Code : PARVBCjTXvIIrvjaaFRVLMnKeFa+2aNoegcTg2n0g5M=
[00-PROCESS]**alg -/- C:\WINDOWS\System32\alg.exe
[00-PROCESS]**ALZip -/- C:\Program Files\ESTsoft\ALZip\ALZip.exe
[00-PROCESS]**aspnet_state -/- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
[00-PROCESS]**BCSSync -/- C:\Program Files\Microsoft Office\Office14\BCSSync.exe
[00-PROCESS]**cisvc -/- C:\WINDOWS\system32\cisvc.exe
[00-PROCESS]**clipsrv -/- C:\WINDOWS\system32\clipsrv.exe
[00-PROCESS]**cmd -/- C:\WINDOWS\system32\cmd.exe
[00-PROCESS]**ctfmon -/- C:\WINDOWS\system32\ctfmon.exe
[00-PROCESS]**dllhost -/- C:\WINDOWS\system32\dllhost.exe
[00-PROCESS]**downhelper_se -/- C:\WINDOWS\system32\downhelper_se.exe
[00-PROCESS]**e_signkey -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\signkey\e_signkey.exe
[00-PROCESS]**explorer -/- C:\WINDOWS\explorer.exe
[00-PROCESS]**flashlinker-se -/- C:\WINDOWS\system32\flashlinker-se.exe
[00-PROCESS]**GROOVE -/- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
[00-PROCESS]**HDeck -/- C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
[00-PROCESS]**hkcmd -/- C:\WINDOWS\system32\hkcmd.exe
[00-PROCESS]**iexplore -/- C:\Program Files\Internet Explorer\iexplore.exe
[00-PROCESS]**igfxpers -/- C:\WINDOWS\system32\igfxpers.exe
[00-PROCESS]**igfxtray -/- C:\WINDOWS\system32\igfxtray.exe
[00-PROCESS]**imapi -/- C:\WINDOWS\system32\imapi.exe
[00-PROCESS]**IMEDICTUPDATE -/- C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE
[00-PROCESS]**IMEKLMG -/- C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE
[00-PROCESS]**infocard -/- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
[00-PROCESS]**KaraokeSer -/- C:\WINDOWS\system32\KaraokeSer.exe
[00-PROCESS]**keypang -/- C:\Program Files\KeyPang\keypang.exe
[00-PROCESS]**KMService -/- C:\WINDOWS\KMService.exe
[00-PROCESS]**locator -/- C:\WINDOWS\system32\locator.exe
[00-PROCESS]**lsass -/- C:\WINDOWS\system32\lsass.exe
[00-PROCESS]**mnmsrvc -/- C:\WINDOWS\system32\mnmsrvc.exe
[00-PROCESS]**mscorsvw -/- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
[00-PROCESS]**msdtc -/- C:\WINDOWS\system32\msdtc.exe
[00-PROCESS]**msiexec -/- C:\WINDOWS\system32\msiexec.exe
[00-PROCESS]**MSOSYNC -/- C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
[00-PROCESS]**netdde -/- C:\WINDOWS\system32\netdde.exe
[00-PROCESS]**OSE -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[00-PROCESS]**OSPPSVC -/- C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
[00-PROCESS]**PresentationFontCache -/- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
[00-PROCESS]**primead -/- C:\Program Files\primead\primead.exe
[00-PROCESS]**RaclSvc -/- C:\Program Files\Racl\RaclSvc.exe
[00-PROCESS]**rsvp -/- C:\WINDOWS\system32\rsvp.exe
[00-PROCESS]**SCardSvr -/- C:\WINDOWS\System32\SCardSvr.exe
[00-PROCESS]**services -/- C:\WINDOWS\system32\services.exe
[00-PROCESS]**sessmgr -/- C:\WINDOWS\system32\sessmgr.exe
[00-PROCESS]**signkey -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\signkey\signkey.exe
[00-PROCESS]**smlogsvc -/- C:\WINDOWS\system32\smlogsvc.exe
[00-PROCESS]**smss -/- C:\WINDOWS\System32\smss.exe
[00-PROCESS]**SpellerSvc -/- C:\Program Files\Speller\SpellerSvc.exe
[00-PROCESS]**spoolsv -/- C:\WINDOWS\system32\spoolsv.exe
[00-PROCESS]**srvany -/- C:\WINDOWS\system32\srvany.exe
[00-PROCESS]**svchost -/- C:\WINDOWS\system32\svchost.exe
[00-PROCESS]**tlntsvr -/- C:\WINDOWS\system32\tlntsvr.exe
[00-PROCESS]**TsService -/- C:\WINDOWS\system32\TsService.exe
[00-PROCESS]**ups -/- C:\WINDOWS\System32\ups.exe
