프로그램분석

[ZeroBoan] Install log : 46ms / 2012-12-24

프로세스 천국 2012. 12. 24. 12:45

----------------------------------------------------------------------
Created by Windowexe.com , Logfile of WindowexeAllkiller
----------------------------------------------------------------------
Windows 7 Ultimate Service Pack 1(6.1.7601.65536)
Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz / 1,023.55 MB
Intel64 Family 6 Model 37 Stepping 5
Date : 2012-12-24
----------------------------------------------------------------------
DF000 C:\Program Files (x86)\ZeroBoan\ZeroBoan.exe
DF001 C:\Program Files (x86)\ZeroBoan\ZeroBoanMtr.exe
DF002 C:\Program Files (x86)\ZeroBoan\ZeroBoanuck.exe
DF003 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\제로보안\제로보안 제거.lnk
DF004 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\제로보안\제로보안.lnk
DF005 C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\16ZLQ1JG\ZeroBoan_Setup[1].exe
----------------------------------------------------------------------
UN006 제로보안 -/- - -/- ZeroBoan -/- - -/- -
TS007 ZeroBoan
----------------------------------------------------------------------
US008 ZeroBoan -/- C:\Program Files (x86)\ZeroBoan\ZeroBoan.exe /run1
----------------------------------------------------------------------
EXADD Microsoft Web Browser -/- C:\Windows\System32\ieframe.dll -/- {8856F961-340A-11D0-A96B-00C04FD705A2}
EXADD Microsoft Web Browser -/- C:\Windows\SysWOW64\ieframe.dll -/- {8856F961-340A-11D0-A96B-00C04FD705A2}
----------------------------------------------------------------------
----------------------------------------------------------------------
NA001 down.zeroboan.com/install/home/ZeroBoan_Setup*.***
NA002 log.adsence.co.kr/logexp.php?aid=ZeroBoan&kind=inst&pid=*.***
NA003 pay.doctorsecurity.co.kr/npay2/dcash/hp/images/btn_view*.***
NA004 pay.zeroboan.com/images/bg_02*.***
NA005 pay.zeroboan.com/images/bg_03*.***
NA006 pay.zeroboan.com/images/btn_bill*.***
NA007 pay.zeroboan.com/images/ico_a*.***
NA008 pay.zeroboan.com/images/pay_01*.***
NA009 pay.zeroboan.com/npay/dcash/hp/js/Commo*.***
NA010 pay.zeroboan.com/npay/dcash/hp/js/Star*.***
NA011 pay.zeroboan.com/npay/dcash/hp/Start.php3?pid=home&mc=000c293ec**.***
NA012 pay.zeroboan.com/npay/dcash/hp/style*.***
NA013 pay.zeroboan.com/payment.php?sncode=000c293ecd7f&pid=*.***
NA014 update.zeroboan.com/partner/partner_info*.***
NA015 update.zeroboan.com/update_data*.***
NA016 update.zeroboan.com/version*.***
NA017 ww*.zeroboan.com/app/count.php?kind=install&pid=home&os=v*.***
NA018 zeroboan.*.***
NA019 zeroboan.com/favicon*.***
NA020 zeroboan.com/home/download/download.*.***
NA021 zeroboan.com/home/download/img/cate_down_1*.***
NA022 zeroboan.com/home/download/img/cate_home_1*.***
NA023 zeroboan.com/home/download/img/cate_news_1*.***
NA024 zeroboan.com/home/download/img/cate_service_1*.***
NA025 zeroboan.com/home/download/img/down_down_top*.***
NA026 zeroboan.com/home/download/img/down_left_1_0*.***
NA027 zeroboan.com/home/download/img/down_left_2_0*.***
NA028 zeroboan.com/home/download/img/down_left_3_0*.***
NA029 zeroboan.com/home/download/img/down_left_t*.***
NA030 zeroboan.com/home/images/i_new*.***
NA031 zeroboan.com/home/images/main_bn*.***
NA032 zeroboan.com/home/images/main_call_bn*.***
NA033 zeroboan.com/home/images/main_link_bn*.***
NA034 zeroboan.com/home/images/main_notice_body*.***
NA035 zeroboan.com/home/images/main_notice_t*.***
NA036 zeroboan.com/home/images/main_qna_btn*.***
NA037 zeroboan.com/home/images/main_service_btn*.***
NA038 zeroboan.com/home/include/img/btm_copy*.***
NA039 zeroboan.com/home/include/img/cate_back*.***
NA040 zeroboan.com/home/include/img/cate_down_0*.***
NA041 zeroboan.com/home/include/img/cate_down_1*.***
NA042 zeroboan.com/home/include/img/cate_home_0*.***
NA043 zeroboan.com/home/include/img/cate_home_1*.***
NA044 zeroboan.com/home/include/img/cate_news_0*.***
NA045 zeroboan.com/home/include/img/cate_news_1*.***
NA046 zeroboan.com/home/include/img/cate_service_0*.***
NA047 zeroboan.com/home/include/img/cate_service_1*.***
NA048 zeroboan.com/home/include/img/left_call_bn*.***
NA049 zeroboan.com/home/include/img/left_customer_menu*.***
NA050 zeroboan.com/home/include/img/left_download_btn*.***
NA051 zeroboan.com/home/include/img/logo*.***
NA052 zeroboan.com/home/include/index.*.***
NA053 zeroboan.com/home/lib/mp_style*.***
NA054 zeroboan.com/lib/uti*.***
NA055 zeroboan.comzeroboan.com/apps/appset.php?pid=*.***
NA056 zeroboan.comzeroboan.com/apps/licensechk.php?sncode=000c**.***
----------------------------------------------------------------------
----------------------------------------------------------------------
Deleted Files : 6
Remove Uninstall Entry : 1
Remove Startup Entry : 1
----------------------------------------------------------------------
Remove these Entry in a WindowexeAllkiller.txt file. Save and Run.
WindowexeAllkiller Remove Database 2012-12-24
[01-HKCUREG]**ZeroBoan

