°Ô½ÃÆÇȨ / À©µµ¿ì / ¿ú °°Àºµ¥ Ä¡·á°¡ ¾ÈµÇ³×¿ä.. ÀâÈ÷Áöµµ ¾Ê°í¿ä.»õ±Û¾²±â ´ä±Û¾²±â

ÀúÀÚ ¿ú °°Àºµ¥ Ä¡·á°¡ ¾ÈµÇ³×¿ä.. ÀâÈ÷Áöµµ ¾Ê°í¿ä.
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2008-03-01 04:26||
¾Æ¹öÁö ÄÄÀÌ ÀÌ»óÇØ¿ä.

¾Ë·Á¾ß µÇ´Â »çÇ×À» ±×³É Âß ¾µ°Ô¿ä.

winXP sp1/ IE6. À̱¸¿ä. ³ëÆ®ºÏÀÔ´Ï´Ù.
===========================================
-¾ó¸¶Àü ¾Æºü°¡ ÄÄÀÌ ºÎÆÃÇÒ¶§ ¸· Æú´õâµµ ¶ß±¸ ¿¡·¯¸Þ¼¼Áöµµ ¶á´Ù°í Çϼż­ ÀúÇÑÅ× °íÃÄ´Þ¶ó°í ¸Ã±â¼Ì½À´Ï´Ù. ºÎÆÃÇÒ¶§ ºí·ç½ºÅ©¸°¿¡ chkdiskµµ ½ÇÇàµÇ°í¿ä.

-±×·¡¼­ ¹ÙÀÌ·¯½º °Ë»ç¸¦Çغ¸´Ï±î Æ®·ÎÀÜ(?)¹ÙÀÌ·¯½º °°Àº°Ô ¹«Àð°Ô °É·ÁÀ־ ±×°Å Ä¡·áÇß½À´Ï´Ù. (¾Ë¾à »ç¿ë)

-±Ùµ¥ ¿À´Ã ¾Æºü°¡ ÄÄÀÌ ¾ÆÁ÷µµ ÀÌ»óÇÏ´Ù°í Çϼż­ ´Ù½Ã º¸´Ï ¾öû ´À·ÁÁ³°í ¿¡·¯¸Þ½ÃÁöµµ ´Ù½Ã ¶ß´õ¶ó±¸¿ä. ino1.dllÀÌ ¾ø´Ù´ÂµÕ..

-³» ³×Æ®¿öÅ© ȯ°æ°¡¼­ ÀÎÅÍ³Ý ¿¬°á»óŸ¦ È®ÀÎÇغ¸´Ï±î º¸³¿ÆÐŶÀÌ 1,222,333,444,555 ÀÌ·± ¼öÁØÀ̳׿ä.-_- ¿ú°°¾Æ¿ä.

-¿À´ÃÀº Áö±Ý »õº®4½Ã±îÁö °è¼Ó ¸¸ÁöÀ۰Ÿ®°í Àִµ¥¿ä. AVG¶ó´Â ¿Ü»ê¹«·á¹é½ÅÀ¸·Î °Ë»çÇغôµ¥ »ç¼ÒÇÑ Æ®·ÎÀ̸ñ¸¶¹ÙÀÌ·¯½º ¸î°³¶ß°í ¸»¾Ò½À´Ï´Ù. ºÐ¸í ¿úÀÌ ÀâÈú°Å¶ó »ý°¢Çߴµ¥ ¾ÈÀâÈ÷³×¿ä.-_- ±×·¡¼­ ¾Ë¾àµ¹·ÁºÃ´Âµ¥ ¿ª½Ã ¿ú ¾ÈÀâÇô¿ä. ¹æ±Ý ¹ÙÀ̷κ¿ µ¹¸®´Ù°¡ ¾È³ª¿À´Â°Å °°¾Æ¼­ Æ÷±âÇß½À´Ï´Ù.

-msconfig·Î ½ÃÀÛÇÁ·Î±×·¥À» º¸´Ï ¼ö»óÇѰ͵é(ºÎÆö§ ¿¡·¯¶ß´ø ino1.dllµµ ÀÖ°í..)ÀÌ ¸¹ÀÌ Àֱ淡 È®½ÇÈ÷ ÇÊ¿äÇѰ͸¸ ³ÀµÎ°í ´Ù ²¨¹ö·È½À´Ï´Ù.(msconfig¿¡¼­ÀÇ ¼³Á¤Àº È®½ÇÇÏ°ÔÇÑ°Å°°½À´Ï´Ù.) ipconfig32.exe¶ó´Â°Íµµ ÀÖ¾ú´Âµ¥ °Ë»öÇغ¸´Ï ¿ú°ú °ü·ÃµÈ°Å´õ¶ó±¸¿ä?-_-

-autoruns¸¦ ÄѺôµ¥ ±×´ÙÁö Àǽɰ¡´Â°Ô ¾ø³×¿ä.

-wintt.net À̶ó´Â °÷¿¡¼­ sp1¿ë À©µµ¾÷µ«isoÆÄÀÏÀ» ¹Þ¾Æ¼­ º¸¾ÈÆÐÄ¡¸¦ ³¡³Â¾¹´Ï´Ù.