[00-PROCESS]**V3LSvc -/- C:\Program Files\AhnLab\UPlus_V3\V3LSvc.exe
[00-PROCESS]**V3LTray -/- C:\Program Files\AhnLab\UPlus_V3\V3LTray.exe
[00-PROCESS]**vssvc -/- C:\WINDOWS\System32\vssvc.exe
[00-PROCESS]**wdfmgr -/- C:\WINDOWS\system32\wdfmgr.exe
[00-PROCESS]**willian -/- C:\Documents and Settings\Administrator\Application Data\willian\willian.exe
[00-PROCESS]**willians -/- C:\Documents and Settings\Administrator\Application Data\willian\willians.exe
[00-PROCESS]**windowstab_mon -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\windowstab\windowstab_mon.exe
[00-PROCESS]**windowstab_uc -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\windowstab\windowstab_uc.exe
[00-PROCESS]**wingg -/- C:\Documents and Settings\Administrator\Application Data\willian\wingg.exe
[00-PROCESS]**winlogon -/- C:\WINDOWS\system32\winlogon.exe
[00-PROCESS]**wmiapsrv -/- C:\WINDOWS\system32\wbem\wmiapsrv.exe
[01-HKCUREG]**AhnLab V3Lite Tray Process -/- C:\Program Files\AhnLab\UPlus_V3\V3LTray.exe /logon
[01-HKCUREG]**appwizn16 -/- C:\WINDOWS\system32\ko\appwizn16.exe
[01-HKCUREG]**BCSSync -/- C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices
[01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[01-HKCUREG]**HDAudDeck -/- C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
[01-HKCUREG]**HotKeysCmds -/- C:\WINDOWS\system32\hkcmd.exe
[01-HKCUREG]**IgfxTray -/- C:\WINDOWS\system32\igfxtray.exe
[01-HKCUREG]**IME14 KOR Setup -/- C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /KOR /Log
[01-HKCUREG]**KernelFaultCheck -/- C:\WINDOWS\system32\dumprep 0 -k
[01-HKCUREG]**KeyPang -/- C:\Program Files\KeyPang\keypang.exe
[01-HKCUREG]**Kp -/- C:\Program Files\kpupdate\kpupdate.exe
[01-HKCUREG]**OfficeSyncProcess -/- C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
[01-HKCUREG]**PC_Clean_Optimizer -/- C:\Documents and Settings\Administrator\Application Data\willian\willian.exe
[01-HKCUREG]**Persistence -/- C:\WINDOWS\system32\igfxpers.exe
[01-HKCUREG]**primead.exe -/- C:\Program Files\primead\primead.exe
[01-HKCUREG]**Racl -/- C:\Program Files\Racl\RaclSvc.exe
[01-HKCUREG]**signkey -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\signkey\signkey.exe
[01-HKCUREG]**Speller -/- C:\Program Files\Speller\SpellerSvc.exe
[01-HKCUREG]**WINDOWSTAB_UC -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\windowstab\windowstab_uc.exe /run
[01-HKCUREG]**wingg -/- C:\Documents and Settings\Administrator\Application Data\willian\wingg.exe
[02-HKLMREG]**AhnLab V3Lite Tray Process -/- C:\Program Files\AhnLab\UPlus_V3\V3LTray.exe /logon
[02-HKLMREG]**appwizn16 -/- C:\WINDOWS\system32\ko\appwizn16.exe
[02-HKLMREG]**BCSSync -/- C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices
[02-HKLMREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[02-HKLMREG]**HDAudDeck -/- C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
[02-HKLMREG]**HotKeysCmds -/- C:\WINDOWS\system32\hkcmd.exe
[02-HKLMREG]**IgfxTray -/- C:\WINDOWS\system32\igfxtray.exe
[02-HKLMREG]**IME14 KOR Setup -/- C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /KOR /Log
[02-HKLMREG]**KernelFaultCheck -/- C:\WINDOWS\system32\dumprep 0 -k
[02-HKLMREG]**KeyPang -/- C:\Program Files\KeyPang\keypang.exe
[02-HKLMREG]**Kp -/- C:\Program Files\kpupdate\kpupdate.exe
[02-HKLMREG]**OfficeSyncProcess -/- C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
[02-HKLMREG]**PC_Clean_Optimizer -/- C:\Documents and Settings\Administrator\Application Data\willian\willian.exe
