프로그램분석

Code : XxCRuCvVv5tPVVNYLZlYsifTKgRGFQCQ

프로세스 천국 2013. 2. 7. 14:13

System Analyzer Report 2013, 02, 07

NA001 ======================================================================
NA002 echo Created by Windowexe.com / do not delete this label.
NA003 ======================================================================
NA004 echo Start
NA005 echo windowexe.com & tskill "ancamcorderupdate" & echo windowdel.com
NA006 echo windowexe.com & tskill "IPlusUpdate_ze" & echo windowdel.com
NA007 echo windowexe.com & tskill "Badakencoder_update" & echo windowdel.com
NA008 echo windowexe.com & tskill "adbrowser" & echo windowdel.com
NA009 echo windowexe.com & tskill "barosvc" & echo windowdel.com
NA010 echo windowexe.com & tskill "best-pcse" & echo windowdel.com
NA011 echo windowexe.com & tskill "ctpopsvc" & echo windowdel.com
NA012 echo windowexe.com & tskill "direcon" & echo windowdel.com
NA013 echo windowexe.com & tskill "GDownService" & echo windowdel.com
NA014 echo windowexe.com & tskill "gomhelpersvc" & echo windowdel.com
NA015 echo windowexe.com & tskill "KUploadService" & echo windowdel.com
NA016 echo windowexe.com & tskill "nnlogon" & echo windowdel.com
NA017 echo windowexe.com & tskill "uptoolsvc" & echo windowdel.com
NA018 echo windowexe.com & tskill "wepsv" & echo windowdel.com
NA019 echo windowexe.com & tskill "WBPatchCntr" & echo windowdel.com
NA020 echo windowexe.com & tskill "intsfsrv" & echo windowdel.com
NA021 echo windowexe.com & tskill "winspop" & echo windowdel.com
NA022 echo windowexe.com & tskill "winspsv" & echo windowdel.com
NA023 echo windowexe.com & tskill "wssvrelv" & echo windowdel.com
NA024 echo windowexe.com & tskill "FBDSvcMan" & echo windowdel.com
NA025 echo windowexe.com & tskill "inforesetupdate" & echo windowdel.com
NA026 echo windowexe.com & tskill "svcspwin" & echo windowdel.com
NA027 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "direcon" /f
NA028 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "direcon" /f
NA029 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA030 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA031 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA032 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA033 echo Created by Windowexe.com
NA034 sc stop "barocn"
NA035 echo Service Disable & sc config "barocn" start= disabled & echo Windowexe.com
NA036 sc stop "best-pcService"
NA037 echo Service Disable & sc config "best-pcService" start= disabled & echo Windowexe.com
NA038 sc stop "BNDownService"
NA039 echo Service Disable & sc config "BNDownService" start= disabled & echo Windowexe.com
NA040 sc stop "ctwopop"
NA041 echo Service Disable & sc config "ctwopop" start= disabled & echo Windowexe.com
NA042 sc stop "efinderservice"
NA043 echo Service Disable & sc config "efinderservice" start= disabled & echo Windowexe.com
NA044 sc stop "FBDSvcman"
NA045 echo Service Disable & sc config "FBDSvcman" start= disabled & echo Windowexe.com
NA046 sc stop "GomHelper Update Services"
NA047 echo Service Disable & sc config "GomHelper Update Services" start= disabled & echo Windowexe.com
NA048 sc stop "InternetSafer Protector"
NA049 echo Service Disable & sc config "InternetSafer Protector" start= disabled & echo Windowexe.com
NA050 sc stop "koltyduyiu"
NA051 echo Service Disable & sc config "koltyduyiu" start= disabled & echo Windowexe.com
NA052 sc stop "KService"
NA053 echo Service Disable & sc config "KService" start= disabled & echo Windowexe.com
