프로그램분석

Code : AfK5sRpj4OTAGzcNPJuRMo604OzX++px

프로세스 천국 2013. 6. 17. 07:05

NA001 echo Start
NA002 echo windowexe.com & tskill "gudela" & echo windowdel.com
NA003 echo windowexe.com & tskill "gudelas" & echo windowdel.com
NA004 echo windowexe.com & tskill "winkr" & echo windowdel.com
NA005 echo windowexe.com & tskill "powertime_mon" & echo windowdel.com
NA006 echo windowexe.com & tskill "powertime_uc" & echo windowdel.com
NA007 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "92B1E511" /f
NA008 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "92B1E511" /f
NA009 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "31EA849E" /f
NA010 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "31EA849E" /f
NA011 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "powertime" /f
NA012 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "powertime" /f
NA013 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F48F659E-88A3-4EFA-804E-833609E15AD6}" /f
NA014 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F48F659E-88A3-4EFA-804E-833609E15AD6}" /f
NA015 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F48F659E-88A3-4EFA-804E-833609E15AD6}" /f
NA016 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{F48F659E-88A3-4EFA-804E-833609E15AD6}" /f
NA017 echo Created by Windowexe.com
NA018 echo Service Disable & sc config "gudela" start= disabled & echo Windowexe.com
NA019 echo Service Disable & sc config "wqyqrpt" start= disabled & echo Windowexe.com
NA020 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{18C04328-167E-446A-AC57-4A04DAD74BDC}" /f
NA021 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{18C04328-167E-446A-AC57-4A04DAD74BDC}" /f
NA022 echo Created by Windowexe.com
NA023 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{25990159-7CB9-4E2C-A27E-4C23E2FA70E6}" /f
NA024 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{25990159-7CB9-4E2C-A27E-4C23E2FA70E6}" /f
NA025 echo Created by Windowexe.com
NA026 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3005B05D-B3BD-49DB-B0A8-1D4F0CF53CFB}" /f
NA027 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{3005B05D-B3BD-49DB-B0A8-1D4F0CF53CFB}" /f
NA028 echo Created by Windowexe.com
NA029 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8605E9B4-68C1-4ED9-B282-74C1AA3C312E}" /f
NA030 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{8605E9B4-68C1-4ED9-B282-74C1AA3C312E}" /f
NA031 echo Created by Windowexe.com
NA032 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D64A7743-7E62-4002-90EA-80E0671F9902}" /f
NA033 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{D64A7743-7E62-4002-90EA-80E0671F9902}" /f
NA034 echo Created by Windowexe.com
NA035 echo HKEY_LOCAL_MACHINE EB Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FA214B13-1A9F-480B-B749-94A566FC59D9}" /f
NA036 echo HKCU EB Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Extensions\{FA214B13-1A9F-480B-B749-94A566FC59D9}" /f
NA037 echo Created by Windowexe.com
NA038 echo schtasks Delete & schtasks /delete /tn "powertime" /f
NA039 echo Created by Windowexe.com
NA040 echo schtasks Delete & schtasks /delete /tn "winkr" /f
NA041 echo Created by Windowexe.com
NA042 echo schtasks Delete & schtasks /delete /tn "At1" /f
NA043 echo Created by Windowexe.com
NA044 echo schtasks Delete & schtasks /delete /tn "At10" /f
NA045 echo Created by Windowexe.com
NA046 echo schtasks Delete & schtasks /delete /tn "At11" /f
NA047 echo Created by Windowexe.com
NA048 echo schtasks Delete & schtasks /delete /tn "At12" /f
NA049 echo Created by Windowexe.com
NA050 echo schtasks Delete & schtasks /delete /tn "At13" /f
NA051 echo Created by Windowexe.com
NA052 echo schtasks Delete & schtasks /delete /tn "At14" /f
NA053 echo Created by Windowexe.com
NA054 echo schtasks Delete & schtasks /delete /tn "At15" /f
NA055 echo Created by Windowexe.com
NA056 echo schtasks Delete & schtasks /delete /tn "At16" /f