[02-HKLMREG]**Persistence -/- C:\WINDOWS\system32\igfxpers.exe
[02-HKLMREG]**primead.exe -/- C:\Program Files\primead\primead.exe
[02-HKLMREG]**Racl -/- C:\Program Files\Racl\RaclSvc.exe
[02-HKLMREG]**signkey -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\signkey\signkey.exe
[02-HKLMREG]**Speller -/- C:\Program Files\Speller\SpellerSvc.exe
[02-HKLMREG]**WINDOWSTAB_UC -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\windowstab\windowstab_uc.exe /run
[02-HKLMREG]**wingg -/- C:\Documents and Settings\Administrator\Application Data\willian\wingg.exe
[03-BHOCLSD]**Groove GFS Browser Helper -/- C:\PROGRA~1\MICROS~4\Office14\GROOVEEX.DLL -/- {72853161-30C5-4D22-B7F9-0BBC1D38A37E}
[03-BHOCLSD]**NateSearchSafeBHO Class -/- C:\Program Files\NATEON\BIN\NateSearchSafe.dll -/- {39AA03A6-B5D9-4F47-99DF-1666A7B8D8E8}
[03-BHOCLSD]**Office Document Cache Handler -/- C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL -/- {B4F3A835-0E21-4959-BA22-42B3008E02FF}
[03-BHOCLSD]**WinExpandB Class -/- C:\Program Files\WinExpand_s4fhk\WinExpand_s4fhk.dll -/- {00000F3F-F3A2-4EC4-BB7F-61F727D1AEC3}
[04-TOOLBAR]**잠김영역복사 -/- C:\Program Files\Racl\RaclTB.dll -/- {BCE04A5B-2B7D-4F4B-BB8E-2A59611733DD}
[05-SERVICE]**downhelper Update Service -/- downhelper Support Service -/- C:\WINDOWS\system32\downhelper_se.exe
[05-SERVICE]**flashlinkerservice -/- Flashlinker Service -/- C:\WINDOWS\system32\flashlinker-se.exe
[05-SERVICE]**hfikexsfrue -/- hfikexsfrue -/- C:\WINDOWS\System32\svchost.exe -/- C:\Program Files\hfikexsfrue\hfikexsfrue.dll
[05-SERVICE]**igmyavy -/- igmyavy -/- C:\WINDOWS\System32\svchost.exe -/- C:\Program Files\igmyavy\igmyavy.dll
[05-SERVICE]**ImeDictUpdateService -/- Microsoft IME Dictionary Update -/- C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE
[05-SERVICE]**KaraokeService -/- VIA Karaoke digital mixer Service -/- C:\WINDOWS\system32\KaraokeSer.exe
[05-SERVICE]**KMService -/- KMService -/- C:\WINDOWS\system32\srvany.exe
[05-SERVICE]**Microsoft SharePoint Workspace Audit Service -/- Microsoft SharePoint Workspace Audit Service -/- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
[05-SERVICE]**napagent -/- Network Access Protection Agent -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\System32\qagentrt.dll
[05-SERVICE]**npggsvc -/- nProtect GameGuard Service -/- C:\WINDOWS\system32\GameMon.des -service
[05-SERVICE]**ompclsyaleh -/- ompclsyaleh -/- C:\WINDOWS\System32\svchost.exe -/- C:\Program Files\ompclsyaleh\ompclsyaleh.dll
[05-SERVICE]**ose -/- Office Source Engine -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[05-SERVICE]**osppsvc -/- Office Software Protection Platform -/- C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
[05-SERVICE]**sakckqmsao -/- sakckqmsao -/- C:\WINDOWS\System32\svchost.exe -/- C:\Program Files\sakckqmsao\sakckqmsao.dll
[05-SERVICE]**smjuajjnpa -/- smjuajjnpa -/- C:\WINDOWS\System32\svchost.exe -/- C:\Program Files\smjuajjnpa\smjuajjnpa.dll
[05-SERVICE]**TsService -/- TsService -/- C:\WINDOWS\system32\TsService.exe
[05-SERVICE]**UMWdf -/- Windows User Mode Driver Framework -/- C:\WINDOWS\system32\wdfmgr.exe
[05-SERVICE]**V3 Lite Service -/- V3 Lite Service -/- C:\Program Files\AhnLab\UPlus_V3\V3LSvc.exe
[05-SERVICE]**willians -/- TabStation -/- C:\Documents and Settings\Administrator\Application Data\willian\willians.exe
[05-SERVICE]**windowstab_mon -/- Windows Tab Manager -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\windowstab\windowstab_mon.exe