프로그램분석

Code : leF857vlJrAEIFCPz8QOsxfrWGxFxGuf6JmHCk/WQ6bp2y//mCl2JQ==

프로세스 천국 2013. 9. 3. 21:55

[00-PROCESS]**AdMatching -/- C:\Program Files\AdMatching\AdMatching.exe
[00-PROCESS]**admsys -/- C:\Program Files\AdMatching\admsys.exe
[00-PROCESS]**AdobeARM -/- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[00-PROCESS]**alg -/- C:\WINDOWS\System32\alg.exe
[00-PROCESS]**aspnet_state -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
[00-PROCESS]**AYLaunch -/- c:\program files\estsoft\alyac\AYLaunch.exe
[00-PROCESS]**cisvc -/- C:\WINDOWS\system32\cisvc.exe
[00-PROCESS]**clipsrv -/- C:\WINDOWS\system32\clipsrv.exe
[00-PROCESS]**conime -/- C:\WINDOWS\system32\conime.exe
[00-PROCESS]**csrss -/- C:\WINDOWS\system32\csrss.exe
[00-PROCESS]**ctfmon -/- C:\WINDOWS\system32\ctfmon.exe
[00-PROCESS]**cwbckver -/- C:\Program Files\IBM\Client Access\cwbckver.exe
[00-PROCESS]**cwbinhlp -/- C:\Program Files\IBM\Client Access\cwbinhlp.exe
[00-PROCESS]**CWBRXD -/- C:\WINDOWS\CWBRXD.EXE
[00-PROCESS]**cwbsvstr -/- C:\Program Files\IBM\Client Access\cwbsvstr.exe
[00-PROCESS]**cwbwlwiz -/- C:\Program Files\IBM\Client Access\cwbwlwiz.exe
[00-PROCESS]**dllhost -/- C:\WINDOWS\system32\dllhost.exe
[00-PROCESS]**dmadmin -/- C:\WINDOWS\System32\dmadmin.exe
[00-PROCESS]**Explorer -/- C:\WINDOWS\Explorer.EXE
[00-PROCESS]**EzQ -/- C:\Program Files\PORTE Messenger\EzQ.exe
[00-PROCESS]**f_LPS -/- C:\Program Files\Fasoo DRM\f_LPS.exe
[00-PROCESS]**f_ssoex_dongbusteel_fsn -/- C:\Program Files\Fasoo DRM\f_ssoex_dongbusteel_fsn.exe
[00-PROCESS]**fclient -/- C:\Program Files\Fasoo DRM\fclient.exe
[00-PROCESS]**FlashPlayerUpdateService -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[00-PROCESS]**fph -/- C:\Program Files\Fasoo DRM\fph.exe
[00-PROCESS]**FSP3Cli -/- C:\WINDOWS\system32\FSP3Cli.exe
[00-PROCESS]**iexplore -/- C:\Program Files\Internet Explorer\iexplore.exe
[00-PROCESS]**imapi -/- C:\WINDOWS\system32\imapi.exe
[00-PROCESS]**IMJPMIG -/- C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE
[00-PROCESS]**IMKRMIG -/- C:\Program Files\Common Files\Microsoft Shared\IME12\IMEKR\IMKRMIG.EXE
[00-PROCESS]**ImScInst -/- C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe
[00-PROCESS]**infocard -/- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
[00-PROCESS]**ISUSPM -/- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[00-PROCESS]**LMS -/- C:\Program Files\Intel\AMT\LMS.exe
[00-PROCESS]**locator -/- C:\WINDOWS\system32\locator.exe
[00-PROCESS]**lsass -/- C:\WINDOWS\system32\lsass.exe
[00-PROCESS]**mnmsrvc -/- C:\WINDOWS\system32\mnmsrvc.exe
[00-PROCESS]**mscorsvw -/- c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
[00-PROCESS]**mscorsvw -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
[00-PROCESS]**msdtc -/- C:\WINDOWS\system32\msdtc.exe
[00-PROCESS]**msiexec -/- C:\WINDOWS\system32\msiexec.exe
[00-PROCESS]**netdde -/- C:\WINDOWS\system32\netdde.exe
[00-PROCESS]**nmgsrv -/- C:\Program Files\wincast\nmgsrv.exe
[00-PROCESS]**npkcmsvc -/- C:\WINDOWS\system32\npkcmsvc.exe
[00-PROCESS]**npkfxsvc -/- C:\WINDOWS\system32\npkfxsvc.exe
[00-PROCESS]**ODSERV -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[00-PROCESS]**OSE -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[00-PROCESS]**PresentationFontCache -/- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
[00-PROCESS]**PrivacyIconClient -/- C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
[00-PROCESS]**Reader_sl -/- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
[00-PROCESS]**RKService -/- C:\WINDOWS\system32\RKService.exe
[00-PROCESS]**rsvp -/- C:\WINDOWS\system32\rsvp.exe
[00-PROCESS]**RTHDCPL -/- C:\WINDOWS\RTHDCPL.EXE
[00-PROCESS]**Rundll32 -/- C:\WINDOWS\system32\Rundll32.exe
[00-PROCESS]**SCardSvr -/- C:\WINDOWS\System32\SCardSvr.exe
[00-PROCESS]**services -/- C:\WINDOWS\system32\services.exe
[00-PROCESS]**sessmgr -/- C:\WINDOWS\system32\sessmgr.exe
[00-PROCESS]**smlogsvc -/- C:\WINDOWS\system32\smlogsvc.exe
