프로그램분석

Code : +AVb9Olc1Za9VQqa1zzPFwJTI1pLSMC1A0m4WSrTDNU=

프로세스 천국 2013. 8. 9. 11:01

[00-PROCESS]**alg -/- C:\WINDOWS\System32\alg.exe
[00-PROCESS]**aspnet_state -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
[00-PROCESS]**cartcon -/- C:\Program Files\cartcon\cartcon.exe
[00-PROCESS]**ccStart -/- C:\Program Files\cartcon\ccStart.exe
[00-PROCESS]**cisvc -/- C:\WINDOWS\system32\cisvc.exe
[00-PROCESS]**clipsrv -/- C:\WINDOWS\system32\clipsrv.exe
[00-PROCESS]**ctfmon -/- C:\WINDOWS\system32\ctfmon.exe
[00-PROCESS]**DaumCleaner -/- C:\Program Files\Daum\Cleaner\DaumCleaner.exe
[00-PROCESS]**DaumStationService -/- C:\Program Files\Daum\DaumStation\DaumStationService.exe
[00-PROCESS]**dllhost -/- C:\WINDOWS\system32\dllhost.exe
[00-PROCESS]**downhelper_se -/- C:\WINDOWS\system32\downhelper_se.exe
[00-PROCESS]**Explorer -/- C:\WINDOWS\Explorer.EXE
[00-PROCESS]**flashlinker-se -/- C:\WINDOWS\system32\flashlinker-se.exe
[00-PROCESS]**FlashPlayerUpdateService -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[00-PROCESS]**IEXPLORE -/- C:\Program Files\Internet Explorer\IEXPLORE.EXE
[00-PROCESS]**imapi -/- C:\WINDOWS\system32\imapi.exe
[00-PROCESS]**IMKRMIG -/- C:\Program Files\Common Files\Microsoft Shared\IME12\IMEKR\IMKRMIG.EXE
[00-PROCESS]**infocard -/- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
[00-PROCESS]**keypang -/- C:\Program Files\KeyPang\keypang.exe
[00-PROCESS]**LMS -/- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
[00-PROCESS]**locator -/- C:\WINDOWS\system32\locator.exe
[00-PROCESS]**lsass -/- C:\WINDOWS\system32\lsass.exe
[00-PROCESS]**mnmsrvc -/- C:\WINDOWS\system32\mnmsrvc.exe
[00-PROCESS]**mscorsvw -/- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
[00-PROCESS]**mscorsvw -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
[00-PROCESS]**msdtc -/- C:\WINDOWS\system32\msdtc.exe
[00-PROCESS]**msiexec -/- C:\WINDOWS\system32\msiexec.exe
[00-PROCESS]**netdde -/- C:\WINDOWS\system32\netdde.exe
[00-PROCESS]**npkcmsvc -/- C:\WINDOWS\system32\npkcmsvc.exe
[00-PROCESS]**nvsvc32 -/- C:\WINDOWS\system32\nvsvc32.exe
[00-PROCESS]**ODSERV -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[00-PROCESS]**OSE -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[00-PROCESS]**PresentationFontCache -/- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
[00-PROCESS]**ProcService -/- C:\Documents and Settings\Administrator\My Documents\ProcessClean\ProcService.exe
[00-PROCESS]**realtyman -/- C:\Documents and Settings\Administrator\Application Data\wingrealtyman\realtyman.exe
[00-PROCESS]**realtymans -/- C:\Documents and Settings\Administrator\Application Data\wingrealtyman\realtymans.exe
[00-PROCESS]**RollingPop_E -/- C:\Documents and Settings\Administrator\Application Data\RollingPop\RollingPop_E.exe
[00-PROCESS]**RollingPop_S -/- C:\Documents and Settings\Administrator\Application Data\RollingPop\RollingPop_S.exe
[00-PROCESS]**rsvp -/- C:\WINDOWS\system32\rsvp.exe
[00-PROCESS]**SCardSvr -/- C:\WINDOWS\System32\SCardSvr.exe
[00-PROCESS]**services -/- C:\WINDOWS\system32\services.exe
[00-PROCESS]**sessmgr -/- C:\WINDOWS\system32\sessmgr.exe
[00-PROCESS]**smlogsvc -/- C:\WINDOWS\system32\smlogsvc.exe
