프로그램분석

Code : BaCEtfouKnQbSGUD6Sry+nF3sPUQ9E6F4JJ21lKAK18=

프로세스 천국 2013. 11. 5. 16:09

[00-PROCESS]**alg -/- C:\WINDOWS\System32\alg.exe
[00-PROCESS]**ALZip -/- C:\Program Files\ESTsoft\ALZip\ALZip.exe
[00-PROCESS]**aspnet_state -/- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
[00-PROCESS]**AYLaunch -/- C:\Program Files\ESTsoft\ALYac\AYLaunch.exe
[00-PROCESS]**cisvc -/- C:\WINDOWS\system32\cisvc.exe
[00-PROCESS]**clipsrv -/- C:\WINDOWS\system32\clipsrv.exe
[00-PROCESS]**cmd -/- C:\WINDOWS\system32\cmd.exe
[00-PROCESS]**conime -/- C:\WINDOWS\system32\conime.exe
[00-PROCESS]**ctfmon -/- C:\WINDOWS\system32\ctfmon.exe
[00-PROCESS]**dllhost -/- C:\WINDOWS\system32\dllhost.exe
[00-PROCESS]**Explorer -/- C:\WINDOWS\Explorer.EXE
[00-PROCESS]**FlashPlayerUpdateService -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[00-PROCESS]**GoogleCrashHandler -/- C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe
[00-PROCESS]**GoogleUpdate -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[00-PROCESS]**GrooveAuditService -/- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
[00-PROCESS]**GrooveMonitor -/- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[00-PROCESS]**HDeck -/- C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
[00-PROCESS]**hkcmd -/- C:\WINDOWS\system32\hkcmd.exe
[00-PROCESS]**HncUpdate -/- C:\Program Files\Common Files\Hnc\HncUtils\HncUpdate.exe
[00-PROCESS]**hpqimzone -/- C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
[00-PROCESS]**hpqSTE08 -/- C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
[00-PROCESS]**hpqtra08 -/- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
[00-PROCESS]**HPWuSchd2 -/- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[00-PROCESS]**HPZipm12 -/- C:\WINDOWS\system32\HPZipm12.exe
[00-PROCESS]**iexplore -/- C:\Program Files\Internet Explorer\iexplore.exe
[00-PROCESS]**igfxpers -/- C:\WINDOWS\system32\igfxpers.exe
[00-PROCESS]**igfxtray -/- C:\WINDOWS\system32\igfxtray.exe
[00-PROCESS]**imapi -/- C:\WINDOWS\system32\imapi.exe
[00-PROCESS]**IMKRMIG -/- C:\Program Files\Common Files\Microsoft Shared\IME12\IMEKR\IMKRMIG.EXE
[00-PROCESS]**infocard -/- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
[00-PROCESS]**KaraokeSer -/- C:\WINDOWS\system32\KaraokeSer.exe
[00-PROCESS]**locator -/- C:\WINDOWS\system32\locator.exe
[00-PROCESS]**lsass -/- C:\WINDOWS\system32\lsass.exe
[00-PROCESS]**mnmsrvc -/- C:\WINDOWS\system32\mnmsrvc.exe
[00-PROCESS]**mscorsvw -/- c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
[00-PROCESS]**msdtc -/- C:\WINDOWS\system32\msdtc.exe
[00-PROCESS]**msiexec -/- C:\WINDOWS\system32\msiexec.exe
[00-PROCESS]**natsvc -/- C:\Program Files\NAT Service\natsvc.exe
[00-PROCESS]**netdde -/- C:\WINDOWS\system32\netdde.exe
[00-PROCESS]**npkcmsvc -/- C:\WINDOWS\system32\npkcmsvc.exe
[00-PROCESS]**ODSERV -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[00-PROCESS]**OpenKeyword -/- C:\Program Files\OpenKeyword\OpenKeyword.exe
[00-PROCESS]**OpenKeywordAgent -/- C:\Program Files\OpenKeyword\OpenKeywordAgent.exe
[00-PROCESS]**OSE -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[00-PROCESS]**PresentationFontCache -/- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