///ÀçºÎÆÃ///
-¿¡·¯¸Þ¼¼Áö°°Àº°Ç ¾È¶å´Ï´Ù. ±Ùµ¥ º¸³¿ÆÐŶÀÌ Àå³­ÀÌ ¾Æ´Õ´Ï´Ù.-_-
¾î¶»°Ô Çؾߵɱî¿ä.. ¹é½Å¿¡ ÀâÈ÷Áöµµ ¾Ê°í À̰Ź¹..

========================================

Âü°í»çÇ×:
sp2·Î ¹Ù²Ü¼ö°¡ ¾ø¾î¿ä.. Á¦°¡ ÁÖ¿öµéÀº¹Ù·Ð sp2±ò¶ó¸é Æ÷¸ËÇÏ°í »õ·Î ±ò¶ó´øµ¥, Áö±Ý Æ÷¸ËÀ» ¸øÇØ¿ä-.- ¾ÆºüÄÄÀÌ »ç¹«¿ëÀε¥ Áß¿äÇÑ À̸ᵵ ¸¹°í °¢Á¾ ¿¢¼¿ÆÄÀϵµ ¹«Àð°Ô ¸¹¾Æ¼­ Æ÷¸ËÇß´Ù ³¯¸®¸é Á¦ ¸ð°¡Áö ³¯¾Æ°¡°Åµ¢¿ä.. Á¦°¡ Æ÷¸Ë°æÇèÀÌ ¸¹Àº°Íµµ ¾Æ´Ï±¸..
¹°·Ð Æ÷¸ËÀÌ Á¦ÀÏ ½±Áö¸¸, Æ÷¸Ë¾ÈÇÏ°í ¿ú Àâ´Â¹æ¹ý ±×´ÙÁö ¾î·Á¿ï°Å °°Áö ¾ÊÀºµ¥.. ¿ÖÀÌ·±Áö ¸ð¸£°Ú³×¿ä.


´äº¯ºÎŹµå¸³´Ï´Ù.
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2008-03-01 06:03||
Á¦°¡ µµ¿òÀÌ µÉÁö ¸ð¸£°ÚÁö¸¸ ¾Æ·¡ ¸µÅ©¸¦ ÀÐÀ¸½Ã°í
HiJack ·Î±× ÀÛ¼ºÇϱâ
autoruns ´Ù¿î¹Þ±â

¿ì¼± hijackthis ÇÏ°í autoruns À» °¢°¢ ½ÇÇàÇÑ ÈÄ log (·Î±×) È­ÀÏ (.txt)À» ÀúÀåÇؼ­ ´Ù½Ã ¿©±â¿¡ Æ÷½ºÆà ÇØ ÁÖ¼¼¿ä. ¾Æ´Ï¸é [email protected] À¸·Î º¸³»¼Åµµ µÇ°í.

Á¦°¡ ·Î±×¸¦ º¸´Â µ¿¾È kykkysp´ÔÀº CD ¶Ç´Â DVD °¡ »ç¿ë°¡´ÉÇÏ¸é ¾Æ¹öÁöÀÇ Áß¿äÇÑ µ¥ÀÌŸ È­ÀÏÀ» Ä«ÇÇÇØ ³õÀ¸½Ã±¸¿ä. ¹ÙÀÌ·¯½º Á¦°ÅÇϴµ¥ °ÅÀÇ »ó°üÀº ¾øÁö¸¸ ¸¸¾àÀ» À§Çؼ­ µ¥ÀÌŸ¸¦ ÀúÀåÇØ ³õ´Â °ÍÀÌ ÁÁÁÒ... ¸¸¾à ÀúÀåÇÒ µ¥ÀÌÅÍ°¡ ³Ê¹« Å©¸é flash drive ³ª ¿ÜÀåÇü hard drive ¸¦ ±¸Çϼż­ ÀúÀåÇØ ³õÀ¸½Ã¸é µÇ±¸¿ä.

¼ÖÁ÷È÷ ¹ÙÀÌ·¯½º Á¦°Å´Â ¿¹»ó¿ÜÀÇ »óȲÀÌ »ý±æ¼ö Àֱ⶧¹®¿¡ ¹ß»ýÇÏ´Â ´Ù¸¥ ¹®Á¦¿¡ ´ëÇØ Ã¥ÀÓÀ» 100% Áú¼ö ÀÖ´Â »óȲÀÌ ¾Æ´Ï¹Ç·Î ²À ¹é¾÷À» ±ÇÇÕ´Ï´Ù.

