프로그램분석

Code : HjepjGjFSp1tFOe8oV4AOmb5xYEA6C2fpoYzfPfDyXA=

프로세스 천국 2013. 10. 19. 22:02

[00-PROCESS]**alg -/- C:\WINDOWS\System32\alg.exe
[00-PROCESS]**aspnet_state -/- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
[00-PROCESS]**cisvc -/- C:\WINDOWS\system32\cisvc.exe
[00-PROCESS]**clipsrv -/- C:\WINDOWS\system32\clipsrv.exe
[00-PROCESS]**ctfmon -/- C:\WINDOWS\system32\ctfmon.exe
[00-PROCESS]**dllhost -/- C:\WINDOWS\system32\dllhost.exe
[00-PROCESS]**downhelper_se -/- C:\WINDOWS\system32\downhelper_se.exe
[00-PROCESS]**Explorer -/- C:\WINDOWS\Explorer.EXE
[00-PROCESS]**ezLink_svc -/- C:\Program Files\Common Files\Windows Favorites\ezLink_svc.exe
[00-PROCESS]**ez-PlusSC -/- C:\Program Files\Common Files\EZ-Plus\ez-PlusSC.exe
[00-PROCESS]**FDUp -/- C:\Documents and Settings\Administrator\Application Data\filedown_new\FDUp.exe
[00-PROCESS]**FDUpSvc -/- C:\Documents and Settings\Administrator\Application Data\filedown_new\FDUpSvc.exe
[00-PROCESS]**flashlinker-se -/- C:\WINDOWS\system32\flashlinker-se.exe
[00-PROCESS]**FsUsbExService -/- C:\WINDOWS\system32\FsUsbExService.Exe
[00-PROCESS]**gcodecopen -/- C:\Program Files\GCodec\gcodecopen.exe
[00-PROCESS]**gcodecsvc -/- C:\Program Files\GCodec\gcodecsvc.exe
[00-PROCESS]**Gobugizip -/- C:\Program Files\Gobugizip\Gobugizip.exe
[00-PROCESS]**GobugizipService -/- C:\Program Files\gobugizip\GobugizipService.exe
[00-PROCESS]**GrooveAuditService -/- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
[00-PROCESS]**GrooveMonitor -/- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[00-PROCESS]**hkcmd -/- C:\WINDOWS\system32\hkcmd.exe
[00-PROCESS]**iexplore -/- C:\Program Files\Internet Explorer\iexplore.exe
[00-PROCESS]**igfxpers -/- C:\WINDOWS\system32\igfxpers.exe
[00-PROCESS]**igfxtray -/- C:\WINDOWS\system32\igfxtray.exe
[00-PROCESS]**IKeeperM -/- C:\Program Files\IKeeper\IKeeperM.exe
[00-PROCESS]**IKeeperOpen -/- C:\Program Files\IKeeper\IKeeperOpen.exe
[00-PROCESS]**IKeeperSvc -/- C:\Program Files\IKeeper\IKeeperSvc.exe
[00-PROCESS]**imapi -/- C:\WINDOWS\system32\imapi.exe
[00-PROCESS]**IMKRMIG -/- C:\Program Files\Common Files\Microsoft Shared\IME12\IMEKR\IMKRMIG.EXE
[00-PROCESS]**infocard -/- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
[00-PROCESS]**KakaoTalk -/- C:\Program Files\Kakao\KakaoTalk\KakaoTalk.exe
[00-PROCESS]**KaraokeSer -/- C:\WINDOWS\system32\KaraokeSer.exe
[00-PROCESS]**Kies -/- C:\Program Files\Samsung\Kies\Kies.exe
[00-PROCESS]**KiesTrayAgent -/- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
[00-PROCESS]**LMS -/- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
[00-PROCESS]**locator -/- C:\WINDOWS\system32\locator.exe
[00-PROCESS]**lsass -/- C:\WINDOWS\system32\lsass.exe
[00-PROCESS]**MK -/- C:\Program Files\MKJogo\MKLOL\MK.exe
[00-PROCESS]**mnmsrvc -/- C:\WINDOWS\system32\mnmsrvc.exe
[00-PROCESS]**mscorsvw -/- c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
[00-PROCESS]**msdtc -/- C:\WINDOWS\system32\msdtc.exe
[00-PROCESS]**msiexec -/- C:\WINDOWS\system32\msiexec.exe
[00-PROCESS]**NBService -/- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
[00-PROCESS]**NeroCheck -/- C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[00-PROCESS]**netdde -/- C:\WINDOWS\system32\netdde.exe
[00-PROCESS]**NMIndexingService -/- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
[00-PROCESS]**npkfxsvc -/- C:\WINDOWS\system32\npkfxsvc.exe
[00-PROCESS]**nvsvc32 -/- C:\WINDOWS\system32\nvsvc32.exe
[00-PROCESS]**ODSERV -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[00-PROCESS]**ONENOTEM -/- C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[00-PROCESS]**OSE -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[00-PROCESS]**PresentationFontCache -/- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
