프로그램분석

Code : +/fvAEuY/UGZH1fsZXMQSR5ksOoAUFNAMctezOe6kQpyIYWAEWJnAg==

프로세스 천국 2013. 9. 26. 21:13

[00-PROCESS]**alg -/- C:\Windows\System32\alg.exe
[00-PROCESS]**ALSee -/- C:\Program Files\ESTsoft\ALSee\ALSee.exe
[00-PROCESS]**aosrts -/- C:\Program Files\AhnLab\ASP\MyFirewall 4.0\aosrts.exe
[00-PROCESS]**aostray -/- C:\Program Files\AhnLab\ASP\Smart Update i\aostray.exe
[00-PROCESS]**AppleMobileDeviceService -/- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
[00-PROCESS]**armsvc -/- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
[00-PROCESS]**ASPLnchr -/- C:\Program Files\AhnLab\ASP\Components\ASPLnchr.exe
[00-PROCESS]**atiesrxx -/- C:\Windows\system32\atiesrxx.exe
[00-PROCESS]**AUDIODG -/- C:\Windows\system32\AUDIODG.EXE
[00-PROCESS]**AYLaunch -/- C:\Program Files\ESTsoft\ALYac\AYLaunch.exe
[00-PROCESS]**chrome -/- C:\Program Files\Google\Chrome\Application\chrome.exe
[00-PROCESS]**ClientSM -/- C:\Program Files\SoftForum\XecureWeb\ActiveX\ClientSM.exe
[00-PROCESS]**csrss -/- C:\Windows\system32\csrss.exe
[00-PROCESS]**dllhost -/- C:\Windows\system32\dllhost.exe
[00-PROCESS]**Dwm -/- C:\Windows\system32\Dwm.exe
[00-PROCESS]**ehRecvr -/- C:\Windows\ehome\ehRecvr.exe
[00-PROCESS]**ehsched -/- C:\Windows\ehome\ehsched.exe
[00-PROCESS]**Explorer -/- C:\Windows\Explorer.EXE
[00-PROCESS]**fxssvc -/- C:\Windows\system32\fxssvc.exe
[00-PROCESS]**GDownService -/- C:\Program Files\GDownService\GDownService.exe
[00-PROCESS]**GoogleUpdate -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[00-PROCESS]**GrooveAuditService -/- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
[00-PROCESS]**icmsmumnic -/- C:\Windows\icmsmumnic.exe
[00-PROCESS]**IEXPLORE -/- C:\Program Files\Internet Explorer\IEXPLORE.EXE
[00-PROCESS]**ImageSAFERStart_X64 -/- C:\Windows\system32\ImageSAFERStart_X64.exe
[00-PROCESS]**ImageSAFERStart_X86 -/- C:\Windows\system32\ImageSAFERStart_X86.exe
[00-PROCESS]**ImageSAFERSvc -/- C:\Windows\ImageSAFERSvc.exe
[00-PROCESS]**infocard -/- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
[00-PROCESS]**INIS60 -/- C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4BLRLKYS\INIS60.exe
[00-PROCESS]**innosvc -/- C:\Windows\system32\innosvc.exe
[00-PROCESS]**intelligent -/- C:\Program Files\Intelligent Client\intelligent.exe
[00-PROCESS]**intelligents -/- C:\Program Files\Intelligent Client\intelligents.exe
[00-PROCESS]**intelligentu -/- C:\Program Files\Intelligent Client\intelligentu.exe
[00-PROCESS]**iPodService -/- C:\Program Files\iPod\bin\iPodService.exe
[00-PROCESS]**ipoint -/- C:\Program Files\Microsoft IntelliPoint\ipoint.exe
[00-PROCESS]**locator -/- C:\Windows\system32\locator.exe
[00-PROCESS]**lsass -/- C:\Windows\system32\lsass.exe
[00-PROCESS]**lsm -/- C:\Windows\system32\lsm.exe
[00-PROCESS]**mDNSResponder -/- C:\Program Files\Bonjour\mDNSResponder.exe
[00-PROCESS]**mf40nt -/- C:\Program Files\AhnLab\ASP\MyFirewall 4.0\mf40nt.exe
[00-PROCESS]**mkd25tray -/- C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\mkd25tray.exe
[00-PROCESS]**mscorsvw -/- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
[00-PROCESS]**mscorsvw -/- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
[00-PROCESS]**msdtc -/- C:\Windows\System32\msdtc.exe
[00-PROCESS]**msiexec -/- C:\Windows\system32\msiexec.exe
[00-PROCESS]**natsvc -/- C:\Program Files\NAT Service\natsvc.exe
[00-PROCESS]**npenksvc5 -/- C:\Program Files\INCAInternet\nProtect Netizen v5.5\npenksvc5.exe
[00-PROCESS]**npkcmsvc -/- C:\Windows\system32\npkcmsvc.exe
[00-PROCESS]**npkfxsvc -/- C:\Windows\system32\npkfxsvc.exe
[00-PROCESS]**ODSERV -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[00-PROCESS]**OSE -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[00-PROCESS]**perfhost -/- C:\Windows\system32\perfhost.exe
[00-PROCESS]**PresentationFontCache -/- C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
[00-PROCESS]**qdownagent -/- C:\Program Files\QuickDownloadService\qdownagent.exe
[00-PROCESS]**qdownupdate -/- C:\Program Files\QuickDownloadService\qdownupdate.exe
[00-PROCESS]**RAVCpl64 -/- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
[00-PROCESS]**sbshbrk64 -/- C:\Program Files\AhnLab\ASP\SBPersonal\sbshbrk64.exe
[00-PROCESS]**sbshmgr -/- C:\Program Files\AhnLab\ASP\SBPersonal\sbshmgr.exe
[00-PROCESS]**SearchFilterHost -/- C:\Windows\system32\SearchFilterHost.exe
[00-PROCESS]**SearchIndexer -/- C:\Windows\system32\SearchIndexer.exe
[00-PROCESS]**SearchProtocolHost -/- C:\Windows\system32\SearchProtocolHost.exe
[00-PROCESS]**services -/- C:\Windows\system32\services.exe
[00-PROCESS]**SMSvcHost -/- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
[00-PROCESS]**snmptrap -/- C:\Windows\System32\snmptrap.exe
[00-PROCESS]**spoolsv -/- C:\Windows\System32\spoolsv.exe
[00-PROCESS]**sppsvc -/- C:\Windows\system32\sppsvc.exe
[00-PROCESS]**SVCADGUGU32 -/- C:\Program Files\adgugu\SVCADGUGU32.exe
[00-PROCESS]**svchost -/- C:\Windows\system32\svchost.exe
[00-PROCESS]**taskhost -/- C:\Windows\system32\taskhost.exe
[00-PROCESS]**TrustedInstaller -/- C:\Windows\servicing\TrustedInstaller.exe
[00-PROCESS]**UI0Detect -/- C:\Windows\system32\UI0Detect.exe
[00-PROCESS]**vds -/- C:\Windows\System32\vds.exe
[00-PROCESS]**vssvc -/- C:\Windows\system32\vssvc.exe
[00-PROCESS]**WatAdminSvc -/- C:\Windows\system32\Wat\WatAdminSvc.exe
[00-PROCESS]**wbengine -/- C:\Windows\system32\wbengine.exe
[00-PROCESS]**wininit -/- C:\Windows\system32\wininit.exe
[00-PROCESS]**winlogon -/- C:\Windows\system32\winlogon.exe
[00-PROCESS]**WmiApSrv -/- C:\Windows\system32\wbem\WmiApSrv.exe
[00-PROCESS]**wmiprvse -/- C:\Windows\system32\wbem\wmiprvse.exe
[00-PROCESS]**wmpnetwk -/- C:\Program Files\Windows Media Player\wmpnetwk.exe
[01-HKCUREG]**ALYac -/- C:\Program Files\ESTsoft\ALYac\AYLaunch.exe /run
[01-HKCUREG]**INTELLIGENTCLIENT -/- C:\Program Files\Intelligent Client\intelligentu.exe /run
[01-HKCUREG]**IntelliPoint -/- C:\Program Files\Microsoft IntelliPoint\ipoint.exe
[01-HKCUREG]**msnmsgr -/- C:\Program Files\Windows Live\Messenger\msnmsgr.exe /background
[01-HKCUREG]**RtHDVCpl -/- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
[02-HKLMREG]**ALYac -/- C:\Program Files\ESTsoft\ALYac\AYLaunch.exe /run
[02-HKLMREG]**INTELLIGENTCLIENT -/- C:\Program Files\Intelligent Client\intelligentu.exe /run
[02-HKLMREG]**IntelliPoint -/- C:\Program Files\Microsoft IntelliPoint\ipoint.exe
[02-HKLMREG]**msnmsgr -/- C:\Program Files\Windows Live\Messenger\msnmsgr.exe /background