NA054 sc stop "NetAccelerator"
NA055 echo Service Disable & sc config "NetAccelerator" start= disabled & echo Windowexe.com
NA056 sc stop "NSpeedMeterManager"
NA057 echo Service Disable & sc config "NSpeedMeterManager" start= disabled & echo Windowexe.com
NA058 sc stop "ServiceHost SH123"
NA059 echo Service Disable & sc config "ServiceHost SH123" start= disabled & echo Windowexe.com
NA060 sc stop "userpc Update Service"
NA061 echo Service Disable & sc config "userpc Update Service" start= disabled & echo Windowexe.com
NA062 sc stop "UTool"
NA063 echo Service Disable & sc config "UTool" start= disabled & echo Windowexe.com
NA064 sc stop "wepop"
NA065 echo Service Disable & sc config "wepop" start= disabled & echo Windowexe.com
NA066 sc stop "WindowBoanPatch OEM Monitoring Center"
NA067 echo Service Disable & sc config "WindowBoanPatch OEM Monitoring Center" start= disabled & echo Windowexe.com
NA068 sc stop "WindowsDriver"
NA069 echo Service Disable & sc config "WindowsDriver" start= disabled & echo Windowexe.com
NA070 sc stop "WindowSearch Service Manager"
NA071 echo Service Disable & sc config "WindowSearch Service Manager" start= disabled & echo Windowexe.com
NA072 sc stop "winspsv32"
NA073 echo Service Disable & sc config "winspsv32" start= disabled & echo Windowexe.com
NA074 sc stop "WinsPop Service"
NA075 echo Service Disable & sc config "WinsPop Service" start= disabled & echo Windowexe.com
NA076 sc stop "Windows WinsPop Diagnostics Service"
NA077 echo Service Disable & sc config "Windows WinsPop Diagnostics Service" start= disabled & echo Windowexe.com
NA078 sc stop "nassvc"
NA079 echo Service Disable & sc config "nassvc" start= disabled & echo Windowexe.com
NA080 sc stop "HGICM"
NA081 echo Service Disable & sc config "HGICM" start= disabled & echo Windowexe.com
NA082 echo schtasks Delete & schtasks /delete /tn "acircle" /f
NA083 echo Created by Windowexe.com
NA084 echo schtasks Delete & schtasks /delete /tn "AnCamCorder 실행" /f
NA085 echo Created by Windowexe.com
NA086 echo schtasks Delete & schtasks /delete /tn "AnToolUpdate 실행" /f
NA087 echo Created by Windowexe.com
NA088 echo schtasks Delete & schtasks /delete /tn "DLL-files.com Fixer_UPDATES" /f
NA089 echo Created by Windowexe.com
NA090 echo schtasks Delete & schtasks /delete /tn "IPlusUpdate_ze" /f
NA091 echo Created by Windowexe.com
NA092 echo schtasks Delete & schtasks /delete /tn "ISZone" /f
NA093 echo Created by Windowexe.com
NA094 echo schtasks Delete & schtasks /delete /tn "OKSTART" /f
NA095 echo Created by Windowexe.com
NA096 echo schtasks Delete & schtasks /delete /tn "utiltop" /f
NA097 echo Created by Windowexe.com
NA098 echo schtasks Delete & schtasks /delete /tn "Window FindKey Controller" /f
NA099 echo Created by Windowexe.com
NA100 echo schtasks Delete & schtasks /delete /tn "Windows Visual ad php" /f
NA101 echo Created by Windowexe.com
NA102 echo schtasks Delete & schtasks /delete /tn "바닥인코더 실행" /f
NA103 echo Created by Windowexe.com
NA104 echo 000 & reg.exe add "HKCU\Control Panel\Desktop" /v "SCRNSAVE.EXE" /d "" /f & echo windowdel.com
NA105 echo Created by Windowexe.com
NA106 echo 000 & reg.exe delete "HKCR\CLSID\{5121BCAB-14D5-40AD-A469-4437CC51F7AA}" /f & echo windowdel.com
NA107 echo Created by Windowexe.com
NA108 echo 000 & reg.exe delete "HKCR\CLSID\{A832F633-668F-4F8A-9EA1-A6375D1C1418}" /f & echo windowdel.com
NA109 echo Created by Windowexe.com
NA110 echo change dir for x64
NA111 cd %windir%
NA112 cd syswow64