"¹°¸®Ä¡ÀÚ ¹ÙÀÌ·¯½º".. ¾Æ½Î ~ È­ÀÌÆÃ.
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2008-03-01 09:40||
¿äÁò ¹ÙÀÌ·¯½º´Â ·çƮŶ¿¡ ¼û´Â °æ¿ì°¡ ¸¹¾Æ Àâ¾Æµµ °è¼Ó »ý±â´Â °æ¿ì°¡ ¸¹½À´Ï´Ù. ÀÏ´Ü Àâ¾Æµµ °è¼Ó »ý±â´Â ¹ÙÀÌ·¯½º Àâ±â¸¦ ¸ÕÀú ÀÐ¾î º¸°í Á¶Ä¡ÇØ º¸±â ¹Ù¶ø´Ï´Ù. ÀÌ ¹æ¹ýÀ» »ç¿ëÇصµ °è¼Ó ¹ÙÀÌ·¯½º°¡ »ý±ä´Ù¸é È¥ÀÚ¼­ ó¸®Çϱ⿡´Â Èûµé °ÍÀ¸·Î º¸ÀÔ´Ï´Ù.
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2008-03-01 15:20||
ÃÖ±Ù¿¡ ¹ÙÀÌ·¯½º Á¦°Å ÀÛ¾÷À» Çß´ø°ÍÀ» ±â·ÏÇßÀ¾´Ï´Ù.

¹ÙÀÌ·¯½º Á¦°Å´Â ¹ÙÀÌ·¯½º¿Í °ü·ÃµÈ Á¤º¸¿Í¿¡ ½Î¿ò?À̶ó »ý°¢ÇÏ¿© ¹«Á¶°Ç »èÁ¦º¸´Ù´Â ¾ÐÃà º¸°üÈÄ »èÁ¦¸¦ ÃßõÇÕ´Ï´Ù.

±×¸®°í ¹ÙÀÌ·¯½º »èÁ¦°úÁ¤À» ±â·ÏÇϸ鼭 ÀÛ¾÷Çϱ⸦ ÃßõÇÕ´Ï´Ù.

1. ¹ÙÀÌ·¯½º °¨¿°ÈÄ ½ÇÇàµÇ´Â ÀÌ»óÆÄÀÏ http://3psilon.free.fr/s45b/S450RC.zip ¿Í http://www.nirsoft.net/utils/cports.zip À» ÀÌ¿ëÇØ ¾Ë¾Æ³½´Ù.

(¹ÙÀÌ·¯½º °¨¿°ÈÄ ½ÇÇàÀÌ µÇÁö¾Ê´Â softwareµéÀÌ ÀÖÀ¾´Ï´Ù. Ư¡À¸·Î´Â ¹ÙÀÌ·¯½º °¨¿°°ú ¸ð´ÏÅ͸µÀÌ °¡´ÉÇÏ´Ù ¾Ë·ÁÁø À¯¸íÇÑ ¸î¸î ¼ÒÇÁÆ®¿þ¾î¿Í ¹é½Å¿¡ ´ëÇؼ­´Â ¹ÙÀÌ·¯½º ÀÚü ¹æ¾î ±â´ÉÀÌ ÀÖ¾î ½ÇÇà°ú ¼³Ä¡°¡ ºÒ°¡ÇÕ´Ï´Ù.)

¤¡. ÆÄÀÏÀº ÆÄÀÏ Á¸Àç °æ·Î¿Í Æú´õ ¹× ·¹Áö½ºÆ®¸® Á¤º¸¸¦ ¾Ë¾Æ¾ßÇÑ´Ù.

¤¤. ÇöÀçÀÇ ¹ÙÀÌ·¯½º´Â Á¤º¸¸¦ ¾Ë±âÀ§ÇÑ Á¸ÀçÀÔ´Ï´Ù. ±×·¯±â¿¡ ³×Æ®¿öÅ© ¸ð´ÏÅ͸µÀ» ÅëÇØ ¿ì¼±µÈ ÆÄÀÏÀ» ¾Ë¼öÀÖÀ¾´Ï´Ù.

¤§. ÀÎÅÍ³Ý ¸ðµ©À» Poweroff¿Í PowerONÀ» ÇÊ¿ä½Ã ¼ö½Ã·Î ÇÑ´Ù.
(ƯÈ÷ óÀ½ ¹ÙÀÌ·¯½º¿¡ °¨¿°µÈ ½ÃÁ¡¿¡¼­´Â ÀÎÅÍ³Ý ¸ðµ© PowrOFF¸¦ ÇÑÈÄ ÇÁ·Î¼¼½º¸¦ ¾Ë¾Æ³»¼¼¿ä)

¤©. ù¹ø° ¹ÙÀÌ·¯½º¸¦ ³»Æ÷ÇÑ ½ÇÇàÆÄÀÏÀÌ ÀÖ´Ù¸é ºÐ¼®Çϴµ¥ À¯¿ëÇÕ´Ï´Ù. »èÁ¦ÇÏÁö ¸¶½Ã°í °¡»óOS³ª °¡»ó Tool¿¡¼­ Total Uninstall¸¦ ÀÌ¿ëÇØ ¹ÙÀÌ·¯½º¿¡ È°µ¿¹üÀ§¸¦ ´ë·«ÀûÀ¸·Î ¾Ë¼öÀÖÀ¾´Ï´Ù.

¤±. ¹ÙÀÌ·¯½º °¨¿°½Ã°£À» Âü°íÇÏ¿© ÆÄÀÏ »ý¼º ½Ã°£À» ±âÁØÀ¸·Î °Ë»öÇÑ´Ù¸é À¯¿ëÇÑ Á¤º¸¸¦ ¾Ë¼öÀÖ´Ù.