[00-PROCESS]**smss -/- C:\WINDOWS\System32\smss.exe
[00-PROCESS]**SMSvcHost -/- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
[00-PROCESS]**spoolsv -/- C:\WINDOWS\system32\spoolsv.exe
[00-PROCESS]**Sunainas -/- C:\Documents and Settings\Administrator\Application Data\Sunainas\Sunainas.exe
[00-PROCESS]**SunainasSvr -/- C:\Documents and Settings\Administrator\Application Data\Sunainas\SunainasSvr.exe
[00-PROCESS]**svchost -/- C:\WINDOWS\system32\svchost.exe
[00-PROCESS]**taskupsb -/- C:\Program Files\smartbar\taskupsb.exe
[00-PROCESS]**TCCheckAgent -/- C:\Program Files\AdvTopC\TCCheckAgent.exe
[00-PROCESS]**TINTSETP -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
[00-PROCESS]**tlntsvr -/- C:\WINDOWS\system32\tlntsvr.exe
[00-PROCESS]**TsService -/- C:\WINDOWS\system32\TsService.exe
[00-PROCESS]**UNS -/- C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
[00-PROCESS]**ups -/- C:\WINDOWS\System32\ups.exe
[00-PROCESS]**vssvc -/- C:\WINDOWS\System32\vssvc.exe
[00-PROCESS]**windowstatus -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\Applications\windowstatus.exe
[00-PROCESS]**winlogon -/- C:\WINDOWS\system32\winlogon.exe
[00-PROCESS]**winpop -/- C:\Documents and Settings\Administrator\Application Data\Sunainas\winpop.exe
[00-PROCESS]**wmiapsrv -/- C:\WINDOWS\system32\wbem\wmiapsrv.exe
[00-PROCESS]**wmiprvse -/- C:\WINDOWS\system32\wbem\wmiprvse.exe
[00-PROCESS]**WMPNetwk -/- C:\Program Files\Windows Media Player\WMPNetwk.exe
[00-PROCESS]**WPFFontCache_v0400 -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
[01-HKCUREG]**AdMatching -/- C:\Program Files\AdMatching\AdMatching.exe
[01-HKCUREG]**admsys -/- C:\Program Files\AdMatching\admsys.exe
[01-HKCUREG]**Adobe ARM -/- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[01-HKCUREG]**Adobe Reader Speed Launcher -/- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
[01-HKCUREG]**Alcmtr -/- ALCMTR.EXE
[01-HKCUREG]**ALYac -/- c:\program files\estsoft\alyac\AYLaunch.exe /run
[01-HKCUREG]**Client Access Check Version -/- C:\Program Files\IBM\Client Access\cwbckver.exe LOGIN
[01-HKCUREG]**Client Access Express Welcome -/- C:\Program Files\IBM\Client Access\cwbwlwiz.exe
[01-HKCUREG]**Client Access Help Update -/- C:\Program Files\IBM\Client Access\cwbinhlp.exe
[01-HKCUREG]**Client Access Service -/- C:\Program Files\IBM\Client Access\cwbsvstr.exe
[01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[01-HKCUREG]**FPH Exe -/- C:\Program Files\Fasoo DRM\fph.exe
[01-HKCUREG]**IMJPMIG8.1 -/- C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
[01-HKCUREG]**ISUSPM -/- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe -scheduler
[01-HKCUREG]**Korean IME Migration -/- C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE
[01-HKCUREG]**MSPY2002 -/- C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
[01-HKCUREG]**PHIME2002A -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
[01-HKCUREG]**PHIME2002ASync -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
[01-HKCUREG]**picon -/- C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe -startup
[01-HKCUREG]**PORTE Messenger -/- C:\Program Files\PORTE Messenger\EzQ.exe
[01-HKCUREG]**RTHDCPL -/- RTHDCPL.EXE
[01-HKCUREG]**windowstatus -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\Applications\windowstatus.exe
[01-HKCUREG]**winpop -/- C:\Documents and Settings\Administrator\Application Data\Sunainas\winpop.exe
[01-HKCUREG]**zcl -/- C:\Program Files\Fasoo DRM\fclient.exe
[02-HKLMREG]**AdMatching -/- C:\Program Files\AdMatching\AdMatching.exe
[02-HKLMREG]**admsys -/- C:\Program Files\AdMatching\admsys.exe
[02-HKLMREG]**Adobe ARM -/- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[02-HKLMREG]**Adobe Reader Speed Launcher -/- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
[02-HKLMREG]**Alcmtr -/- ALCMTR.EXE
[02-HKLMREG]**ALYac -/- c:\program files\estsoft\alyac\AYLaunch.exe /run
[02-HKLMREG]**Client Access Check Version -/- C:\Program Files\IBM\Client Access\cwbckver.exe LOGIN