NA113 echo windowexe.com & tskill "ancamcorderupdate" & echo windowdel.com
NA114 echo windowexe.com & tskill "IPlusUpdate_ze" & echo windowdel.com
NA115 echo windowexe.com & tskill "Badakencoder_update" & echo windowdel.com
NA116 echo windowexe.com & tskill "adbrowser" & echo windowdel.com
NA117 echo windowexe.com & tskill "barosvc" & echo windowdel.com
NA118 echo windowexe.com & tskill "best-pcse" & echo windowdel.com
NA119 echo windowexe.com & tskill "ctpopsvc" & echo windowdel.com
NA120 echo windowexe.com & tskill "direcon" & echo windowdel.com
NA121 echo windowexe.com & tskill "GDownService" & echo windowdel.com
NA122 echo windowexe.com & tskill "gomhelpersvc" & echo windowdel.com
NA123 echo windowexe.com & tskill "KUploadService" & echo windowdel.com
NA124 echo windowexe.com & tskill "nnlogon" & echo windowdel.com
NA125 echo windowexe.com & tskill "uptoolsvc" & echo windowdel.com
NA126 echo windowexe.com & tskill "wepsv" & echo windowdel.com
NA127 echo windowexe.com & tskill "WBPatchCntr" & echo windowdel.com
NA128 echo windowexe.com & tskill "intsfsrv" & echo windowdel.com
NA129 echo windowexe.com & tskill "winspop" & echo windowdel.com
NA130 echo windowexe.com & tskill "winspsv" & echo windowdel.com
NA131 echo windowexe.com & tskill "wssvrelv" & echo windowdel.com
NA132 echo windowexe.com & tskill "FBDSvcMan" & echo windowdel.com
NA133 echo windowexe.com & tskill "inforesetupdate" & echo windowdel.com
NA134 echo windowexe.com & tskill "svcspwin" & echo windowdel.com
NA135 echo HKCU Startup Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "direcon" /f
NA136 echo HKLM Startup Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "direcon" /f
NA137 echo HKEY_LOCAL_MACHINE BHO Delete & reg.exe delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA138 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA139 echo HKEY_CURRENT_USER.BHO.Stats Delete & reg.exe delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA140 echo HKEY_CLASSES_ROOT.CLSID Delete & reg.exe delete "HKCR\CLSID\{AB705622-B25B-491B-A6BF-4A46FDDBC88E}" /f
NA141 echo Created by Windowexe.com
NA142 sc stop "barocn"
NA143 echo Service Disable & sc config "barocn" start= disabled & echo Windowexe.com
NA144 sc stop "best-pcService"
NA145 echo Service Disable & sc config "best-pcService" start= disabled & echo Windowexe.com
NA146 sc stop "BNDownService"
NA147 echo Service Disable & sc config "BNDownService" start= disabled & echo Windowexe.com
NA148 sc stop "ctwopop"
NA149 echo Service Disable & sc config "ctwopop" start= disabled & echo Windowexe.com
NA150 sc stop "efinderservice"
NA151 echo Service Disable & sc config "efinderservice" start= disabled & echo Windowexe.com
NA152 sc stop "FBDSvcman"
NA153 echo Service Disable & sc config "FBDSvcman" start= disabled & echo Windowexe.com
NA154 sc stop "GomHelper Update Services"
NA155 echo Service Disable & sc config "GomHelper Update Services" start= disabled & echo Windowexe.com
NA156 sc stop "InternetSafer Protector"
NA157 echo Service Disable & sc config "InternetSafer Protector" start= disabled & echo Windowexe.com
NA158 sc stop "koltyduyiu"
NA159 echo Service Disable & sc config "koltyduyiu" start= disabled & echo Windowexe.com
NA160 sc stop "KService"
NA161 echo Service Disable & sc config "KService" start= disabled & echo Windowexe.com
NA162 sc stop "NetAccelerator"
NA163 echo Service Disable & sc config "NetAccelerator" start= disabled & echo Windowexe.com
NA164 sc stop "NSpeedMeterManager"
