프로그램분석

Code : K8Cqtfl26QTip51OnmTqr4DP0cNO7EHM3NFQsX/9BDxoRUOFIIOMvQ==

프로세스 천국 2013. 6. 22. 21:53

[00-PROCESS]**asperacentral -/- C:\Program Files\Aspera\Aspera Central\bin\asperacentral.exe
[00-PROCESS]**asperasync -/- C:\Program Files\Aspera\Aspera Scp\bin\asperasync.exe
[00-PROCESS]**aspnet_state -/- C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
[00-PROCESS]**BDRIntSetup -/- C:\Documents and Settings\Administrator\Desktop\BDRIntSetup.exe
[00-PROCESS]**BDRLive -/- C:\Program Files\ZenithBDR\BDRLive.exe
[00-PROCESS]**BDRScheduler -/- C:\Program Files\ZenithBDR\BDRScheduler.exe
[00-PROCESS]**CheckMD5 -/- C:\Program Files\ZenithBDR\CheckMD5.exe
[00-PROCESS]**cidaemon -/- C:\WINDOWS\system32\cidaemon.exe
[00-PROCESS]**COLOPostFile -/- C:\Program Files\ZenithBDR\COLOPostFile.exe
[00-PROCESS]**COLOWebpost -/- C:\Program Files\ZenithBDR\COLOWebpost.exe
[00-PROCESS]**Dfssvc -/- C:\WINDOWS\system32\Dfssvc.exe
[00-PROCESS]**DMPHelpDesk -/- C:\Program Files\SAAZOD\DMPHelpDesk.exe
[00-PROCESS]**IEXPLORE -/- C:\Program Files\Internet Explorer\IEXPLORE.EXE
[00-PROCESS]**ImageManager -/- C:\Program Files\Zenith\ImageManager\ImageManager.exe
[00-PROCESS]**irsetup -/- C:\Documents and Settings\Administrator\Local Settings\Temp\2\_ir_sf7_temp_1\irsetup.exe
[00-PROCESS]**ismserv -/- C:\WINDOWS\System32\ismserv.exe
[00-PROCESS]**llssrv -/- C:\WINDOWS\System32\llssrv.exe
[00-PROCESS]**LMIGuardianSvc -/- C:\Program Files\LogMeIn\x64\LMIGuardianSvc.exe
[00-PROCESS]**LogMeIn -/- C:\Program Files\LogMeIn\x64\LogMeIn.exe
[00-PROCESS]**LogMeInSystray -/- C:\Program Files\LogMeIn\x64\LogMeInSystray.exe
[00-PROCESS]**mainConsole -/- C:\Program Files\SAAZOD\mainConsole.exe
[00-PROCESS]**mscorsvw -/- C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
[00-PROCESS]**NOTEPAD -/- C:\WINDOWS\system32\NOTEPAD.EXE
[00-PROCESS]**ntfrs -/- C:\WINDOWS\system32\ntfrs.exe
[00-PROCESS]**OSE -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[00-PROCESS]**QPMD5RECAlerts -/- C:\Program Files\ZenithBDR\QPMD5RECAlerts.exe
[00-PROCESS]**RaMaint -/- C:\Program Files\LogMeIn\x64\RaMaint.exe
[00-PROCESS]**rdpclip -/- C:\WINDOWS\system32\rdpclip.exe
[00-PROCESS]**RMHLPDSK -/- C:\Program Files\SAAZOD\RMHLPDSK.exe
[00-PROCESS]**RSoPProv -/- C:\WINDOWS\system32\RSoPProv.exe
[00-PROCESS]**rtdrHlpDk -/- C:\Program Files\SAAZOD\zRealTime\rtdrHlpDk.exe
[00-PROCESS]**rtHlpDk -/- C:\Program Files\SAAZOD\zRealTime\rtHlpDk.exe
[00-PROCESS]**rundll32 -/- C:\WINDOWS\system32\rundll32.exe
[00-PROCESS]**SAAZappr -/- C:\Program Files\SAAZOD\zRealTime\SAAZappr.exe
[00-PROCESS]**SAAZapsc -/- C:\Program Files\SAAZOD\zRealTime\SAAZapsc.exe
[00-PROCESS]**SAAZMSMACTL -/- C:\Program Files\SAAZOD\SAAZMSMACTL.EXE
[00-PROCESS]**SAAZPasswordVault -/- C:\Program Files\SAAZOD\SAAZPasswordVault.exe
[00-PROCESS]**SAAZRCCTL -/- C:\Program Files\SAAZOD\SAAZRCCTL.EXE
[00-PROCESS]**SAAZRemoteSupport -/- C:\Program Files\SAAZOD\SAAZRemoteSupport.exe