[02-HKLMREG]**Client Access Express Welcome -/- C:\Program Files\IBM\Client Access\cwbwlwiz.exe
[02-HKLMREG]**Client Access Help Update -/- C:\Program Files\IBM\Client Access\cwbinhlp.exe
[02-HKLMREG]**Client Access Service -/- C:\Program Files\IBM\Client Access\cwbsvstr.exe
[02-HKLMREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[02-HKLMREG]**FPH Exe -/- C:\Program Files\Fasoo DRM\fph.exe
[02-HKLMREG]**IMJPMIG8.1 -/- C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
[02-HKLMREG]**ISUSPM -/- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe -scheduler
[02-HKLMREG]**Korean IME Migration -/- C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE
[02-HKLMREG]**MSPY2002 -/- C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
[02-HKLMREG]**PHIME2002A -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
[02-HKLMREG]**PHIME2002ASync -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
[02-HKLMREG]**picon -/- C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe -startup
[02-HKLMREG]**PORTE Messenger -/- C:\Program Files\PORTE Messenger\EzQ.exe
[02-HKLMREG]**RTHDCPL -/- RTHDCPL.EXE
[02-HKLMREG]**windowstatus -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\Applications\windowstatus.exe
[02-HKLMREG]**winpop -/- C:\Documents and Settings\Administrator\Application Data\Sunainas\winpop.exe
[02-HKLMREG]**zcl -/- C:\Program Files\Fasoo DRM\fclient.exe
[04-TOOLBAR]**N.A -/- N.A -/- Locked
[05-SERVICE]**AdobeFlashPlayerUpdateSvc -/- Adobe Flash Player Update Service -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[05-SERVICE]**ALYac_AgentSrv -/- ALYac Agent Service -/- C:\Program Files\ESTsoft\ASM\AYAgentSrv.aye
[05-SERVICE]**ALYac_RTSrv -/- ALYac RealTime Service -/- C:\Program Files\ESTsoft\ALYac\AYRTSrv.aye
[05-SERVICE]**ALYac_UpdSrv -/- ALYac Update Service -/- C:\Program Files\ESTsoft\ALYac\AYUpdSrv.aye
[05-SERVICE]**Cwbrxd -/- Windows용 iSeries Access 리모트 명령 -/- C:\WINDOWS\CWBRXD.EXE
[05-SERVICE]**Fasoo Process Service -/- Fasoo Process Service -/- C:\Program Files\Fasoo DRM\f_LPS.exe
[05-SERVICE]**KongGa -/- 무료만화(KongGa) -/- C:\Program Files\KongGa\KGAChkSvc.exe
[05-SERVICE]**LMS -/- Intel(R) Active Management Technology Local Management Service -/- C:\Program Files\Intel\AMT\LMS.exe
[05-SERVICE]**napagent -/- Network Access Protection Agent -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\System32\qagentrt.dll
[05-SERVICE]**npkcmsvc -/- npkcmsvc -/- C:\WINDOWS\system32\npkcmsvc.exe
[05-SERVICE]**npkfxsvc -/- npkfxsvc -/- C:\WINDOWS\system32\npkfxsvc.exe
[05-SERVICE]**odserv -/- Microsoft Office Diagnostics Service -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[05-SERVICE]**ose -/- Office Source Engine -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[05-SERVICE]**pcfast Update Service -/- pcfast Support Service -/- C:\WINDOWS\userconfigupdate.exe
[05-SERVICE]**RKSvc -/- RealKeyword Updater -/- C:\WINDOWS\system32\RKService.exe
[05-SERVICE]**RunS -/- MultidownLoad Service -/- C:\Documents and Settings\Administrator\APPLIC~1\MULTID~1\MultiDownLoadSvc.exe
[05-SERVICE]**SearchN -/- 서치엔(SearchN) -/- C:\Program Files\SearchN\SNChkSvc.exe
[05-SERVICE]**SunainasSvr -/- SubShop -/- C:\Documents and Settings\Administrator\Application Data\Sunainas\SunainasSvr.exe
[05-SERVICE]**TCCheckAgent -/- TCCheckAgent -/- C:\Program Files\AdvTopC\TCCheckAgent.exe
[05-SERVICE]**TsService -/- TsService -/- C:\WINDOWS\system32\TsService.exe
[05-SERVICE]**UNS -/- Intel(R) Active Management Technology User Notification Service -/- C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
[05-SERVICE]**WinCast Controler -/- WinCast Controler Application -/- C:\Program Files\wincast\nmgsrv.exe
[05-SERVICE]**WinRM -/- Windows Remote Management (WS-Management) -/- C:\WINDOWS\system32\svchost.exe -/- C:\WINDOWS\system32\WsmSvc.dll
[05-SERVICE]**WPFFontCache_v0400 -/- Windows Presentation Foundation Font Cache 4.0.0.0 -/- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe