프로그램분석

[kcc.Adware.Package] 설치 및 삭제로그 : 782ms

프로세스 천국 2011. 4. 23. 06:58
----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Microsoft Windows XP Service Pack 2(5.1.2600.131072)
Genuine Intel(R) CPU T2300 , 1.66GHz / 311.48 MB
x86 Family 6 Model 14 Stepping 8
Date : 2011-04-23
----------------------------------------------------------------------
S001 wsuvav - Windows Live Smart Update Service - C:\Program Files\Windows Live Smart Update .NETAV\wsuvav.exe -
----------------------------------------------------------------------
D001 C:\Documents and Settings\Administrator\Application Data\Torrenser\Torrenser.exe
D002 C:\Documents and Settings\Administrator\Application Data\Torrenser\TorrenserClient.exe
D003 C:\Documents and Settings\Administrator\Application Data\Torrenser\TorrenserLog.exe
D004 C:\Documents and Settings\Administrator\Application Data\Torrenser\Uninstall.exe
D005 C:\Documents and Settings\Administrator\Application Data\Torrenser\utorrent.exe
D006 C:\Documents and Settings\Administrator\Local Settings\Application Data\smartfinder\smartfinder.dll
D007 C:\Documents and Settings\Administrator\Local Settings\Application Data\smartfinder\smartfinders.exe
D008 C:\Documents and Settings\Administrator\Local Settings\Application Data\smartfinder\smartfinders_sp.exe
D009 C:\Documents and Settings\Administrator\Local Settings\Application Data\smartfinder\uninstall.exe
D010 C:\Program Files\atbfsh.exe
D011 C:\Program Files\EasyFavo\EasyFavo.exe
D012 C:\Program Files\EasyFavo\EasyFavoUninst.exe
D013 C:\Program Files\F2Day\f2dalimi.exe
D014 C:\Program Files\F2Day\f2ddel.exe
D015 C:\Program Files\F2Day\f2ddll.dll
D016 C:\Program Files\F2Day\f2dmain.exe
D017 C:\Program Files\F2Day\f2dupdater.exe
D018 C:\Program Files\F2Day\f2dux.exe
D019 C:\Program Files\fun\funtop\dynamic.exe
D020 C:\Program Files\fun\funtop\inst.exe
D021 C:\Program Files\fun\funtop\MainOpen.exe
D022 C:\Program Files\fun\funtop\uninst.exe
D023 C:\Program Files\GuideOn\GuideOn.dll
D024 C:\Program Files\GuideOn\GuideOn.exe
D025 C:\Program Files\GuideOn\uninstall.exe
D026 C:\Program Files\KinPle\KINPle.exe
D027 C:\Program Files\KinPle\KinPleStart.exe
D028 C:\Program Files\KinPle\KPUpdate.exe
D029 C:\Program Files\MicroLab\ieframe.dll
D030 C:\Program Files\MicroLab\MicroLabCon.exe
D031 C:\Program Files\MicroLab\MicroLabProc.exe
D032 C:\Program Files\MicroLab\Uninstall.exe
D033 C:\Program Files\onBar\onbar.dll
D034 C:\Program Files\onBar\onuninstall.exe
D035 C:\Program Files\onBar\onupdate.exe
D036 C:\Program Files\PcGkimi\PcGkimi.exe
D037 C:\Program Files\PcGkimi\PcGkimicfg.exe
D038 C:\Program Files\PcGkimi\PcGkimiMon.exe
D039 C:\Program Files\PcGkimi\uninst.exe
D040 C:\Program Files\PostTip\PostTip.dll
D041 C:\Program Files\PostTip\PostTip.exe
D042 C:\Program Files\PostTip\uninstall.exe
D043 C:\Program Files\SearchLite\SearchLite.dll
D044 C:\Program Files\SearchLite\SearchLite.exe
D045 C:\Program Files\SearchLite\SLHelper.dll
D046 C:\Program Files\SearchLite\uninstall.exe
D047 C:\Program Files\smartscan\smartscan.exe
D048 C:\Program Files\smartscan\smartscanBK.exe
D049 C:\Program Files\smartscan\smartscandm.exe
D050 C:\Program Files\smartscan\smartscanU.exe
D051 C:\Program Files\SmartTool\SmartTool.dll
D052 C:\Program Files\SmartTool\SmartTool.exe
D053 C:\Program Files\SmartTool\Uninstall.exe
D054 C:\Program Files\werpingt2\asycfilt.dll