NA165 echo Service Disable & sc config "NSpeedMeterManager" start= disabled & echo Windowexe.com
NA166 sc stop "ServiceHost SH123"
NA167 echo Service Disable & sc config "ServiceHost SH123" start= disabled & echo Windowexe.com
NA168 sc stop "userpc Update Service"
NA169 echo Service Disable & sc config "userpc Update Service" start= disabled & echo Windowexe.com
NA170 sc stop "UTool"
NA171 echo Service Disable & sc config "UTool" start= disabled & echo Windowexe.com
NA172 sc stop "wepop"
NA173 echo Service Disable & sc config "wepop" start= disabled & echo Windowexe.com
NA174 sc stop "WindowBoanPatch OEM Monitoring Center"
NA175 echo Service Disable & sc config "WindowBoanPatch OEM Monitoring Center" start= disabled & echo Windowexe.com
NA176 sc stop "WindowsDriver"
NA177 echo Service Disable & sc config "WindowsDriver" start= disabled & echo Windowexe.com
NA178 sc stop "WindowSearch Service Manager"
NA179 echo Service Disable & sc config "WindowSearch Service Manager" start= disabled & echo Windowexe.com
NA180 sc stop "winspsv32"
NA181 echo Service Disable & sc config "winspsv32" start= disabled & echo Windowexe.com
NA182 sc stop "WinsPop Service"
NA183 echo Service Disable & sc config "WinsPop Service" start= disabled & echo Windowexe.com
NA184 sc stop "Windows WinsPop Diagnostics Service"
NA185 echo Service Disable & sc config "Windows WinsPop Diagnostics Service" start= disabled & echo Windowexe.com
NA186 sc stop "nassvc"
NA187 echo Service Disable & sc config "nassvc" start= disabled & echo Windowexe.com
NA188 sc stop "HGICM"
NA189 echo Service Disable & sc config "HGICM" start= disabled & echo Windowexe.com
NA190 echo schtasks Delete & schtasks /delete /tn "acircle" /f
NA191 echo Created by Windowexe.com
NA192 echo schtasks Delete & schtasks /delete /tn "AnCamCorder 실행" /f
NA193 echo Created by Windowexe.com
NA194 echo schtasks Delete & schtasks /delete /tn "AnToolUpdate 실행" /f
NA195 echo Created by Windowexe.com
NA196 echo schtasks Delete & schtasks /delete /tn "DLL-files.com Fixer_UPDATES" /f
NA197 echo Created by Windowexe.com
NA198 echo schtasks Delete & schtasks /delete /tn "IPlusUpdate_ze" /f
NA199 echo Created by Windowexe.com
NA200 echo schtasks Delete & schtasks /delete /tn "ISZone" /f
NA201 echo Created by Windowexe.com
NA202 echo schtasks Delete & schtasks /delete /tn "OKSTART" /f
NA203 echo Created by Windowexe.com
NA204 echo schtasks Delete & schtasks /delete /tn "utiltop" /f
NA205 echo Created by Windowexe.com
NA206 echo schtasks Delete & schtasks /delete /tn "Window FindKey Controller" /f
NA207 echo Created by Windowexe.com
NA208 echo schtasks Delete & schtasks /delete /tn "Windows Visual ad php" /f
NA209 echo Created by Windowexe.com
NA210 echo schtasks Delete & schtasks /delete /tn "바닥인코더 실행" /f
NA211 echo Created by Windowexe.com
NA212 echo 000 & reg.exe add "HKCU\Control Panel\Desktop" /v "SCRNSAVE.EXE" /d "" /f & echo windowdel.com
NA213 echo Created by Windowexe.com
NA214 echo 000 & reg.exe delete "HKCR\CLSID\{5121BCAB-14D5-40AD-A469-4437CC51F7AA}" /f & echo windowdel.com
NA215 echo Created by Windowexe.com
NA216 echo 000 & reg.exe delete "HKCR\CLSID\{A832F633-668F-4F8A-9EA1-A6375D1C1418}" /f & echo windowdel.com
NA217 echo Created by Windowexe.com
NA218 echo End
NA219 ======================================================================
NA220 echo Created by Windowexe.com / do not delete this label.
NA221 ======================================================================