-> ÀÌ¿Í °°Àº ÀÛ¾÷À¸·Î ¹ÙÀÌ·¯½º°¡ »ý¼º, »èÁ¦, ¼öÁ¤ÇÑ µ¥ÀÌÅÍ(ÆÄÀÏ°ú ·¹Áö½ºÆ®¸®)¿¡ ´ëÇØ ´ë·«ÀûÀ¸·Î ¾Ë¼öÀÖÀ¾´Ï´Ù.

2. ÀÌ»óÆÄÀÏ(¹ÙÀÌ·¯½º·ÎÀÎÇÑ »ý¼ºµÈ ÆÄÀϵî)À» ¾ÐÃàÇÏ¿© http://www.virustotal.com/ ¿¡ ¾÷·ÎµåÇÏ¸é ¹ÙÀÌ·¯½º¿¡ ´ëÇÑ Á¤º¸¸¦ ¾Ë¼öÀÖÀ¾´Ï´Ù.

¤¡. Ž»ö±â¿¡´Â º¸ÀÌÁö ¾Ê´Âµ¥ ½ÇÇàÀÌ µÇ¾î È°µ¿ÇÏ´Â ¹ÙÀÌ·¯½º°¡ ´ëºÎºÐÀÔ´Ï´Ù. ÆÄÀÏ °Ë»öÀ» ÇÑÈÄ °Ë»öâ¿¡¼­ ¿À¸¥ÂÊÅ°¸¦ ´­·¯ ¾ÐÃàÇϼ¼¿ä.

¤¤. ÇöÀç Trojan ¹ÙÀÌ·¯½º °æ¿ì Á¦°ÅÇÒ¼öÀÖ´Â ¹é½ÅÀº ±¸ÇÏ¿´À¸³ª ¼³Ä¡°¡ ¾ÈµÇ´Â°æ¿ì°¡¿Í ¾ÈÀü¸ðµå Á¢±Ùµµ ¾ÈµÇ´Â °æ¿ì°¡ ¸¹À¾´Ï´Ù. ÀÌ´Â Window PE¸¦ ÅëÇÑ ¼öÀÛ¾÷À¸·Î Á¦°ÅÇÕ´Ï´Ù.

¤§. ÀϹÝÀûÀÎ ¼­ºñ½º°ü¸®¿Í À©µµ¿ì ½ÃÀÛÀ» ¸ð´ÏÅ͸µÇØÁÖ´Â Åø·Î´Â ¾Ë¼ö¾øÀ¾´Ï´Ù.

¤©. ·¹Áö½ºÆ®¸® ÆíÁý±â¿¡¼­ ¼­ºñ½º¿Í °ü·ÃµÈ ·¹Áö½ºÆ®¸®¸¦ ÇϳªÇϳª Á¡°ËÇÑÈÄ ¾ËÁö¸øÇÑ °ÍÀ» google¿¡¼­ °Ë»öÇÏ¿© »èÁ¦Çϼ¼¿ä.


3. ½ÇÇàµÇ´Â ¹ÙÀÌ·¯½º¿Í °ü·ÃµÈ ¼­ºñ½º¸¦ ¾Ë¾Æ³»¾ú´Ù¸é WIndow PEµî ºÎÆÃÀÌ °¡´ÉÇÑ OS·Î °ü·ÃµÈ µð·ºÅ丮¿Í ÆÄÀÏ¹× ·¹Áö½ºÆ®¸®¸¦ Á¦°ÅÇÕ´Ï´Ù.
(°£´ÜÈ÷ ÆÄÀÏ»èÁ¦¸¦ ÅëÇØ Á¦°ÅµË´Ï´Ù. )

4.´Ù½Ã Á¤»ó ºÎÆÃÈÄ ¼­ºñ½º¿Í ÇÁ·Î¼¼¼­¹× ³×Æ®¿÷ ¸ð´ÏÅÍ´×À» ÇÑÈÄ ÀÌ»ó¡Èĸ¦ ¹ß°ßÇÏÁö ¸øÇß´Ù¸é ¹é½ÅÀ» ´Ù¿î¹Þ¾Æ ½ÇÇàÇÕ´Ï´Ù.

¤¡. ¹ÙÀÌ·¯½º È°µ¿¿¡ ´ëÇÑ Á¡°Ë ¹æ¹ýÁß Çϳª´Â ¹ÙÀÌ·¯½º·Î ÀÎÇØ »ý¼ºµÈ ÆÄÀÏ°ú µ¿ÀÏÇÑ ÆÄÀϸíÀ¸·Î »õ ÆÄÀÏÀ» ¸¸µé¾î º»´Ù. »ý¼ºÇÑ ÆÄÀÏÀÌ ¹ÙÀÌ·¯½º·Î ÀÎÇØ »ý¼ºµÈ ÆÄÀÏ°ú Áõ»óÀ¸·Î ÆÄÀÏÀÌ »ý¼ºµÇÀÚ¸¶ÀÚ Å½»ö±â¿¡¼­ º¸ÀÌÁö ¾Ê´Â´Ùµî¿¡ ¡ÈÄ°¡ º¸ÀÎ´Ù¸é ¾ÆÁ÷ ¿ÏÀüÈ÷ ¹ÙÀÌ·¯½º¿¡ °ü·ÃµÈ ÆÄÀÏ¹× µ¥ÀÌÅÍ°¡ Á¦°ÅµÇÁö¾Ê¾Ò´Ù´Â °ÍÀÌ´Ù.

¤¤. ¹é½Å ¼³Ä¡°¡ µÇÁö¾Ê´Â´Ù´Â Á¡µµ À§ (¤¡.)°ú µ¿ÀÏÇÑ Àǹ̷Πº¸¾Æ¾ß ÇÑ´Ù.

5. À§ ÀÛ¾÷À» Àç Á¡°ËÇÑ´Ù.

6. ´õ ³ºÀº ÀÛ¾÷¹æ¹ýÀÌ ÀÖ´Ù¸é ½º½º·Î Çغ»´Ù.

¿©±â±îÁö ¹ÙÀÌ·¯½º¿¡ °¨¿°¹× »ý¼ºµÈ µ¥ÀÌÅÍ Á¦°ÅÀÔ´Ï´Ù.

Áö±ÝºÎÅÍ´Â ¹ÙÀÌ·¯½º°¡ »ý¼ºÇÑ µ¥ÀÌÅÍ°¡ ¾Æ´Ñ Á¦°ÅµÈ ÆÄÀÏÀ̳ª ¼öÁ¤ÇÑ ÆÄÀϵ鿡 ´ëÇÑ ´ëóÀÔ´Ï´Ù.

1.¹ÙÀÌ·¯½º·Î ÀÎÇØ Á¦°ÅµÈ OS ·¹Áö½ºÆ®¸® : ¾ÈÀüÇÑ °¡»óOS°¡ È£½ºÆ® OS¿Í µ¿ÀÏÇÏ°Ô (È£½ºÆ® Winxp = °¡»ó OS Winxp) Á¸ÀçÇϰųª ¸¸µé¾î °¡»ó OS¿¡¼­ ·¹Áö½ºÆ®¸®¸¦ ±¸ÇÏ¿© È£½ºÆ®¿¡ ¹é¾÷ÇØÁÖ¼¼¿ä.

¤¡. Çö ¹ÙÀÌ·¯½º Ư¡Áß Çϳª´Â Á¤º¸¸¦ ¾Ë¾Æ³»±â À§ÇÕÀÔ´Ï´Ù. ½É°¢ÇÑ ÄÄÇ»ÅÍ ´Ù¿îÀ̳ª À©µµ¿ì ºÎÆýÿ¡ ÇÊ¿äÇÑ Áß¿äÆÄÀÏ¿¡ ´ëÇÑ »èÁ¦µîÀº ÀϹÝÀûÀ¸·Î º¸ÀÌÁö ¾Ê½À´Ï´Ù.

¤¤. ¾ÈÀü¸ðµå·Î ºÎÆÃÀÌ ¾ÈµÇ°Ô ÇÏ´Â ¹ÙÀÌ·¯½º°¡ÀÖÀ¾´Ï´Ù. ÀÌ´Â ¾ÈÀü¸ðµå°¡ ³×Æ®¿÷ÀÌ µÇÁö¾Ê±â¿¡ ¹ÙÀÌ·¯½º·Î¼­ »ýÁ¸°¡Ä¡¿¡ ºÒÇÊ¿äÇϹǷΠ¾ÈÀü¸ðµå¿¡ °ü·ÃµÇ ·¹Áö½ºÆ®¸®¸¦ »èÁ¦ÇÑ´Ù´Â Á¡ÀÌ´Ù.

2.¹ÙÀÌ·¯½º·Î ÀÎÇØ Á¦°ÅµÈ Software : Á¤»ó ÀÛµ¿ÇÏÁö ¾ÊÀº softwareÁ¦°Å¿Í À缳ġ¸¦ ÇÕ´Ï´Ù.

¤¡. ÀûÀº ¿ë·®¿¡ Tool¶ÇÇÑ ½ÇÇàµÇÁö ¾Ê´Â°ÍÀº »èÁ¦ÈÄ Àç ´Ù¿î¹Þ¾Æ »ç¿ëÇؾßÇÑ´Ù.

¤¤. CCleaner. ICEworld. Ram Dump Tool. VaccineµîÀÌ ½ÇÇàµÇÁö ¾Ê´Â´Ù.

¤§. V3 Neo+ Á¤»óÀÛµ¿ÇÑ´Ù. ¿Ö? Ä¡·á¸¦ ¸øÇϴϱñ... ÀÌÁ¡À» ÅëÇØ ¹ÙÀÌ·¯½º °¨¿¬ÈÄ VaccineÀº ¹«¿ëÁö¹°ÀÌ´Ù. (Kaspersky¶ÇÇÑ °¡»óOS¸¦ ÅëÇÑ °Ë»ç¸¦ Çغ¸¾ÒÀ¸³ª °¨¿°µÈ ÆÄÀÏÀº »èÁ¦µÇÁö¾Ê´Â´Ù. Kaspersky ¸Þ¼¼Áö´Â "¾ÈÀüÇÏ°Ô »èÁ¦µÇ¾úÀ¾´Ï´Ù." ¶ó°í °ÅÁþ¸»ÇÑ´Ù.)