[00-PROCESS]**rsvp -/- C:\WINDOWS\system32\rsvp.exe
[00-PROCESS]**SCardSvr -/- C:\WINDOWS\System32\SCardSvr.exe
[00-PROCESS]**services -/- C:\WINDOWS\system32\services.exe
[00-PROCESS]**sessmgr -/- C:\WINDOWS\system32\sessmgr.exe
[00-PROCESS]**smart-update-se -/- C:\Program Files\smart-update\smart-update-se.exe
[00-PROCESS]**smlogsvc -/- C:\WINDOWS\system32\smlogsvc.exe
[00-PROCESS]**smss -/- C:\WINDOWS\System32\smss.exe
[00-PROCESS]**spoolsv -/- C:\WINDOWS\system32\spoolsv.exe
[00-PROCESS]**svchost -/- C:\WINDOWS\system32\svchost.exe
[00-PROCESS]**system-update-se -/- C:\Program Files\system-update\system-update-se.exe
[00-PROCESS]**tlntsvr -/- C:\WINDOWS\system32\tlntsvr.exe
[00-PROCESS]**UNS -/- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
[00-PROCESS]**ups -/- C:\WINDOWS\System32\ups.exe
[00-PROCESS]**vssvc -/- C:\WINDOWS\System32\vssvc.exe
[00-PROCESS]**win_aplussvc -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows aplus\win_aplussvc.exe
[00-PROCESS]**windatainfoset -/- C:\WINDOWS\windatainfoset.exe
[00-PROCESS]**windowreset -/- C:\WINDOWS\windowreset.exe
[00-PROCESS]**windowupdatereset -/- C:\WINDOWS\windowupdatereset.exe
[00-PROCESS]**winlogon -/- C:\WINDOWS\system32\winlogon.exe
[00-PROCESS]**winnetplus -/- C:\Program Files\FileNori\winnetplus.exe
[00-PROCESS]**wmiapsrv -/- C:\WINDOWS\system32\wbem\wmiapsrv.exe
[00-PROCESS]**wuauclt -/- C:\WINDOWS\system32\wuauclt.exe
[01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[01-HKCUREG]**FDStart -/- C:\Documents and Settings\Administrator\Application Data\filedown_new\FDUp.exe /startup
[01-HKCUREG]**GrooveMonitor -/- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[01-HKCUREG]**KakaoTalk -/- C:\Program Files\Kakao\KakaoTalk\KakaoTalk.exe -bystartup
[01-HKCUREG]**KernelFaultCheck -/- C:\WINDOWS\system32\dumprep 0 -k
[01-HKCUREG]**KiesAirMessage -/- C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
[01-HKCUREG]**KiesPreload -/- C:\Program Files\Samsung\Kies\Kies.exe /preload
[01-HKCUREG]**KiesTrayAgent -/- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
[01-HKCUREG]**Korean IME Migration -/- C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE
[01-HKCUREG]**MKLOL -/- C:\Program Files\MKJogo\MKLOL\MK.exe -auto
[01-HKCUREG]**NvCplDaemon -/- RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dllNvStartup
[02-HKLMREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[02-HKLMREG]**FDStart -/- C:\Documents and Settings\Administrator\Application Data\filedown_new\FDUp.exe /startup
[02-HKLMREG]**GrooveMonitor -/- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[02-HKLMREG]**KakaoTalk -/- C:\Program Files\Kakao\KakaoTalk\KakaoTalk.exe -bystartup
[02-HKLMREG]**KernelFaultCheck -/- C:\WINDOWS\system32\dumprep 0 -k
[02-HKLMREG]**KiesAirMessage -/- C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
[02-HKLMREG]**KiesPreload -/- C:\Program Files\Samsung\Kies\Kies.exe /preload
[02-HKLMREG]**KiesTrayAgent -/- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
[02-HKLMREG]**Korean IME Migration -/- C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE
[02-HKLMREG]**MKLOL -/- C:\Program Files\MKJogo\MKLOL\MK.exe -auto
[02-HKLMREG]**NvCplDaemon -/- RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dllNvStartup
[03-BHOCLSD]**BrKeywordObj Class -/- C:\Program Files\Favorite_Icons\FavoriteIcons.dll -/- {4D4D2A74-0249-49E6-BC41-0586A0333CB3}
[03-BHOCLSD]**FGDownloadUIBHO Class -/- C:\Documents and Settings\Administrator\Application Data\filedown_new\FDDownloadUI.dll -/- {70171C86-7A8A-4fe9-BC5F-CEEEA5E989BC}
[03-BHOCLSD]**gcodecband -/- C:\Program Files\GCodec\gcodecband.dll -/- {D51B53A3-FFAD-4F50-98AC-E30085EBD987}
[03-BHOCLSD]**Groove GFS Browser Helper -/- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll -/- {72853161-30C5-4D22-B7F9-0BBC1D38A37E}
