프로그램분석

[VaccineToolbar] Install log : 73ms / 2012-11-09

프로세스 천국 2012. 11. 9. 00:22

----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Windows 7 Ultimate Service Pack 1(6.1.7601.65536)
Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz / 1,023.55 MB
Intel64 Family 6 Model 37 Stepping 5
Date : 2012-11-09
----------------------------------------------------------------------
DF000 C:\Program Files (x86)\vaccinetoolbar\EGutil.dll
DF001 C:\Program Files (x86)\vaccinetoolbar\vaccinetoolbar.dll
DF002 C:\Program Files (x86)\vaccinetoolbar\vaccinetoolbar.exe
DF003 C:\Program Files (x86)\vaccinetoolbar\vaccinetoolbarctl.exe
DF004 C:\Program Files (x86)\vaccinetoolbar\vaccinetoolbard.dll
DF005 C:\Program Files (x86)\vaccinetoolbar\vaccinetoolbarsvc.exe
DF006 C:\Users\Administrator\Desktop\vaccinetoolbar.lnk
DF007 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
DF008 C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D96M9V6E\vaccinetoolbarsetup[1].exe
----------------------------------------------------------------------
SC009 VaccineToolbar Service -/- VaccineToolbar Service -/- - -/-  -/- "C:\Program Files (x86)\vaccinetoolbar\vaccinetoolbarsvc.exe" /service
----------------------------------------------------------------------
NA001 update.vaccinetoolbar.co.kr/bin/EGutil*.***
NA002 update.vaccinetoolbar.co.kr/bin/vaccinetoolbar*.***
NA003 update.vaccinetoolbar.co.kr/bin/vaccinetoolbar*.***
NA004 update.vaccinetoolbar.co.kr/bin/vaccinetoolbar_uninstall*.***
NA005 update.vaccinetoolbar.co.kr/bin/vaccinetoolbarctl*.***
NA006 update.vaccinetoolbar.co.kr/bin/vaccinetoolbard*.***
NA007 update.vaccinetoolbar.co.kr/bin/vaccinetoolbarsvc*.***
NA008 update.vaccinetoolbar.co.kr/setupa/vaccinetoolbarsetup*.***
NA009 vaccinetoolbar.co*.***
NA010 vaccinetoolbar.co.kr/css/board*.***
NA011 vaccinetoolbar.co.kr/css/default*.***
NA012 vaccinetoolbar.co.kr/css/layout*.***
NA013 vaccinetoolbar.co.kr/dbk*.***
NA014 vaccinetoolbar.co.kr/etc/yak*.***
NA015 vaccinetoolbar.co.kr/imgs/common/bg_footer*.***
NA016 vaccinetoolbar.co.kr/imgs/common/f_logo*.***
NA017 vaccinetoolbar.co.kr/imgs/common/fnb_1*.***
NA018 vaccinetoolbar.co.kr/imgs/common/fnb_2*.***
NA019 vaccinetoolbar.co.kr/imgs/common/fnb_3*.***
NA020 vaccinetoolbar.co.kr/imgs/common/fnb_5*.***
NA021 vaccinetoolbar.co.kr/imgs/common/fnb_7*.***
NA022 vaccinetoolbar.co.kr/imgs/common/gnb_home*.***
NA023 vaccinetoolbar.co.kr/imgs/common/gnb_mail*.***
NA024 vaccinetoolbar.co.kr/imgs/common/gnb_notice*.***
NA025 vaccinetoolbar.co.kr/imgs/common/gnb_update*.***
NA026 vaccinetoolbar.co.kr/imgs/common/ico_dot*.***
NA027 vaccinetoolbar.co.kr/imgs/common/logo*.***
NA028 vaccinetoolbar.co.kr/imgs/common/p_address*.***
NA029 vaccinetoolbar.co.kr/imgs/main/btn_service1*.***
NA030 vaccinetoolbar.co.kr/imgs/main/btn_service2*.***
NA031 vaccinetoolbar.co.kr/imgs/main/btn_service3*.***
NA032 vaccinetoolbar.co.kr/imgs/main/h2_customer*.***
NA033 vaccinetoolbar.co.kr/imgs/main/h2_download*.***
NA034 vaccinetoolbar.co.kr/imgs/main/h2_notice*.***
NA035 vaccinetoolbar.co.kr/imgs/main/h2_service*.***
NA036 vaccinetoolbar.co.kr/imgs/main/p_customer*.***
NA037 vaccinetoolbar.co.kr/imgs/main/p_download*.***
NA038 vaccinetoolbar.co.kr/imgs/main/spot_main*.***
NA039 vaccinetoolbar.co.kr/mbk.php?v1=vaccinetoolbar&v2=00:0C:29:3E:C**.***
NA040 vaccinetoolbar.co.kr/script/flas*.***
NA041 vaccinetoolbar.co.kr/script/to*.***
NA042 vaccinetoolbar.co.kr/swf/lnb.swf?pageNum=1&subN*.***
----------------------------------------------------------------------
NA001 ======================================================================
NA002 echo Created by Windowexe.com / do not delete this label.
NA003 ======================================================================
NA004 echo Start
NA005 echo windowexe.com & tskill "vaccinetoolbarsvc" & echo windowdel.com
NA006 echo windowexe.com & tskill "vaccinetoolbarsvc" & echo windowdel.com
NA007 echo windowexe.com & tskill "vaccinetoolbar" & echo windowdel.com