+:+:+: Âü°í :+:+:+:+

1. ¸ÅÀÏ Á¤»ó ºÎÆÃÈÄ ·¹Áö½ºÆ®¸®¹× Áß¿äÆÄÀÏ°ú Áñ°Üã±â ¹é¾÷.

2. ¹é¾÷µÈ µ¥ÀÌŸ°¡ ÀÖ´Â Çϵ峪 USB¹× ÀúÀå¸Åü´Â Àϻ󿡼­´Â º»Ã¼¿Í ¿¬°áÀ» ÇØÁ¦ÇØ ³õÀº´Ù.

3. Window PE¿Í USB ¸¦ ÀÌ¿ëÇÑ ºÎÆÃ¹× °ü¸® OS¸¦ ÇϳªÂëÀº ¼ÒÀåÇÑ´Ù.
Âü°í»çÀÌÆ® : http://www.frozentech.com/content/livecd.php

4. ¹ÙÀÌ·¯½º Á¦°Å¸¦ Çϴµ¿¾È ÇÊ¿äÇÑ ±â·Ï(ÆÄÀϸí. ·¹Áö½ºÆ®¸® ÁÖ¼Òµî)À» ¸ðµÎ ÇسõÀº´Ù.

5. ¹ÙÀÌ·¯½º¿¡ °ü·ÃµÈ ÆÄÀÏÀ» ¾ÐÃàÇÏ¿© ÀúÀåÇØ ³õÀº´Ù. Á¤º¸ ºÐ¼®¿¡ ÇÊ¿äÇÒ¶§°¡ ÀÖ´Ù. ¹«Á¶°Ç Áö¿ìÁö ¸»ÀÚ.

7. °Ë»öÀº Google¹× ¹é½Å¾÷ü¿¡ ¹ÙÀÌ·¯½º µ¥ÀÌÅ͸¦ ÀÌ¿ëÇÏÀÚ!

6. °¨¿°µÈ Computer¿¡¼­ ¹ÙÀÌ·¯½º Á¦°Å ÀÛ¾÷Àº Àå½Ã°£¿¡ ü·Â°ú ´Ù¾çÇÑ Á¤º¸¸¦ ¿äÇÑ´Ù. Â÷ÇÑÀÜ ¸¶½Ã¸é¼­ Virus¸¦ ¿ôÀ½À¸·Î ´ëÀÀÇÏÀÚ!!!!

[ ¸Þ½ÃÁö¼öÁ¤: savit ÀϽÃ: 2008-03-01 15:43 ]
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2008-03-01 16:37||
hijack°ú autoruns ·Î±×´Â yoonsangfan ´Ô À̸ÞÀÏ·Î º¸³Â¾¹´Ï´Ù.
¿©±â ÷ºÎÇÏ´Â ¹æ¹ýÀ» ¸ô¶ó¼­ ±×³É ºÙ¿©³Ö±â¿¡´Â ³Ê¹« ³»¿ëÀÌ ¸¹³×¿ä.

´Ù¸¥¹æ¹ýÀº Áö±ÝºÎÅÍ ½ÃµµÇغ¼²²¿ä. ´äº¯ °í¸¿½À´Ï´Ù.
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2008-03-02 11:29||
kykkysp ´Ô autoruns ·Î±× È­ÀÏ ³»¿ë¿¡ ºüÁø ºÎºÐÀÌ ÀÖ´Âµí ½Í³×¿ä.
winlogon ºÎºÐ µîÀÌ ¾ø´Â°ÍÀ¸·Î º¸¾Æ¼­ ·Î±×°¡ Àß »ý¼ºµÇÁö ¾ÊÀºµí ½Í½À´Ï´Ù. autoruns ´Â ½ÇÇàÀ» ÇÏ°í searching ÇÏ´Â ½Ã°£ÀÌ Á» °É¸®¹Ç·Î ¹Ù·Î ÀúÀåÇÏÁö ¸¶½Ã°í ±â´Ù·È´Ù°¡ searching ÀÌ ´Ù µÈÈÄ¿¡ ÀúÀåÇÏ½Ã¸é µË´Ï´Ù. ´Ù½Ã ÀúÀåÇؼ­ º¸³»ÁÖ¼¼¿ä. ¾Æ´Ï¸é °Ô½ÃÆÇ¿¡ ±Ûó·³ ºÙ¿©³Ö±â·Î ÇÏ½Ã¸é µË´Ï´Ù.

hijackthis ¸¦ º¸´Ï DPF ( ActiveXcontrol) ÀÌ ¾öû³ª°Ô ¸¹´õ±º¿ä.
Àü Çѱ¹ÀÌ ¾Æ´Ñ ¾Èµå·Î¸Þ´Ù¿¡(?) »ì±â ¶§¹®¿¡ ÀºÇàÀ̶ó´øÁö Ưº°ÇÏ°Ô ActiveXcontrol À» ¸¹ÀÌ ¼³Ä¡ÇÏÁö ¾Ê°Ô µÇ´Â ȯ°æÀε¥ ¿ª½Ã Çѱ¹Àº ÀÌ°Ô ¹«Àð°Ô ¸¹³×¿ä. °ÅÀÇ 60~70¿©°³ Á¤µµ µÇ¾î º¸ÀÌ´õ±º¿ä. ÀÌ°Ô ¸ðµÎ ÇÊ¿äÇÏÁö ¾Ê´Â °ÍÀ̶ó¸é ½Ï Á¤¸®ÇÏ½Ã±æ ±ÇÇϴµ¥ Ȥ½Ã ¸ð¸£´Ï ¾Æ¹öÁö¿Í »óÀÇ Çϼż­ Á¦°Å ÇϽøé ÁÁ°Ú±º¿ä. ¾îÂ÷ÇÇ ÇÊ¿äÇÒ¶§ ´Ù½Ã ´Ù¿î¹ÞÀ¸¸é µÇ±â ¶§¹®¿¡...