[02-HKLMREG]**RtHDVCpl -/- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
[05-SERVICE]**AdobeARMservice -/- Adobe Acrobat Update Service -/- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
[05-SERVICE]**ALYac_RTSrv -/- ALYac RealTime Service -/- C:\Program Files\ESTsoft\ALYac\AYRTSrv.aye
[05-SERVICE]**ALYac_UpdSrv -/- ALYac Update Service -/- C:\Program Files\ESTsoft\ALYac\AYUpdSrv.aye
[05-SERVICE]**AMD External Events Utility -/- AMD External Events Utility -/- C:\Windows\system32\atiesrxx.exe
[05-SERVICE]**Apple Mobile Device -/- Apple Mobile Device -/- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
[05-SERVICE]**BNDownService -/- File Download Service -/- C:\Program Files\GDownService\GDownService.exe
[05-SERVICE]**Bonjour Service -/- Bonjour 서비스 -/- C:\Program Files\Bonjour\mDNSResponder.exe
[05-SERVICE]**FontCache -/- Windows Font Cache Service -/- C:\Windows\system32\svchost.exe -/- C:\Windows\system32\FntCache.dll
[05-SERVICE]**gupdate -/- Google 업데이트 서비스 (gupdate) -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[05-SERVICE]**gupdatem -/- Google 업데이트 서비스 (gupdatem) -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[05-SERVICE]**icmsmumnic -/- Intelligent Service -/- C:\Windows\icmsmumnic.exe
[05-SERVICE]**Image Protection -/- Image Protect Service -/- C:\Windows\ImageSAFERSvc.exe
[05-SERVICE]**Innosvc -/- Innosvc -/- C:\Windows\system32\innosvc.exe
[05-SERVICE]**iPod Service -/- iPod 서비스 -/- C:\Program Files\iPod\bin\iPodService.exe
[05-SERVICE]**Microsoft Office Groove Audit Service -/- Microsoft Office Groove Audit Service -/- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
[05-SERVICE]**NATService -/- NATService -/- C:\Program Files\NAT Service\natsvc.exe
[05-SERVICE]**NetTcpPortSharing -/- Net.Tcp Port Sharing Service -/- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
[05-SERVICE]**NoPhishing -/- NoPhishing -/- C:\Users\Administrator\SoftRun\NoPhishing\NPNTService
[05-SERVICE]**npggsvc -/- nProtect GameGuard Service -/- C:\Windows\system32\GameMon.des -service
[05-SERVICE]**npkcmsvc -/- npkcmsvc -/- C:\Windows\system32\npkcmsvc.exe
[05-SERVICE]**npkfxsvc -/- npkfxsvc -/- C:\Windows\system32\npkfxsvc.exe
[05-SERVICE]**odserv -/- Microsoft Office Diagnostics Service -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[05-SERVICE]**ose -/- Office Source Engine -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[05-SERVICE]**PerfHost -/- Performance Counter DLL Host -/- C:\Windows\system32\perfhost.exe
[05-SERVICE]**QuickDownload Agent -/- QuickDownload Agent -/- C:\Program Files\QuickDownloadService\qdownagent.exe
[05-SERVICE]**QuickDownload Update -/- QuickDownload Update -/- C:\Program Files\QuickDownloadService\qdownupdate.exe
[05-SERVICE]**SVCADGUGU32 -/- Serviceadgugu32 -/- C:\Program Files\adgugu\SVCADGUGU32.exe
[06-TASKLST]**ESTsoft RunAsStdUser 479983Task -/- C:\Program Files\ESTsoft\ALSee\ALSee.exe
[06-TASKLST]**GoogleUpdateTaskMachineCore -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[06-TASKLST]**GoogleUpdateTaskMachineUA -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[06-TASKLST]**icssmumnic -/- C:\Program Files\Intelligent Client\intelligents.exe
[06-TASKLST]**Microsoft_Hardware_Launch_IPoint_exe -/- C:\Program Files\Microsoft IntelliPoint\IPoint.exe