NA008 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA009 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA010 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA011 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA012 echo Created by Windowexe.com
NA013 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA014 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA015 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA016 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA017 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA018 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA019 echo Created by Windowexe.com
NA020 sc stop "VaccineToolbar Service"
NA021 echo Service Disable & sc config "VaccineToolbar Service" start= disabled & echo Windowexe.com
NA022 echo change dir for x64
NA023 cd %windir%
NA024 cd syswow64
NA025 echo windowexe.com & tskill "vaccinetoolbarsvc" & echo windowdel.com
NA026 echo windowexe.com & tskill "vaccinetoolbarsvc" & echo windowdel.com
NA027 echo windowexe.com & tskill "vaccinetoolbar" & echo windowdel.com
NA028 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA029 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA030 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA031 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA032 echo Created by Windowexe.com
NA033 echo HKEY_LOCAL_MACHINE Toolbar Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA034 echo HKEY_CURRENT_USER Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA035 echo HKCU Search Hook Delete & reg.exe delete "HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" /v "{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA036 echo HKEY_LOCAL_MACHINE Ext PreApproved Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA037 echo HKEY_CURRENT_USER Ext Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA038 echo HKEY_CLASSES_ROOT CLSID Delete & reg.exe delete "HKCR\CLSID\{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}" /f
NA039 echo Created by Windowexe.com
NA040 sc stop "VaccineToolbar Service"
NA041 echo Service Disable & sc config "VaccineToolbar Service" start= disabled & echo Windowexe.com
NA042 echo End
NA043 ======================================================================
NA044 echo Created by Windowexe.com / do not delete this label.
NA045 ======================================================================
----------------------------------------------------------------------
BH010 VaccineToolbar -/- C:\Program Files (x86)\vaccinetoolbar\vaccinetoolbar.dll -/- {5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}
EXADD Shockwave Flash Object -/- C:\Windows\system32\Macromed\Flash\Flash64_11_1_102.ocx -/- {D27CDB6E-AE6D-11CF-96B8-444553540000}
EXADD VaccineToolbar -/- C:\Program Files (x86)\vaccinetoolbar\vaccinetoolbar.dll -/- {5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}
EXADD Shockwave Flash Object -/- C:\Windows\SysWOW64\Macromed\Flash\Flash11g.ocx -/- {D27CDB6E-AE6D-11CF-96B8-444553540000}
----------------------------------------------------------------------
----------------------------------------------------------------------
TB011 VaccineToolbar -/- C:\Program Files (x86)\vaccinetoolbar\vaccinetoolbar.dll -/- {5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}
----------------------------------------------------------------------
----------------------------------------------------------------------
Deleted Files : 9
Remove Service : 1
Remove Browser Helper Object : 1
Remove Toolbar : 1
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
WindowexeAllkiller Remove Database 2012-11-09
[03-BHOCLSD]**{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}
[04-TOOLBAR]**{5732A6EC-AA3D-45D4-829C-6A2A39FF5CFA}
[05-SERVICE]**VaccineToolbar Service
----------------------------------------------------------------------
Total Processing Time : 73ms
----------------------------------------------------------------------