----------------------------------------------------------------------
Total Processing Time : 46ms
----------------------------------------------------------------------
NA001 ======================================================================
NA002 echo Created by Windowexe.com / do not delete this label.
NA003 ======================================================================
NA004 echo Start
NA005 echo windowexe.com & tskill "ZeroBoanuck" & echo windowdel.com
NA006 echo windowexe.com & tskill "ZeroBoanuck" & echo windowdel.com
NA007 echo windowexe.com & tskill "ZeroBoanMtr" & echo windowdel.com
NA008 echo windowexe.com & tskill "ZeroBoanMtr" & echo windowdel.com
NA009 echo windowexe.com & tskill "ZeroBoan" & echo windowdel.com
NA010 echo windowexe.com & tskill "ZeroBoan" & echo windowdel.com
NA011 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "ZeroBoan" /f
NA012 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "ZeroBoan" /f
NA013 echo schtasks Delete & schtasks /delete /tn "ZeroBoan" /f
NA014 echo Created by Windowexe.com
NA015 echo change dir for x64
NA016 cd %windir%
NA017 cd syswow64
NA018 echo windowexe.com & tskill "ZeroBoanuck" & echo windowdel.com
NA019 echo windowexe.com & tskill "ZeroBoanuck" & echo windowdel.com
NA020 echo windowexe.com & tskill "ZeroBoanMtr" & echo windowdel.com
NA021 echo windowexe.com & tskill "ZeroBoanMtr" & echo windowdel.com
NA022 echo windowexe.com & tskill "ZeroBoan" & echo windowdel.com
NA023 echo windowexe.com & tskill "ZeroBoan" & echo windowdel.com
NA024 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "ZeroBoan" /f
NA025 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "ZeroBoan" /f
NA026 echo schtasks Delete & schtasks /delete /tn "ZeroBoan" /f
NA027 echo Created by Windowexe.com
NA028 echo End
NA029 ======================================================================
NA030 echo Created by Windowexe.com / do not delete this label.
NA031 ======================================================================