D055 C:\Program Files\werpingt2\msvbvm60.dll
D056 C:\Program Files\werpingt2\oleaut32.dll
D057 C:\Program Files\werpingt2\olepro32.dll
D058 C:\Program Files\werpingt2\uninst.exe
D059 C:\Program Files\werpingt2\werpingt2.dll
D060 C:\Program Files\werpingt2\werpingt2.exe
D061 C:\Program Files\Windows Live Smart Update .NETAV\Uninstall.exe
D062 C:\Program Files\Windows Live Smart Update .NETAV\wsucav.exe
D063 C:\Program Files\Windows Live Smart Update .NETAV\wsueav.dll
D064 C:\Program Files\Windows Live Smart Update .NETAV\wsupav.exe
D065 C:\Program Files\Windows Live Smart Update .NETAV\wsuvav.exe
D066 C:\Program Files\Windows Safe Search AV30\Uninstall.exe
D067 C:\Program Files\Windows Safe Search AV30\winsscore.dll
D068 C:\Program Files\Windows Safe Search AV30\winssearch.exe
D073 C:\WINDOWS\atbfsh.exe
D074 C:\WINDOWS\bcmate.exe
D075 C:\WINDOWS\delf2ddll.exe
D076 C:\WINDOWS\dynamic_setup11.exe
D077 C:\WINDOWS\EasyFavoSetup.exe
D078 C:\WINDOWS\f2dinstall.exe
D079 C:\WINDOWS\GuideOn__GO45.exe
D080 C:\WINDOWS\install_p1.exe
D081 C:\WINDOWS\KinpleSetup_p058.exe
D082 C:\WINDOWS\oninstall.exe
D083 C:\WINDOWS\PcGkimi_cold_rs.exe
D084 C:\WINDOWS\PlusTab__PT06.exe
D085 C:\WINDOWS\PostTip__IP70.exe
D086 C:\WINDOWS\SearchLite__SL25.exe
D087 C:\WINDOWS\system32\KPDelete.exe
D088 C:\WINDOWS\system32\uninst_smartscan.exe
D089 C:\WINDOWS\ToolOn_kit.exe
D090 C:\WINDOWS\Translation.exe
D091 C:\WINDOWS\werpingt2_setup.exe
----------------------------------------------------------------------
A001 upstat.smartscan.co.kr
A002 update.smartscan.co.kr
A003 up1.popgame.co.kr
A004 up.smartfinder.kr
A005 up.enterpop.co.kr
A006 smartscan.co.kr
A007 sm.plustab.co.kr
A008 searchlite.co.kr
A009 postip.sidetab.co.kr
A010 player.kinple.com
A011 pcgkimi.com
A012 netcom.byus.net
A013 naver.com
A014 micronames.co.kr
A015 kinple.com
A016 kgo3.com
A017 IXBFYFFBX.dgplayshop.com
A018 guideon.sidegreen.com
A019 file.sidetab.co.kr
A020 file.sidegreen.com
A021 file.plustab.co.kr
A022 favoclick.com
A023 dw.toolon.co.kr
A024 download.kinple.com
A025 download.keysearch.co.kr
A026 down.pcgkimi.com
A027 down.feel2day.com
A028 down.easyfavo.com
A029 admin.torrenser.com
A030 ad.werping.com
A031 ad.kinple.com
A032 221.143.43.151
A033 220.73.162.8
A034 220.73.162.6
A035 218.232.110.66
A036 ***.torrenser.net
A037 ***.smartscan.co.kr
A038 ***.smartfinder.kr
A039 ***.onbar.co.kr
A040 ***.naver.com
A041 ***.makevalue.com
A042 ***.keysearch.co.kr
A043 ***.itemprice.kr
A044 ***.gagalive.kr
A045 ***.funad.co.kr
A046 ***.dynamicicon.co.kr
----------------------------------------------------------------------
C065 Windows Dynamic ShortCut. | dynamic | dynamic |  | -
C066 EasyFavo | - | EasyFavo | - | -
C067 Feel 2 Day | feel2day, Inc. | F2Day |
C068 GuideOn | - | GuideOn | - | -
C069 Windows Music KinplePlay | KINPLE | Kinple | - |
C070 Micronames Multi Language Convert Service | - | Micronames Multi Language Convert Service | - | -
C071 onBar | - | onBar | - | -
C072 피씨지키미 | - | PcGkimi | - | -
C073 PostTip | - | PostTip | - | -
C074 SearchLite | - | SearchLite | - | -
C075 Win Search forsmartfinder | - | smartfinder | - | -
C076 smartscan | - | smartscan |
C077 SmartTool 제거 | - | SmartTool | - | -
C078 Torrenser 1.03 | - | Torrenser 1.03 | - | -
C079 werpingt2 | - | werpingt2 | - | -
C080 Windows Safe Search AV30 | - | Windows Safe Search AV30 | - | -
C081 Windows Live Smart Update 3.0 | - | wsurav | - | -