[00-PROCESS]**smss -/- C:\WINDOWS\System32\smss.exe
[00-PROCESS]**spoolsv -/- C:\WINDOWS\system32\spoolsv.exe
[00-PROCESS]**svchost -/- C:\WINDOWS\system32\svchost.exe
[00-PROCESS]**tamguard -/- C:\Documents and Settings\Administrator\Application Data\theam\common\bin\tamguard.exe
[00-PROCESS]**TheAm -/- C:\Documents and Settings\Administrator\Application Data\theam\common\bin\TheAm.exe
[00-PROCESS]**tlntsvr -/- C:\WINDOWS\system32\tlntsvr.exe
[00-PROCESS]**UNS -/- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
[00-PROCESS]**ups -/- C:\WINDOWS\System32\ups.exe
[00-PROCESS]**vssvc -/- C:\WINDOWS\System32\vssvc.exe
[00-PROCESS]**WinCloud -/- C:\Program Files\mFile.co.kr\mFile(fast)\WinCloud.exe
[00-PROCESS]**winlogon -/- C:\WINDOWS\system32\winlogon.exe
[00-PROCESS]**winnetplus -/- C:\Program Files\FileNori\winnetplus.exe
[00-PROCESS]**wmiapsrv -/- C:\WINDOWS\system32\wbem\wmiapsrv.exe
[00-PROCESS]**WPFFontCache_v0400 -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
[00-PROCESS]**wuauclt -/- C:\WINDOWS\system32\wuauclt.exe
[01-HKCUREG]**cartcon -/- C:\Program Files\cartcon\ccStart.exe UPDATE
[01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[01-HKCUREG]**DaumCleaner -/- C:\Program Files\Daum\Cleaner\DaumCleaner.exe /T
[01-HKCUREG]**guardtam -/- C:\Documents and Settings\Administrator\Application Data\theam\common\bin\tamguard.exe
[01-HKCUREG]**KeyPang -/- C:\Program Files\KeyPang\keypang.exe
[01-HKCUREG]**Korean IME Migration -/- C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE
[01-HKCUREG]**Kp -/- C:\Program Files\kpupdate\kpupdate.exe
[01-HKCUREG]**NvCplDaemon -/- RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dllNvStartup
[01-HKCUREG]**tamgrd -/- C:\Documents and Settings\Administrator\Application Data\theam\common\bin\tamguard.exe
[01-HKCUREG]**TheAM -/- C:\Documents and Settings\Administrator\Application Data\theam\common\bin\TheAm.exe
[02-HKLMREG]**cartcon -/- C:\Program Files\cartcon\ccStart.exe UPDATE
[02-HKLMREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[02-HKLMREG]**DaumCleaner -/- C:\Program Files\Daum\Cleaner\DaumCleaner.exe /T
[02-HKLMREG]**guardtam -/- C:\Documents and Settings\Administrator\Application Data\theam\common\bin\tamguard.exe
[02-HKLMREG]**KeyPang -/- C:\Program Files\KeyPang\keypang.exe
[02-HKLMREG]**Korean IME Migration -/- C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE
[02-HKLMREG]**Kp -/- C:\Program Files\kpupdate\kpupdate.exe
[02-HKLMREG]**NvCplDaemon -/- RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dllNvStartup
[02-HKLMREG]**tamgrd -/- C:\Documents and Settings\Administrator\Application Data\theam\common\bin\tamguard.exe
[02-HKLMREG]**TheAM -/- C:\Documents and Settings\Administrator\Application Data\theam\common\bin\TheAm.exe
[03-BHOCLSD]**IEHlprObj Class -/- C:\WINDOWS\system32\kakutk.dll -/- {AB705622-B25B-491B-A6BF-4A46FDDBC88E}
[05-SERVICE]**AdobeFlashPlayerUpdateSvc -/- Adobe Flash Player Update Service -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[05-SERVICE]**DaumStationService -/- DaumStationService -/- C:\Program Files\Daum\DaumStation\DaumStationService.exe