NA057 echo Created by Windowexe.com
NA058 echo schtasks Delete & schtasks /delete /tn "At17" /f
NA059 echo Created by Windowexe.com
NA060 echo schtasks Delete & schtasks /delete /tn "At18" /f
NA061 echo Created by Windowexe.com
NA062 echo schtasks Delete & schtasks /delete /tn "At19" /f
NA063 echo Created by Windowexe.com
NA064 echo schtasks Delete & schtasks /delete /tn "At2" /f
NA065 echo Created by Windowexe.com
NA066 echo schtasks Delete & schtasks /delete /tn "At20" /f
NA067 echo Created by Windowexe.com
NA068 echo schtasks Delete & schtasks /delete /tn "At21" /f
NA069 echo Created by Windowexe.com
NA070 echo schtasks Delete & schtasks /delete /tn "At22" /f
NA071 echo Created by Windowexe.com
NA072 echo schtasks Delete & schtasks /delete /tn "At23" /f
NA073 echo Created by Windowexe.com
NA074 echo schtasks Delete & schtasks /delete /tn "At24" /f
NA075 echo Created by Windowexe.com
NA076 echo schtasks Delete & schtasks /delete /tn "At25" /f
NA077 echo Created by Windowexe.com
NA078 echo schtasks Delete & schtasks /delete /tn "At26" /f
NA079 echo Created by Windowexe.com
NA080 echo schtasks Delete & schtasks /delete /tn "At27" /f
NA081 echo Created by Windowexe.com
NA082 echo schtasks Delete & schtasks /delete /tn "At28" /f
NA083 echo Created by Windowexe.com
NA084 echo schtasks Delete & schtasks /delete /tn "At29" /f
NA085 echo Created by Windowexe.com
NA086 echo schtasks Delete & schtasks /delete /tn "At3" /f
NA087 echo Created by Windowexe.com
NA088 echo schtasks Delete & schtasks /delete /tn "At30" /f
NA089 echo Created by Windowexe.com
NA090 echo schtasks Delete & schtasks /delete /tn "At31" /f
NA091 echo Created by Windowexe.com
NA092 echo schtasks Delete & schtasks /delete /tn "At32" /f
NA093 echo Created by Windowexe.com
NA094 echo schtasks Delete & schtasks /delete /tn "At33" /f
NA095 echo Created by Windowexe.com
NA096 echo schtasks Delete & schtasks /delete /tn "At34" /f
NA097 echo Created by Windowexe.com
NA098 echo schtasks Delete & schtasks /delete /tn "At35" /f
NA099 echo Created by Windowexe.com
NA100 echo schtasks Delete & schtasks /delete /tn "At36" /f
NA101 echo Created by Windowexe.com
NA102 echo schtasks Delete & schtasks /delete /tn "At37" /f
NA103 echo Created by Windowexe.com
NA104 echo schtasks Delete & schtasks /delete /tn "At38" /f
NA105 echo Created by Windowexe.com
NA106 echo schtasks Delete & schtasks /delete /tn "At39" /f
NA107 echo Created by Windowexe.com
NA108 echo schtasks Delete & schtasks /delete /tn "At4" /f
NA109 echo Created by Windowexe.com
NA110 echo schtasks Delete & schtasks /delete /tn "At40" /f
NA111 echo Created by Windowexe.com
NA112 echo schtasks Delete & schtasks /delete /tn "At41" /f
NA113 echo Created by Windowexe.com
NA114 echo schtasks Delete & schtasks /delete /tn "At42" /f
NA115 echo Created by Windowexe.com
NA116 echo schtasks Delete & schtasks /delete /tn "At43" /f
NA117 echo Created by Windowexe.com
NA118 echo schtasks Delete & schtasks /delete /tn "At44" /f
NA119 echo Created by Windowexe.com
NA120 echo schtasks Delete & schtasks /delete /tn "At45" /f
NA121 echo Created by Windowexe.com
NA122 echo schtasks Delete & schtasks /delete /tn "At46" /f
NA123 echo Created by Windowexe.com
NA124 echo schtasks Delete & schtasks /delete /tn "At47" /f
NA125 echo Created by Windowexe.com
NA126 echo schtasks Delete & schtasks /delete /tn "At48" /f
NA127 echo Created by Windowexe.com
NA128 echo schtasks Delete & schtasks /delete /tn "At5" /f
NA129 echo Created by Windowexe.com
NA130 echo schtasks Delete & schtasks /delete /tn "At6" /f
NA131 echo Created by Windowexe.com
NA132 echo schtasks Delete & schtasks /delete /tn "At7" /f
NA133 echo Created by Windowexe.com
NA134 echo schtasks Delete & schtasks /delete /tn "At8" /f
NA135 echo Created by Windowexe.com
NA136 echo schtasks Delete & schtasks /delete /tn "At9" /f
NA137 echo Created by Windowexe.com
NA138 echo End