프로그램분석

Code : Bb/hkg8n4lFP50xTNvN8d2b+n67gEk4kAmIzD5LObmEDvTf2yJ/lRA==

프로세스 천국 2013. 8. 16. 22:42

[00-PROCESS]**24naq -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-46689\24naq.exe
[00-PROCESS]**aara9 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-82290\aara9.exe
[00-PROCESS]**alg -/- C:\Windows\System32\alg.exe
[00-PROCESS]**Aydcdc -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Aydcdc.exe
[00-PROCESS]**cafef9 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-15555590\cafef9.exe
[00-PROCESS]**chrome -/- C:\Program Files\Google\Chrome\Application\chrome.exe
[00-PROCESS]**dllhost -/- C:\Windows\system32\dllhost.exe
[00-PROCESS]**Dwm -/- C:\Windows\system32\Dwm.exe
[00-PROCESS]**Explorer -/- C:\Windows\Explorer.EXE
[00-PROCESS]**FWDmgr -/- C:\RECYCLER\FWDmgr.exe
[00-PROCESS]**fxssvc -/- C:\Windows\system32\fxssvc.exe
[00-PROCESS]**GoogleUpdate -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[00-PROCESS]**IDMan -/- C:\Program Files\Internet Download Manager\IDMan.exe
[00-PROCESS]**inetb123 -/- c:\recycler\s-1-5-21-0243556031-888888379-781863308-121921\inetb123.exe
[00-PROCESS]**infocard -/- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
[00-PROCESS]**Iydcdk -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Iydcdk.exe
[00-PROCESS]**locator -/- C:\Windows\system32\locator.exe
[00-PROCESS]**lsass -/- C:\Windows\system32\lsass.exe
[00-PROCESS]**mscorsvw -/- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
[00-PROCESS]**msdtc -/- C:\Windows\System32\msdtc.exe
[00-PROCESS]**msiexec -/- C:\Windows\system32\msiexec.exe
[00-PROCESS]**mspaint -/- C:\Windows\system32\mspaint.exe
[00-PROCESS]**notepad -/- C:\Windows\system32\notepad.exe
[00-PROCESS]**PresentationFontCache -/- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
[00-PROCESS]**RtHDVCpl -/- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
[00-PROCESS]**s11h10 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-187892\s11h10.exe
[00-PROCESS]**s11z2ec -/- c:\recycler\s-1-5-21-0243556031-888888379-781863308-101417\s11z2ec.exe
[00-PROCESS]**s1sh10 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-87892\s1sh10.exe
[00-PROCESS]**s222h10 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-22892\s222h10.exe
[00-PROCESS]**SearchIndexer -/- C:\Windows\system32\SearchIndexer.exe
[00-PROCESS]**sidebar -/- C:\Program Files\Windows Sidebar\sidebar.exe
[00-PROCESS]**SMSvcHost -/- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
[00-PROCESS]**snmptrap -/- C:\Windows\System32\snmptrap.exe
[00-PROCESS]**spoolsv -/- C:\Windows\System32\spoolsv.exe
[00-PROCESS]**sppsvc -/- C:\Windows\system32\sppsvc.exe
[00-PROCESS]**svchost -/- C:\Windows\system32\svchost.exe
[00-PROCESS]**sxsh10 -/- c:\recycler\s-1-5-21-0243556031-888888379-781863308-87891\sxsh10.exe
[00-PROCESS]**sxshin -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81540\sxshin.exe
[00-PROCESS]**sxshin1 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81140\sxshin1.exe
[00-PROCESS]**sxshin1 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81240\sxshin1.exe
[00-PROCESS]**sxshin3 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81340\sxshin3.exe
[00-PROCESS]**sxshin4 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81350\sxshin4.exe
[00-PROCESS]**sxshin5 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81650\sxshin5.exe
[00-PROCESS]**sxshin6 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-86650\sxshin6.exe
[00-PROCESS]**sxshin7 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-87650\sxshin7.exe
[00-PROCESS]**sxshin8 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-87850\sxshin8.exe
[00-PROCESS]**szsec -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-861397\szsec.exe
[00-PROCESS]**taskhost -/- C:\Windows\system32\taskhost.exe
[00-PROCESS]**TrustedInstaller -/- C:\Windows\servicing\TrustedInstaller.exe
[00-PROCESS]**UI0Detect -/- C:\Windows\system32\UI0Detect.exe
[00-PROCESS]**update -/- C:\Users\Administrator\AppData\Local\Start\update.exe
[00-PROCESS]**Updater -/- C:\Program Files\Skype\Updater\Updater.exe
