프로그램분석

[link***n] Win32/Trojan downloader Report : 275ms

프로세스 천국 2011. 6. 10. 12:03

----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Microsoft Windows XP Service Pack 3(5.1.2600.196608)
Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz / 767.48 MB
x86 Family 6 Model 37 Stepping 5
Date : 2011-06-09
----------------------------------------------------------------------
DF000 C:\Documents and Settings\Administrator\Application Data\Temp\antidefend_hanpan.exe
DF001 C:\Documents and Settings\Administrator\Application Data\Temp\ClipViewSetup.exe
DF002 C:\Documents and Settings\Administrator\Application Data\Temp\CShortCut.exe
DF003 C:\Documents and Settings\Administrator\Application Data\Temp\privacyview_hanpan.exe
DF004 C:\Documents and Settings\Administrator\Application Data\Temp\setup_c3h009.exe
DF005 C:\Documents and Settings\Administrator\Application Data\Temp\SevenlinkInstall.exe
DF006 C:\Documents and Settings\Administrator\Application Data\Temp\SmartTool_bizt06_s.exe
DF007 C:\Documents and Settings\Administrator\My Documents\CCLEANER[1]\CCLEANER.exe
DF008 C:\Program Files\AntiDefend\ADAutoUpdate.exe
DF009 C:\Program Files\AntiDefend\ADEngine.dll
DF010 C:\Program Files\AntiDefend\AntiDefend.exe
DF011 C:\Program Files\AntiDefend\db\filter.dll
DF012 C:\Program Files\AntiDefend\db\inter.dll
DF013 C:\Program Files\AntiDefend\etc\ADFilterDriver.SYS
DF014 C:\Program Files\AntiDefend\etc\adMon.exe
DF015 C:\Program Files\AntiDefend\etc\ADmonRemote.dll
DF016 C:\Program Files\AntiDefend\etc\adReg.exe
DF017 C:\Program Files\AntiDefend\Uninstall.exe
DF018 C:\Program Files\clipview\clipview.exe
DF019 C:\Program Files\clipview\clipview_setup.exe
DF020 C:\Program Files\clipview\ClipViewUpdate.exe
DF021 C:\Program Files\clipview\unins000.exe
DF022 C:\Program Files\PrivacyView\PrivacyView.exe
DF023 C:\Program Files\PrivacyView\PrivacyViewcfg.exe
DF024 C:\Program Files\PrivacyView\PrivacyViewMon.exe
DF025 C:\Program Files\PrivacyView\Uninstall.exe
DF026 C:\Program Files\Sevenlink\sevenlink.exe
DF027 C:\Program Files\Sevenlink\Uninstall.exe
DF028 C:\Program Files\WinsHelp\sqlite3.dll
DF029 C:\Program Files\WinsHelp\uninst1.exe
DF030 C:\Program Files\WinsHelp\winshelpb8.dll
DF031 C:\Program Files\WinsHelp\winshelps8.dll
DF032 C:\Program Files\WinsHelp\winshelpu.exe
DF033 C:\WINDOWS\Temp\setup_wc_c3h009_1.1.0.8(202406).exe
----------------------------------------------------------------------
SC034 Windows WinsHelp Update Service -/- Windows WinsHelp Update Service -/- - -/-  -/- C:\Program Files\WinsHelp\winshelpu.exe
----------------------------------------------------------------------
UN035 AntiDefend -/- - -/- AntiDefendMain -/- - -/- -
UN036 clipview v1.0 -/- ClipView, Inc. -/- ClipView_is1 -/- - -/- -
UN037 프라이버시뷰 -/- - -/- PrivacyView -/- - -/- -
----------------------------------------------------------------------
US038 clipview -/- C:\Program Files\clipview\clipview.exe
LS039 AntiDefendMain -/- C:\Program Files\AntiDefend\AntiDefend.exe /Boot
LS040 PrivacyView -/- C:\Program Files\PrivacyView\PrivacyView.exe /run1
LS041 sevenlink -/- C:\Program Files\Sevenlink\sevenlink.exe
----------------------------------------------------------------------
A001 yeongasi.kr
A002 update.privacyview.co.kr
A003 update.antidefend.com
A004 log.adsence.co.kr
A005 file.winshelp.net
A006 click.bizsearch.co.kr
A007 cilpview.com
A008 bugsticket.co.kr
A009 ag.winshelp.net
A010 ***.privacyview.co.kr
A011 ***.antidefend.com
----------------------------------------------------------------------
Deleted Files : 34
Remove Service : 1
Remove Uninstall Entry : 3
Remove Startup Entry : 4
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
[01-HKCUREG]**clipview
[02-HKLMREG]**AntiDefendMain
[02-HKLMREG]**PrivacyView
[02-HKLMREG]**sevenlink
[05-SERVICE]**Windows WinsHelp Update Service
----------------------------------------------------------------------
Total Processing Time : 275ms
----------------------------------------------------------------------
What's new : LS041 sevenlink -/- C:\Program Files\Sevenlink\sevenlink.exe
----------------------------------------------------------------------