***
NA025 update.searchpop.co.kr/?med*.***
NA026 update.ucfdb.co.kr/version/except/excp*.***
NA027 update.VaccineSecure.co.kr/Update_ini/VaccineSecure/autoupdate.**.***
NA028 werpingad.com/partner/c.php?m=b&mac=000C2961CEE7&p=codene*.***
NA029 werpingad.com/partner/dl*.***
NA030 werpingad.com/partner/s*.***
NA031 werpingad.com/partner/x*.***
NA032 withblogger.net/updateserver/wnm/%5Csetting*.***
NA033 wuu.co.kr/request_update/request.php?action=execute&mac=00:0c:2**.***
NA034 wuu.co.kr/request_update/version*.***
NA035 ww*.liveonair.net/app/loa7/advert/config*.***
NA036 ww*.liveonair.net/app/loa7/advert/popup.*.***
NA037 ww*.liveonair.net/app/loa7/analytics/request/count.php?mode=loa**.***
NA038 ww*.liveonair.net/app/loa7/update/update*.***
NA039 ww*.msftncsi.com/ncsi*.***
NA040 ww*.muuk.co.kr/app/windowstab/windowstab.php?kind=service&pt=ut**.***
NA041 ww*.muuk.co.kr/app/windowstab/windowstab.php?kind=tab&pt=utilto**.***
NA042 ww*.muuk.co.kr/app/windowstab/windowstab.php?kind=update&pt=uti**.***
NA043 ww*.targetkeyword.co.kr/app/info/info_001*.***
NA044 ww*.targetkeyword.co.kr/app/iniweblink/info/info.php?u=P022&o=6**.***
----------------------------------------------------------------------
Deleted Files : 103
Remove Service : 3
Remove Uninstall Entry : 12
Remove Startup Entry : 13
Remove Browser Helper Object : 3
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
WindowexeAllkiller Remove Database 2013-05-29
[01-HKCUREG]**InfoSave
[01-HKCUREG]**iniweblink
[01-HKCUREG]**loa7
[01-HKCUREG]**revealerApp
[01-HKCUREG]**revealerApps
[01-HKCUREG]**signkey
[01-HKCUREG]**windoguide
[01-HKCUREG]**windoguideagent
[01-HKCUREG]**windoguideopt
[01-HKCUREG]**WINDOWSTAB_UC
[01-HKCUREG]**wuu
[02-HKLMREG]**Window Network Manager
[02-HKLMREG]**WINDOWSTAB_UC
[03-BHOCLSD]**{46E54E77-A5AE-4AB0-B27F-22DA3F95FAD6}
[03-BHOCLSD]**{5DE6D47F-8805-4AB9-BD32-6D1D13F43C14}
[03-BHOCLSD]**{CC01FC6C-ED00-4E28-BCBC-F4AD5F9F0D7D}
[05-SERVICE]**premiumpc Update Service
[05-SERVICE]**premiumpcService
[05-SERVICE]**windowstab_mon
[06-TASKLST]**InfoSave
[06-TASKLST]**InfoSaveA
[06-TASKLST]**IProtect
[06-TASKLST]**OKSTART
[06-TASKLST]**PC_Clean_Optimizer
[06-TASKLST]**Window_Network_Manager
[06-TASKLST]**백신시큐어 실행
----------------------------------------------------------------------
Total Processing Time : 622ms
----------------------------------------------------------------------