[03-BHOCLSD]**ikeeper -/- C:\Program Files\IKeeper\IKeeper.dll -/- {E2D71B19-CCD4-4c9e-92FC-449699215330}
[03-BHOCLSD]**windviewer Class -/- C:\Program Files\windviewer\windviewer.dll -/- {CC34B3C3-3904-4D0E-8035-536715B28BBA}
[03-BHOCLSD]**winsearchincpg.winsearchinc -/- C:\Program Files\winsearchinc\winsearchinc.dll -/- {17A84F9A-84E7-47FE-BC10-91FA1383241D}
[03-BHOCLSD]**이지플러스(ez-Plus)_ezPlusbho -/- C:\Program Files\Common Files\EZ-Plus\ez-Plus.dll -/- {1F810C3E-B96E-400d-A8CB-B822620AC3BE}
[05-SERVICE]**ALYac_RTSrv -/- ALYac RealTime Service -/- C:\Program Files\ESTsoft\ALYac\AYRTSrv.aye
[05-SERVICE]**ALYac_UpdSrv -/- ALYac Update Service -/- C:\Program Files\ESTsoft\ALYac\AYUpdSrv.aye
[05-SERVICE]**downhelper Update Service -/- downhelper Support Service -/- C:\WINDOWS\system32\downhelper_se.exe
[05-SERVICE]**ezLink -/- Windows Favorites ezLink -/- C:\Program Files\Common Files\Windows Favorites\ezLink_svc.exe
[05-SERVICE]**ez-Plus -/- Windows ez-Plus V.1.1 -/- C:\Program Files\Common Files\EZ-Plus\ez-PlusSC.exe
[05-SERVICE]**FileDown Services -/- FileDown Services -/- C:\Documents and Settings\Administrator\Application Data\filedown_new\FDUpSvc.exe
[05-SERVICE]**flashlinkerservice -/- Flashlinker Service -/- C:\WINDOWS\system32\flashlinker-se.exe
[05-SERVICE]**FsUsbExService -/- FsUsbExService -/- C:\WINDOWS\system32\FsUsbExService.Exe
[05-SERVICE]**GCRunS -/- GCodec Service -/- C:\PROGRA~1\GCodec\gcodecsvc.exe
[05-SERVICE]**GobugizipService -/- GobugizipService -/- C:\Program Files\gobugizip\GobugizipService.exe
[05-SERVICE]**HwRunS -/- HowCodec Service -/- C:\PROGRA~1\howcodec\howcodecsvc.exe
[05-SERVICE]**IKeeper Update Services -/- IKeeper Update Services -/- C:\Program Files\IKeeper\IKeeperSvc.exe
[05-SERVICE]**KaraokeService -/- VIA Karaoke digital mixer Service -/- C:\WINDOWS\system32\KaraokeSer.exe
[05-SERVICE]**LMS -/- Intel(R) Management and Security Application Local Management Service -/- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
[05-SERVICE]**Microsoft Office Groove Audit Service -/- Microsoft Office Groove Audit Service -/- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
[05-SERVICE]**napagent -/- Network Access Protection Agent -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\System32\qagentrt.dll
[05-SERVICE]**NBService -/- NBService -/- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
[05-SERVICE]**NMIndexingService -/- NMIndexingService -/- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
[05-SERVICE]**npkfxsvc -/- npkfxsvc -/- C:\WINDOWS\system32\npkfxsvc.exe
[05-SERVICE]**nvsvc -/- NVIDIA Display Driver Service -/- C:\WINDOWS\system32\nvsvc32.exe
[05-SERVICE]**odserv -/- Microsoft Office Diagnostics Service -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[05-SERVICE]**ose -/- Office Source Engine -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[05-SERVICE]**personalboan Update Service -/- personalboan Support Service -/- C:\WINDOWS\windowreset.exe
[05-SERVICE]**smart-updateservice -/- smart-update service -/- C:\Program Files\smart-update\smart-update-se.exe
[05-SERVICE]**speedmanager Update Service -/- speedmanager Support Service -/- C:\WINDOWS\windatainfoset.exe
[05-SERVICE]**system-updateservice -/- system-update service -/- C:\Program Files\system-update\system-update-se.exe
[05-SERVICE]**UNS -/- Intel(R) Management and Security Application User Notification Service -/- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
[05-SERVICE]**vprotect Update Service -/- vprotect Support Service -/- C:\WINDOWS\windowupdatereset.exe
[05-SERVICE]**Windows aplus -/- Windows aplus -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows aplus\win_aplussvc.exe
[05-SERVICE]**WinnetPlusService -/- WinnetPlusService -/- C:\Program Files\FileNori\winnetplus.exe