----------------------------------------------------------------------
U082 smartfindervk - C:\Documents and Settings\Administrator\Local Settings\Application Data\smartfinder\smartfinders_sp.exe
U083 MicroLabCon - C:\Program Files\MicroLab\MicroLabCon.exe
L084 SearchLite - C:\Program Files\SearchLite\SearchLite.exe
L085 PcGkimi - C:\Program Files\PcGkimi\PcGkimi.exe /run1
L086 onBar - C:\Program Files\onBar\onupdate.exe
L087 EasyFavo - C:\Program Files\EasyFavo\EasyFavo.exe /update
L088 GuideOn - C:\Program Files\GuideOn\GuideOn.exe
L089 dynamic - C:\Program Files\fun\funtop\dynamic.exe
L090 PostTip - C:\Program Files\PostTip\PostTip.exe
L091 F2Day - C:\Program Files\F2Day\f2dupdater.exe
L092 smartscanS - C:\Program Files\smartscan\smartscanU.exe
L093 KINPle Update Check - C:\Program Files\KinPle\\KinPleStart.exe
L094 SmartTool - C:\Program Files\SmartTool\SmartTool.exe
L095 ntasvr - C:\Program Files\Windows Safe Search AV30\winssearch.exe
L096 atbfsh.exe - C:\Program Files\\atbfsh.exe
----------------------------------------------------------------------
B097  - C:\PROGRA~1\onBar\onbar.dll - {0C8AF4E4-03FF-42F0-B130-C5174E799A09}
B098 SmartToolCtl Class - C:\Program Files\SmartTool\SmartTool.dll - {2D891923-34B7-4186-9B47-752624535DC1}
B099 O - C:\DOCUME~1\ADMINI~1\LOCALS~1\APPLIC~1\SMARTF~1\SMARTF~1.DLL - {3BA7920F-08E7-4840-AAF3-1256BE12ACC3}
B100 GuideHelper Class - C:\Program Files\GuideOn\GuideOn.dll - {6704E2EA-6213-4d17-BB3D-4AE9E3609536}
B101 IECtrl Class - C:\PROGRA~1\F2Day\f2ddll.dll - {91C1AE56-D2C9-4017-8BF1-75EA182CEB38}
B102 ExplorerManager Class - C:\PROGRA~1\WERPIN~1\WERPIN~1.DLL - {AA4E73CB-0853-41F1-98FF-8425F1FAF463}
B103 SLHelperCtl Class - C:\Program Files\SearchLite\SLHelper.dll - {ACB8FE57-01FF-4E61-A2E2-4FB54C77A0E7}
B104 PostTip - C:\Program Files\PostTip\PostTip.dll - {C4BF6897-41A2-454b-AC3B-437F30BEA671}
B105 WinSS Search Class - C:\Program Files\Windows Safe Search AV30\winsscore.dll - {FFDE727F-3330-45EB-B9F9-C1668E6E08B2}
----------------------------------------------------------------------
Remove Service : 1
Deleted Files : 63
Remove Uninstall Entry : 17
Remove Startup Entry : 15
Remove Browser Helper Object : 9
Process Failure : 0
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
[01-HKCUREG]**smartfindervk
[01-HKCUREG]**MicroLabCon
[02-HKLMREG]**SearchLite
[02-HKLMREG]**PcGkimi
[02-HKLMREG]**onBar
[02-HKLMREG]**EasyFavo
[02-HKLMREG]**GuideOn
[02-HKLMREG]**dynamic
[02-HKLMREG]**PostTip
[02-HKLMREG]**F2Day
[02-HKLMREG]**smartscanS
[02-HKLMREG]**KINPle Update Check
[02-HKLMREG]**SmartTool
[02-HKLMREG]**ntasvr
[02-HKLMREG]**atbfsh.exe
[03-BHOCLSD]**{0C8AF4E4-03FF-42F0-B130-C5174E799A09}
[03-BHOCLSD]**{2D891923-34B7-4186-9B47-752624535DC1}
[03-BHOCLSD]**{3BA7920F-08E7-4840-AAF3-1256BE12ACC3}
[03-BHOCLSD]**{6704E2EA-6213-4d17-BB3D-4AE9E3609536}
[03-BHOCLSD]**{91C1AE56-D2C9-4017-8BF1-75EA182CEB38}
[03-BHOCLSD]**{AA4E73CB-0853-41F1-98FF-8425F1FAF463}
[03-BHOCLSD]**{ACB8FE57-01FF-4E61-A2E2-4FB54C77A0E7}
[03-BHOCLSD]**{C4BF6897-41A2-454b-AC3B-437F30BEA671}
[03-BHOCLSD]**{FFDE727F-3330-45EB-B9F9-C1668E6E08B2}
[05-SERVICE]**wsuvav
----------------------------------------------------------------------
Total Processing Time : 782ms
----------------------------------------------------------------------
What's new : smartfinders_sp.exe
----------------------------------------------------------------------