[00-PROCESS]**quickadmgr -/- C:\Program Files\quickad\quickadmgr.exe
[00-PROCESS]**quickadsvc -/- C:\Program Files\quickad\quickadsvc.exe
[00-PROCESS]**RaRegistry -/- C:\Program Files\ipTIME\Common\RaRegistry.exe
[00-PROCESS]**Reader_sl -/- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
[00-PROCESS]**reflectioninfo -/- C:\Program Files\Information Reflection\reflectioninfo.exe
[00-PROCESS]**reflectioninfos -/- C:\Program Files\Information Reflection\reflectioninfos.exe
[00-PROCESS]**reflectioninfou -/- C:\Program Files\Information Reflection\reflectioninfou.exe
[00-PROCESS]**rimirnmums -/- C:\WINDOWS\rimirnmums.exe
[00-PROCESS]**rsvp -/- C:\WINDOWS\system32\rsvp.exe
[00-PROCESS]**SCardSvr -/- C:\WINDOWS\System32\SCardSvr.exe
[00-PROCESS]**services -/- C:\WINDOWS\system32\services.exe
[00-PROCESS]**sessmgr -/- C:\WINDOWS\system32\sessmgr.exe
[00-PROCESS]**signkey -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\signkey\signkey.exe
[00-PROCESS]**signkeyiey -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\signkey\signkeyiey.exe
[00-PROCESS]**smartmanager -/- C:\Program Files\smartmanager\smartmanager.exe
[00-PROCESS]**smart-update-se -/- C:\Program Files\smart-update\smart-update-se.exe
[00-PROCESS]**smlogsvc -/- C:\WINDOWS\system32\smlogsvc.exe
[00-PROCESS]**smpsvc -/- C:\Program Files\smartmanager\smpsvc.exe
[00-PROCESS]**smpsvt -/- C:\Program Files\smartmanager\smpsvt.exe
[00-PROCESS]**smss -/- C:\WINDOWS\System32\smss.exe
[00-PROCESS]**spoolsv -/- C:\WINDOWS\system32\spoolsv.exe
[00-PROCESS]**SSI -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\SSI\SSI.exe
[00-PROCESS]**SSIagent -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\SSI\SSIagent.exe
[00-PROCESS]**svchost -/- C:\WINDOWS\system32\svchost.exe
[00-PROCESS]**system-update-se -/- C:\Program Files\system-update\system-update-se.exe
[00-PROCESS]**TINTSETP -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
[00-PROCESS]**tlntsvr -/- C:\WINDOWS\system32\tlntsvr.exe
[00-PROCESS]**TopTool -/- C:\Program Files\TopTool\TopTool.exe
[00-PROCESS]**ups -/- C:\WINDOWS\System32\ups.exe
[00-PROCESS]**vssvc -/- C:\WINDOWS\System32\vssvc.exe
[00-PROCESS]**WBPatch -/- C:\Program Files\WindowBoanPatch\WBPatch.exe
[00-PROCESS]**win_applussvc -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows applus\win_applussvc.exe
[00-PROCESS]**windataresetinfo -/- C:\WINDOWS\windataresetinfo.exe
[00-PROCESS]**windoguide -/- C:\Program Files\windoguide\windoguide.exe
[00-PROCESS]**windoguideagent -/- C:\Program Files\windoguide\windoguideagent.exe
[00-PROCESS]**WindowNetworkManager -/- C:\Program Files\Window Network Manager\WindowNetworkManager.exe
[00-PROCESS]**WinKey -/- C:\Program Files\WinKey\WinKey.exe
[00-PROCESS]**winlogon -/- C:\WINDOWS\system32\winlogon.exe
[00-PROCESS]**wmiapsrv -/- C:\WINDOWS\system32\wbem\wmiapsrv.exe
[00-PROCESS]**WMPNetwk -/- C:\Program Files\Windows Media Player\WMPNetwk.exe
[00-PROCESS]**wuauclt -/- C:\WINDOWS\system32\wuauclt.exe
[00-PROCESS]**wuu -/- C:\Program Files\Windows Utility Update\wuu.exe
[01-HKCUREG]**Adobe Reader Speed Launcher -/- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
[01-HKCUREG]**ALYac -/- C:\Program Files\ESTsoft\ALYac\AYLaunch.exe /run