[00-PROCESS]**vds -/- C:\Windows\System32\vds.exe
[00-PROCESS]**vssvc -/- C:\Windows\system32\vssvc.exe
[00-PROCESS]**WatAdminSvc -/- C:\Windows\system32\Wat\WatAdminSvc.exe
[00-PROCESS]**wbengine -/- C:\Windows\system32\wbengine.exe
[00-PROCESS]**WmiApSrv -/- C:\Windows\system32\wbem\WmiApSrv.exe
[00-PROCESS]**wmime -/- C:\Program Files\HEM\wmime.exe
[00-PROCESS]**wmpnetwk -/- C:\Program Files\Windows Media Player\wmpnetwk.exe
[01-HKCUREG]**aa0rab9 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-82290\aara9.exe
[01-HKCUREG]**Aydcdc -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Aydcdc.exe
[01-HKCUREG]**Best Codec Pack803932.exe -/- C:\Users\Administrator\AppData\Local\Temp\Best Codec Pack803932.exe /XML=C:\Users\Administrator\AppData\Local\Temp\62E7.tmp /ROS /STP=0:2
[01-HKCUREG]**BrowserUid -/- C:\Users\Administrator\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe
[01-HKCUREG]**ca40229dd -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-15555590\cafef9.exe
[01-HKCUREG]**Eydcdg -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Eydcdg.exe
[01-HKCUREG]**Gydcdi -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Gydcdi.exe
[01-HKCUREG]**IDMan -/- C:\Program Files\Internet Download Manager\IDMan.exe /onboot
[01-HKCUREG]**inetb123 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-121921\inetb123.exe
[01-HKCUREG]**Iydcdk -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Iydcdk.exe
[01-HKCUREG]**Oxdcdq -/- C:\Users\Administrator\AppData\Roaming\Oxdcdq.exe
[01-HKCUREG]**Oydcdq -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Oydcdq.exe
[01-HKCUREG]**RtHDVCpl -/- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
[01-HKCUREG]**Screen Saver Pro 3.1 -/- C:\Users\Administrator\AppData\Roaming\ScreenSaverPro.scr
[01-HKCUREG]**Sidebar -/- C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
[01-HKCUREG]**Sydcdu -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Sydcdu.exe
[01-HKCUREG]**sz1s3ec -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-101417\s11z2ec.exe
[01-HKCUREG]**szsec -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-861397\szsec.exe
[01-HKCUREG]**t4q -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-46689\24naq.exe
[01-HKCUREG]**Vydcdx -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Vydcdx.exe
[01-HKCUREG]**Windows Firewall IP Manager -/- C:\RECYCLER\FWDmgr.exe
[01-HKCUREG]**wmime -/- C:\Program Files\HEM\wmime.exe /STARTUP
[01-HKCUREG]**x111n9 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-187892\s11h10.exe
[01-HKCUREG]**x1h2n9 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-87892\s1sh10.exe
[01-HKCUREG]**x222n9 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-22892\s222h10.exe
[01-HKCUREG]**xsh2n1 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81240\sxshin1.exe
[01-HKCUREG]**xsh2n3 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81340\sxshin3.exe
[01-HKCUREG]**xsh2n4 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81350\sxshin4.exe
[01-HKCUREG]**xsh2n5 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81650\sxshin5.exe
[01-HKCUREG]**xsh2n6 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-86650\sxshin6.exe
[01-HKCUREG]**xsh2n7 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-87650\sxshin7.exe
[01-HKCUREG]**xsh2n8 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-87850\sxshin8.exe
[01-HKCUREG]**xsh2n9 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-87891\sxsh10.exe
[01-HKCUREG]**xshin -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81540\sxshin.exe
[01-HKCUREG]**xshin1 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81140\sxshin1.exe
[02-HKLMREG]**aa0rab9 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-82290\aara9.exe
[02-HKLMREG]**Aydcdc -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Aydcdc.exe
[02-HKLMREG]**Best Codec Pack803932.exe -/- C:\Users\Administrator\AppData\Local\Temp\Best Codec Pack803932.exe /XML=C:\Users\Administrator\AppData\Local\Temp\62E7.tmp /ROS /STP=0:2
[02-HKLMREG]**BrowserUid -/- C:\Users\Administrator\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe
[02-HKLMREG]**ca40229dd -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-15555590\cafef9.exe
[02-HKLMREG]**Eydcdg -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Eydcdg.exe
[02-HKLMREG]**Gydcdi -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Gydcdi.exe
[02-HKLMREG]**IDMan -/- C:\Program Files\Internet Download Manager\IDMan.exe /onboot
[02-HKLMREG]**inetb123 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-121921\inetb123.exe
[02-HKLMREG]**Iydcdk -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Iydcdk.exe
[02-HKLMREG]**Oxdcdq -/- C:\Users\Administrator\AppData\Roaming\Oxdcdq.exe
[02-HKLMREG]**Oydcdq -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Oydcdq.exe
[02-HKLMREG]**RtHDVCpl -/- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
[02-HKLMREG]**Screen Saver Pro 3.1 -/- C:\Users\Administrator\AppData\Roaming\ScreenSaverPro.scr
[02-HKLMREG]**Sidebar -/- C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
[02-HKLMREG]**Sydcdu -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Sydcdu.exe
[02-HKLMREG]**sz1s3ec -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-101417\s11z2ec.exe
[02-HKLMREG]**szsec -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-861397\szsec.exe
[02-HKLMREG]**t4q -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-46689\24naq.exe
[02-HKLMREG]**Vydcdx -/- C:\Users\Administrator\AppData\Roaming\Microsoft\Vydcdx.exe
[02-HKLMREG]**Windows Firewall IP Manager -/- C:\RECYCLER\FWDmgr.exe
[02-HKLMREG]**wmime -/- C:\Program Files\HEM\wmime.exe /STARTUP
[02-HKLMREG]**x111n9 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-187892\s11h10.exe
[02-HKLMREG]**x1h2n9 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-87892\s1sh10.exe
[02-HKLMREG]**x222n9 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-22892\s222h10.exe
[02-HKLMREG]**xsh2n1 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81240\sxshin1.exe
[02-HKLMREG]**xsh2n3 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81340\sxshin3.exe
[02-HKLMREG]**xsh2n4 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81350\sxshin4.exe
[02-HKLMREG]**xsh2n5 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81650\sxshin5.exe
[02-HKLMREG]**xsh2n6 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-86650\sxshin6.exe
[02-HKLMREG]**xsh2n7 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-87650\sxshin7.exe
[02-HKLMREG]**xsh2n8 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-87850\sxshin8.exe
[02-HKLMREG]**xsh2n9 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-87891\sxsh10.exe
[02-HKLMREG]**xshin -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81540\sxshin.exe
[02-HKLMREG]**xshin1 -/- C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-81140\sxshin1.exe
[03-BHOCLSD]**Cool Smiley Bar for Facebook -/- C:\Program Files\Cool Smiley Bar for Facebook\ScriptHost.dll -/- {4723AAA8-B2F9-4CC1-9E60-190976DB1FA4}
[03-BHOCLSD]**IDM integration (IDMIEHlprObj Class) -/- C:\Program Files\Internet Download Manager\IDMIECC.dll -/- {0055C089-8582-441B-A0BF-17B458C2A3A8}
[03-BHOCLSD]**SpeedAnalysis.com -/- C:\Program Files\SpeedAnalysis.com\ScriptHost.dll -/- {45564571-A21B-48ED-B584-69752EEE9C3D}
[03-BHOCLSD]**TBSB09893 Class -/- C:\Program Files\GirlGamesForFree Toolbar\tbunsr31DB.tmp\tbcore3.dll -/- {EFDFAB50-A609-493A-BDE3-FEA291715868}
[04-TOOLBAR]**GirlGamesForFree Toolbar -/- C:\Program Files\GirlGamesForFree Toolbar\tbunsr31DB.tmp\tbcore3.dll -/- {5FC86FB3-A8B1-400B-8BE7-0EAF0D857F5D}
[05-SERVICE]**gupdate -/- Google Update Service (gupdate) -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[05-SERVICE]**gupdatem -/- Google Update Service (gupdatem) -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[05-SERVICE]**lmhosts -/- TCP/IP NetBIOS Helper -/- C:\Windows\system32\svchost.exe -/- C:\Windows\System32\lltdsvc.dll
[05-SERVICE]**NlaSvc -/- Network Location Awareness -/- C:\Windows\System32\svchost.exe
[05-SERVICE]**nsi -/- Network Store Interface Service -/- C:\Windows\system32\svchost.exe
[05-SERVICE]**SkypeUpdate -/- Skype Updater -/- C:\Program Files\Skype\Updater\Updater.exe