±×¸®°í
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

Àº Áö¿öµµ µÇ´Âµ¥ ÃÖ±Ù¿¡ bluescreen ¿¡·¯°¡ system ¿¡¼­ ¹ß»ýÇÑ°ÍÀ¸·Î º¸¿©Áö´Â±º¿ä.

·Î±×¸¦ º¸¾ÆÇÏ´Ï Æ¯º°ÇÏ°Ô ¹®Á¦µÇ¾î º¸À̴°ÍÀº ¾ø±¸¿ä. DPF °¡ ¸¹ÀÌ ÀÖ´Ù°í ÄÄÇ»ÅÍ°¡ ´À·ÁÁöÁø ¾Ê´Â°Í °°À¸¹Ç·Î ´Ù¸¥ ÀÌÀ¯Àεí ÇÕ´Ï´Ù.

ÄÄÇ»ÅÍ°¡ ´À¸®´Ù´Â°ÍÀÌ ½Ã½ºÅÛ ¿î¿µÀÌ ´À¸°°ÍÀÎÁö ÀÎÅÍ³Ý ºê¶ó¿ìÁ®¸¦ ¿­¶§ ´À¸°°ÍÀÎÁö ±Ã±ÝÇϳ׿ä. IE ¸¦ ¿­¸é ³×À̹ö Åø¹Ù³ª ´Ù¸¥ addon Åø¹Ù µîÀÌ °°ÀÌ ½ÇÇàµÇ´Ï±ñ ´À·ÁÁø´Ù°í ºÁ¾ß ÇÕ´Ï´Ù. ³×À̹ö Åø¹Ù¸¦ uncheck ÇϽÅÈÄ IE ¿©´Â ¼Óµµ¸¦ È®ÀÎÇØ º¸¼Å¾ß ÇÒ°Í °°±º¿ä. ÄÄÇ»ÅÍÀÇ ¿î¿µ¼Óµµ°¡ ´À¸°°ÍÀº ¸Þ¸ð¸®°¡ ¾ó¸¶³ª ÀÖ´ÂÁö CPU »ç¾çÀÌ ¾ó¸¶³ª ÀÖ´ÂÁö ¿¡ µû¶ó¼­µµ Â÷ÀÌ°¡ ³ª¹Ç·Î °ü·ÃÁ¤º¸ ¾øÀÌ ¸»¾¸µå¸®±â°¡ ¸ðÈ£ÇÕ´Ï´Ù. ´Ù¸¸ xp sp1ÀÌ ¼³Ä¡µÇ¾î Àִ°ÍÀ¸·Î º¸¾Æ ¹æÈ­º®ÀÌ ÇöÀç ¼³Ä¡µÇ¾î ÀÖÁö ¾ÊÀ¸¸ç ÄÄÇ»ÅÍ »ç¾çÀÌ Á» ¿¾³¯°ÍÀ̶ó ¸Þ¸ð¸®³ª ½ÃÇÇÀ¯ ¼Óµµ°¡ ÀûÀ»°ÍÀÌ´Ù¶ó°í »ý°¢µÇ¾î Áö´Â±º¿ä. ¿úÀÌ Àִ°æ¿ì ¹æÈ­º®À» ¼³Ä¡ÇÏ¸é ¹Ù·Î Àû¹ßÀÌ µÇ´Â °æ¿ì°¡ ÀÖÀ¸¹Ç·Î ¹æÈ­º®ÀÌ ¾ø´Ù¸é sp2·Î ¾÷±ÛÇϰųª zonealarm °°Àº ¹æÈ­º®À» ¼³Ä¡ÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù.

ÇöÀç ÁֽŠ·Î±×·Î ºÃÀ»¶§ Ưº°ÇÏ°Ô Àǽɰ¡´Â È­ÀÏÀ̳ª ÇÁ·Î¼¼½º ¸ñ·ÏÀº ¾ø¾î º¸ÀÔ´Ï´Ù.

O18 - Protocol: s-http - {D37E6C5F-1C0F-47C0-A3B6-403EEC555402} - C:\Program Files\INITECH\SHTTP\InitechSHTTPInterface.10111.dll

Àº ÀúÇÑÅ× »ý¼ÒÇѵ¥ inisafe web v.7 Àΰ¡ ÇÏ´Â ÀºÇà¾Æ´Ï¸é °ü°ø¼­ °ü·Ã ÇÁ·Î±×·¥À̳ª ÇÁ·ÎÅäÄÝ °°¾Æ º¸À̹ǷΠ±×³É Á¦°Å ÇÏÁö ¾ÊÀ¸¼Åµµ µÉ°Í °°³×¿ä.