[00-PROCESS]**SAAZScheduler -/- C:\Program Files\SAAZOD\SAAZScheduler.exe
[00-PROCESS]**SAAZServerPlus -/- C:\Program Files\SAAZOD\SAAZServerPlus.exe
[00-PROCESS]**SAAZWatchDog -/- C:\Program Files\SAAZOD\SAAZWatchDog.exe
[00-PROCESS]**SBAMSvc -/- C:\Program Files\GFI Software\VIPRE\SBAMSvc.exe
[00-PROCESS]**SBAMTray -/- C:\Program Files\GFI Software\VIPRE\SBAMTray.exe
[00-PROCESS]**SBPIMSvc -/- C:\Program Files\GFI Software\VIPRE\SBPIMSvc.exe
[00-PROCESS]**ShadowProtect -/- C:\Program Files\zenith\zenith infotech\ShadowProtect.Exe
[00-PROCESS]**SMSvcHost -/- C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
[00-PROCESS]**sysocmgr -/- C:\WINDOWS\system32\sysocmgr.exe
[00-PROCESS]**taskmgr -/- C:\Program Files\SAAZOD\taskmgr.exe
[00-PROCESS]**tssdis -/- C:\WINDOWS\System32\tssdis.exe
[00-PROCESS]**vBoxzScm -/- C:\Program Files\SAAZOD\vBoxzScm.exe
[00-PROCESS]**wdfmgr -/- C:\WINDOWS\system32\wdfmgr.exe
[00-PROCESS]**WPFFontCache_v0400 -/- C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
[00-PROCESS]**zColoTransfer -/- C:\Program Files\ZenithBDR\zColoTransfer.exe
[00-PROCESS]**zeeAsperaSy -/- C:\Program Files\SAAZOD\zeeAsperaSy.exe
[01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[01-HKCUREG]**LogMeIn GUI -/- C:\Program Files\LogMeIn\x64\LogMeInSystray.exe
[01-HKCUREG]**NAS -/- C:\Progra~2\SAAZOD\mainConsole.exe a
[01-HKCUREG]**SBAMTray -/- C:\Program Files\GFI Software\VIPRE\SBAMTray.exe
[01-HKCUREG]**zEye -/- C:\PROGRA~2\SAAZOD\zEye.exe
[02-HKLMREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[02-HKLMREG]**LogMeIn GUI -/- C:\Program Files\LogMeIn\x64\LogMeInSystray.exe
[02-HKLMREG]**NAS -/- C:\Progra~2\SAAZOD\mainConsole.exe a
[02-HKLMREG]**SBAMTray -/- C:\Program Files\GFI Software\VIPRE\SBAMTray.exe
[02-HKLMREG]**zEye -/- C:\PROGRA~2\SAAZOD\zEye.exe
[05-SERVICE]**asperacentral -/- asperacentral -/- C:\Program Files\Aspera\Aspera Central\bin\asperacentral.exe
[05-SERVICE]**asperasync -/- asperasync -/- C:\Program Files\Aspera\Aspera Scp\bin\asperasync.exe
[05-SERVICE]**BDRLive -/- BDRLive -/- C:\PROGRA~2\ZENITH~1\BDRLive.exe
[05-SERVICE]**BDRScheduler -/- BDRScheduler -/- C:\PROGRA~2\ZENITH~1\BDRScheduler.exe
[05-SERVICE]**Dfs -/- Distributed File System -/- C:\WINDOWS\system32\Dfssvc.exe
[05-SERVICE]**Dhcp -/- DHCP Client -/- C:\WINDOWS\system32\svchost.exe -/- C:\WINDOWS\System32\dhcpcsvc.dll
[05-SERVICE]**ERSvc -/- Error Reporting Service -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\System32\ersvc.dll
[05-SERVICE]**HTTPFilter -/- HTTP SSL -/- C:\WINDOWS\System32\lsass.exe -/- C:\WINDOWS\System32\w3ssl.dll
[05-SERVICE]**IASJet -/- IAS Jet Database Access -/- C:\WINDOWS\system32\svchost.exe -/- C:\WINDOWS\system32\iasrecst.dll
[05-SERVICE]**IsmServ -/- Intersite Messaging -/- C:\WINDOWS\System32\ismserv.exe
[05-SERVICE]**kdc -/- Kerberos Key Distribution Center -/- C:\WINDOWS\System32\lsass.exe
[05-SERVICE]**LicenseService -/- License Logging -/- C:\WINDOWS\System32\llssrv.exe