[01-HKCUREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[01-HKCUREG]**GrooveMonitor -/- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[01-HKCUREG]**HDAudDeck -/- C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
[01-HKCUREG]**HncUpdate -/- C:\Program Files\Common Files\Hnc\HncUtils\HncUpdate.exe /A
[01-HKCUREG]**HotKeysCmds -/- C:\WINDOWS\system32\hkcmd.exe
[01-HKCUREG]**HP Software Update -/- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[01-HKCUREG]**IgfxTray -/- C:\WINDOWS\system32\igfxtray.exe
[01-HKCUREG]**Korean IME Migration -/- C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE
[01-HKCUREG]**OpenKeyword -/- C:\Program Files\OpenKeyword\OpenKeywordAgent.exe
[01-HKCUREG]**Persistence -/- C:\WINDOWS\system32\igfxpers.exe
[01-HKCUREG]**PHIME2002A -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
[01-HKCUREG]**PHIME2002ASync -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
[01-HKCUREG]**REFLECTIONS -/- C:\Program Files\Information Reflection\reflectioninfou.exe /run
[01-HKCUREG]**signkey -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\signkey\signkey.exe
[01-HKCUREG]**SSI -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\SSI\SSI.exe /byboot
[01-HKCUREG]**SSIagent -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\SSI\SSIagent.exe
[01-HKCUREG]**TopTool -/- C:\Program Files\TopTool\TopTool.exe
[01-HKCUREG]**windoguide -/- C:\Program Files\windoguide\windoguide.exe
[01-HKCUREG]**windoguideagent -/- C:\Program Files\windoguide\windoguideagent.exe
[01-HKCUREG]**Window Network Manager -/- C:\Program Files\Window Network Manager\WindowNetworkManager.exe
[01-HKCUREG]**WindowBoanPatch -/- C:\Program Files\WindowBoanPatch\WBPatch.exe -startup
[01-HKCUREG]**WinKey -/- C:\Program Files\WinKey\WinKey.exe
[01-HKCUREG]**wuu -/- C:\Program Files\Windows Utility Update\wuu.exe
[02-HKLMREG]**Adobe Reader Speed Launcher -/- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
[02-HKLMREG]**ALYac -/- C:\Program Files\ESTsoft\ALYac\AYLaunch.exe /run
[02-HKLMREG]**ctfmon.exe -/- C:\WINDOWS\system32\ctfmon.exe
[02-HKLMREG]**GrooveMonitor -/- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[02-HKLMREG]**HDAudDeck -/- C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
[02-HKLMREG]**HncUpdate -/- C:\Program Files\Common Files\Hnc\HncUtils\HncUpdate.exe /A
[02-HKLMREG]**HotKeysCmds -/- C:\WINDOWS\system32\hkcmd.exe
[02-HKLMREG]**HP Software Update -/- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[02-HKLMREG]**IgfxTray -/- C:\WINDOWS\system32\igfxtray.exe
[02-HKLMREG]**Korean IME Migration -/- C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE
[02-HKLMREG]**OpenKeyword -/- C:\Program Files\OpenKeyword\OpenKeywordAgent.exe
[02-HKLMREG]**Persistence -/- C:\WINDOWS\system32\igfxpers.exe
[02-HKLMREG]**PHIME2002A -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
[02-HKLMREG]**PHIME2002ASync -/- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
[02-HKLMREG]**REFLECTIONS -/- C:\Program Files\Information Reflection\reflectioninfou.exe /run
[02-HKLMREG]**signkey -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\signkey\signkey.exe
[02-HKLMREG]**SSI -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\SSI\SSI.exe /byboot
[02-HKLMREG]**SSIagent -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\SSI\SSIagent.exe