[05-SERVICE]**downhelper Update Service -/- downhelper Support Service -/- C:\WINDOWS\system32\downhelper_se.exe
[05-SERVICE]**flashlinkerservice -/- Flashlinker Service -/- C:\WINDOWS\system32\flashlinker-se.exe
[05-SERVICE]**hfikexsfrue -/- hfikexsfrue -/- C:\WINDOWS\System32\svchost.exe -/- C:\Program Files\hfikexsfrue\hfikexsfrue.dll
[05-SERVICE]**HwRunS -/- HowCodec Service -/- C:\PROGRA~1\howcodec\Howcodecsvc.exe
[05-SERVICE]**ismsvc -/- Windows ISM -/- C:\Program Files\Windows ISM\ismsvc.exe
[05-SERVICE]**ismsvc32 -/- INSAFE Client 1.0 -/- C:\Program Files\insafeclient\ismsvc.exe
[05-SERVICE]**kohwpxrl -/- kohwpxrl -/- C:\WINDOWS\System32\svchost.exe -/- C:\Program Files\kohwpxrl\kohwpxrl.dll
[05-SERVICE]**KongGa -/- 무료만화(KongGa) -/- C:\Program Files\KongGa\KGAChkSvc.exe
[05-SERVICE]**LMS -/- Intel(R) Management and Security Application Local Management Service -/- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
[05-SERVICE]**napagent -/- Network Access Protection Agent -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\System32\qagentrt.dll
[05-SERVICE]**NetTcpPortSharing -/- Net.Tcp Port Sharing Service -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
[05-SERVICE]**npkcmsvc -/- npkcmsvc -/- C:\WINDOWS\system32\npkcmsvc.exe
[05-SERVICE]**nvsvc -/- NVIDIA Display Driver Service -/- C:\WINDOWS\system32\nvsvc32.exe
[05-SERVICE]**odserv -/- Microsoft Office Diagnostics Service -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[05-SERVICE]**ose -/- Office Source Engine -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[05-SERVICE]**Process Clean Service -/- Process Clean Service -/- C:\Documents and Settings\Administrator\My Documents\ProcessClean\ProcService.exe
[05-SERVICE]**realtyman -/- Microsoft AD WS -/- C:\Documents and Settings\Administrator\Application Data\wingrealtyman\realtymans.exe
[05-SERVICE]**RollingPop_Service -/- RollingPop_Service -/- C:\Documents and Settings\Administrator\Application Data\RollingPop\RollingPop_S.exe ROLL02
[05-SERVICE]**RunS -/- MultidownLoad Service -/- C:\Documents and Settings\Administrator\APPLIC~1\MULTID~1\MultiDownLoadSvc.exe
[05-SERVICE]**smjuajjnpa -/- smjuajjnpa -/- C:\WINDOWS\System32\svchost.exe -/- C:\Program Files\smjuajjnpa\smjuajjnpa.dll
[05-SERVICE]**tnrgmij -/- tnrgmij -/- C:\WINDOWS\System32\svchost.exe -/- C:\Program Files\tnrgmij\tnrgmij.dll
[05-SERVICE]**uazwcfpwo -/- uazwcfpwo -/- C:\WINDOWS\System32\svchost.exe -/- C:\Program Files\uazwcfpwo\uazwcfpwo.dll
[05-SERVICE]**UNS -/- Intel(R) Management and Security Application User Notification Service -/- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
[05-SERVICE]**WinCloud -/- WinCloud -/- C:\Program Files\mFile.co.kr\mFile(fast)\WinCloud.exe
[05-SERVICE]**WinnetPlusService -/- WinnetPlusService -/- C:\Program Files\FileNori\winnetplus.exe
[05-SERVICE]**WPFFontCache_v0400 -/- Windows Presentation Foundation Font Cache 4.0.0.0 -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
[05-SERVICE]**ymlhkoqru -/- ymlhkoqru -/- C:\WINDOWS\System32\svchost.exe -/- C:\Program Files\ymlhkoqru\ymlhkoqru.dll
[05-SERVICE]**zuqcfzyo -/- zuqcfzyo -/- C:\WINDOWS\System32\svchost.exe -/- C:\Program Files\zuqcfzyo\zuqcfzyo.dll