[05-SERVICE]**LMIGuardianSvc -/- LMIGuardianSvc -/- C:\Program Files\LogMeIn\x64\LMIGuardianSvc.exe
[05-SERVICE]**LMIMaint -/- LogMeIn Maintenance Service -/- C:\Program Files\LogMeIn\x64\RaMaint.exe
[05-SERVICE]**LogMeIn -/- LogMeIn -/- C:\Program Files\LogMeIn\x64\LogMeIn.exe
[05-SERVICE]**NetTcpPortSharing -/- Net.Tcp Port Sharing Service -/- C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
[05-SERVICE]**NtFrs -/- File Replication -/- C:\WINDOWS\system32\ntfrs.exe
[05-SERVICE]**ose -/- Office Source Engine -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[05-SERVICE]**RSoPProv -/- Resultant Set of Policy Provider -/- C:\WINDOWS\system32\RSoPProv.exe
[05-SERVICE]**SAAZappr -/- SAAZ RMM Agent Presence-PR -/- C:\PROGRA~2\SAAZOD\zRealTime\SAAZappr.exe SAAZappr
[05-SERVICE]**SAAZapsc -/- SAAZ RMM Agent Presence-SC -/- C:\PROGRA~2\SAAZOD\zRealTime\SAAZapsc.exe SAAZapsc
[05-SERVICE]**SAAZMSMACTL -/- SAAZMSMACTL -/- C:\Program Files\SAAZOD\SAAZMSMACTL.EXE
[05-SERVICE]**SAAZPasswordVault -/- SAAZPasswordVault -/- C:\PROGRA~2\SAAZOD\SAAZPasswordVault.exe
[05-SERVICE]**SAAZRCCTL -/- SAAZRCCTL -/- C:\Program Files\SAAZOD\SAAZRCCTL.EXE
[05-SERVICE]**SAAZRemoteSupport -/- SAAZRemoteSupport -/- C:\Program Files\SAAZOD\SAAZRemoteSupport.exe
[05-SERVICE]**SAAZScheduler -/- SAAZScheduler -/- C:\PROGRA~2\SAAZOD\SAAZScheduler.exe
[05-SERVICE]**SAAZServerPlus -/- SAAZServerPlus -/- C:\Program Files\SAAZOD\SAAZServerPlus.exe
[05-SERVICE]**SAAZWatchDog -/- SAAZWatchDog -/- C:\Program Files\SAAZOD\SAAZWatchDog.exe
[05-SERVICE]**sacsvr -/- Special Administration Console Helper -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\system32\sacsvr.dll
[05-SERVICE]**SBAMSvc -/- VIPRE Antivirus -/- C:\Program Files\GFI Software\VIPRE\SBAMSvc.exe
[05-SERVICE]**SBPIMSvc -/- SB Recovery Service -/- C:\Program Files\GFI Software\VIPRE\SBPIMSvc.exe
[05-SERVICE]**StorageCraft Image Manager -/- StorageCraft Image Manager -/- C:\Program Files\Zenith\ImageManager\ImageManager.exe
[05-SERVICE]**TapiSrv -/- Telephony -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\System32\tapisrv.dll
[05-SERVICE]**TermService -/- Terminal Services -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\System32\termsrv.dll
[05-SERVICE]**TrkSvr -/- Distributed Link Tracking Server -/- C:\WINDOWS\system32\svchost.exe -/- C:\WINDOWS\system32\trksvr.dll
[05-SERVICE]**Tssdis -/- Terminal Services Session Directory -/- C:\WINDOWS\System32\tssdis.exe
[05-SERVICE]**UMWdf -/- Windows User Mode Driver Framework -/- C:\WINDOWS\system32\wdfmgr.exe
[05-SERVICE]**vBoxzScm -/- vBoxzScm -/- C:\Program Files\SAAZOD\vBoxzScm.exe
[05-SERVICE]**WPFFontCache_v0400 -/- Windows Presentation Foundation Font Cache 4.0.0.0 -/- C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
[05-SERVICE]**zColoTransfer -/- zColoTransfer -/- C:\PROGRA~2\ZENITH~1\zColoTransfer.exe
[05-SERVICE]**zeeAsperaSy -/- zeeAsperaSy -/- C:\Program Files\SAAZOD\zeeAsperaSy.exe