[02-HKLMREG]**TopTool -/- C:\Program Files\TopTool\TopTool.exe
[02-HKLMREG]**windoguide -/- C:\Program Files\windoguide\windoguide.exe
[02-HKLMREG]**windoguideagent -/- C:\Program Files\windoguide\windoguideagent.exe
[02-HKLMREG]**Window Network Manager -/- C:\Program Files\Window Network Manager\WindowNetworkManager.exe
[02-HKLMREG]**WindowBoanPatch -/- C:\Program Files\WindowBoanPatch\WBPatch.exe -startup
[02-HKLMREG]**WinKey -/- C:\Program Files\WinKey\WinKey.exe
[02-HKLMREG]**wuu -/- C:\Program Files\Windows Utility Update\wuu.exe
[05-SERVICE]**6to4 -/- 6to4 -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\system32\6to432.dll
[05-SERVICE]**AdobeFlashPlayerUpdateSvc -/- Adobe Flash Player Update Service -/- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[05-SERVICE]**ALYac_RTSrv -/- ALYac RealTime Service -/-
[05-SERVICE]**ALYac_UpdSrv -/- ALYac Update Service -/-
[05-SERVICE]**gupdate -/- Google 업데이트 서비스 (gupdate) -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[05-SERVICE]**gupdatem -/- Google 업데이트 서비스 (gupdatem) -/- C:\Program Files\Google\Update\GoogleUpdate.exe
[05-SERVICE]**KaraokeService -/- VIA Karaoke digital mixer Service -/- C:\WINDOWS\system32\KaraokeSer.exe
[05-SERVICE]**Microsoft Office Groove Audit Service -/- Microsoft Office Groove Audit Service -/- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
[05-SERVICE]**napagent -/- Network Access Protection Agent -/- C:\WINDOWS\System32\svchost.exe -/- C:\WINDOWS\System32\qagentrt.dll
[05-SERVICE]**NATService -/- NATService -/- C:\Program Files\NAT Service\natsvc.exe
[05-SERVICE]**npkcmsvc -/- npkcmsvc -/- C:\WINDOWS\system32\npkcmsvc.exe
[05-SERVICE]**odserv -/- Microsoft Office Diagnostics Service -/- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
[05-SERVICE]**ose -/- Office Source Engine -/- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
[05-SERVICE]**Pml Driver HPZ12 -/- Pml Driver HPZ12 -/- C:\WINDOWS\system32\HPZipm12.exe
[05-SERVICE]**quickadsvc -/- quickad -/- C:\Program Files\quickad\quickadsvc.exe
[05-SERVICE]**RalinkRegistryWriter -/- Ralink Registry Writer -/- C:\Program Files\ipTIME\Common\RaRegistry.exe
[05-SERVICE]**rimirnmums -/- Reflect Service Client -/- C:\WINDOWS\rimirnmums.exe
[05-SERVICE]**RunS -/- MultidownLoad Service -/- C:\Documents and Settings\Administrator\APPLIC~1\MULTID~1\MultiDownLoadSvc.exe
[05-SERVICE]**smart-updateservice -/- smart-update service -/- C:\Program Files\smart-update\smart-update-se.exe
[05-SERVICE]**smpsvc32 -/- Windows Smart Pack Service -/- C:\Program Files\smartmanager\smpsvc.exe
[05-SERVICE]**system-updateservice -/- system-update service -/- C:\Program Files\system-update\system-update-se.exe
[05-SERVICE]**Windows applus -/- Windows applus -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows applus\win_applussvc.exe
[05-SERVICE]**windowstab_mon -/- Windows Tab Manager -/- C:\Documents and Settings\Administrator\Local Settings\Application Data\windowstab\windowstab_mon.exe
[05-SERVICE]**winfaster Update Service -/- winfaster Support Service -/- C:\WINDOWS\windataresetinfo.exe
[05-SERVICE]**WinRM -/- Windows Remote Management (WS-Management) -/- C:\WINDOWS\system32\svchost.exe -/- C:\WINDOWS\system32\WsmSvc.dll