ÇöÀç ÁֽŠautoruns ·Î±×¿¡¼­ º¸¸é

+ ÀÛ¾÷ Ç¥½ÃÁÙ ¹× ½ÃÀÛ ¸Þ´º File not found: CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}\InprocServer32

ÀÌ·±½ÄÀ¸·Î File not found ¶ó°í µÈ entries ´Â ¸ðµÎ »èÁ¦Çϼŵµ µË´Ï´Ù. ÀÌ°ÍÀº ÇöÀç ÇØ´çÀ§Ä¡¿¡ ÀÖ´Â È­ÀÏÀº ¾ø°Å³ª Á¦°Å µÇ¾ú´Âµ¥ ·¹Áö½ºÆ®¸®¿¡ ³²¾Æ¼­ ³ªÅ¸³ª´Â °ÍÀÌ°í ÀÌ·± ºÒÇÊ¿äÇÑ ·¹Áö½ºÆ®¸®µéÀº ³ªÁß¿¡ ÄÄÇ»Å͸¦ ´À¸®°Ô ÇÒ ¼öÀÖÀ¸¹Ç·Î ·¹Áö½ºÆ®¸® ¹é¾÷À» Çϼ̴ٸé Áö¿ì½Ã±æ ±ÇÀ¯ ÇÕ´Ï´Ù.

´Ù½Ã Çѹø autoruns ·Î±×¸¦ ÀúÀåÇؼ­ ¿Ã·ÁÁֽñ¸¿ä. ½Ã½ºÅÛ »ç¾çµµ ¾Ë·ÁÁֽñ¸¿ä.

º¸Åë ¹ÙÀÌ·¯½ºµéÀº winlogon.exe, userinit.exe, explorer.exe °°Àº shell ÇÁ·Î¼¼½º¿¡ hook À» Çϰųª Internet explorer ¿¡ Åø¹ÙµîÀÇ addon Çü½ÄÀ̳ª system32 ¶Ç´Â windows Æú´õ, Temp Æú´õ¿¡¼­ Á÷Á¢ ½ÇÇàÇϱâ À§ÇØ run ·¹Áö½ºÆ®¸® ºÎºÐ¿¡ µî·ÏÀ» ÇÕ´Ï´Ù. ¿äÁò¿£ ¾Æ¿¹ Driver.sys ³ª System Volume information Æú´õ ¶Ç´Â °¡Â¥ ºñµð¿À ¿Àµð¿À codec µîÀ¸·Î À§ÀåÀ» ÇÏ´õ±º¿ä.

ÇÑ°¡Áö ´õ Sp2 ¾÷±×·¡À̵å ÇÒ¶§ Æ÷¸äÀ» ÇÑ´Ù°í Çϼ̴µ¥ Æ÷¸äÀ» ÇÏÁö´Â ¾Ê±¸¿ä,
¾÷±×·¡À̵å ÇϱâÀü¿¡ ¼³Ä¡µÇ¾î ÀÖ´Â ÇÁ·Î±×·¥µé Áß¿¡ Ȥ½Ã ȣȯÀÌ ¾ÈµÇ´Â°Ô ÀÖ´ÂÁö (º¸Åë ¿äÁò¿£ ´Ù ȣȯÀÌ Àß µÇ´Â°ÍÀ¸·Î ¾Ð´Ï´Ù.) ȤÀº ¹ÙÀÌ·¯½º¿¡ °¨¿°µÇ¾î ÀÖ´Â »óÅ°ųª ºÒ¾ÈÁ¤ÇÑ »óÅ¿¡¼­ ¾÷±ÛÀ» Çϸé Áß°£¿¡ ¿¡·¯°¡ ³ª¼­ Á¦°ÅÇϴµ¥ °í»ýÀ» ÇÏ°Ô µÇÁö¿ä. ºÐ¸í Áß°£¿¡ À߸øµÇ¾îµµ º¹±¸ ÄÜ¼Ö ¸í·ÉÇà¿¡¼­ Á¦°ÅÇÏ´Â ¹æ¹ýµµ ÀÖ½À´Ï´Ù¸¸ À¢¸¸ÇÏ¸é ¾÷±ÛÀÌ Àß µÈ´ä´Ï´Ù.

´Ù¸¥ °í¼ö´ÔµéÀ» À§ÇØ º¸³»ÁֽŠ·Î±×¸¦ ¿©±â¿¡ Á¦°¡ ¿Ã¸®°Ú½À´Ï´Ù.

hijackthis ·Î±× È­ÀÏ
Àοë
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at ¿ÀÈÄ 4:27:19, on 2008-03-01
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\npkcmsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: IWebInterception Class - {BFDDBDBB-F62C-4D4A-B574-59D276F47196} - C:\Program Files\Click To Tweak [Basic]\WebInterception.dll
O2 - BHO: NoPhishing - {D3B071BE-7C15-43f6-8348-01EFC6092591} - C:\Progra~1\SoftRun\NoPhishing\NoPhishing.dll
O3 - Toolbar: ³×À̹ö Åø¹Ù(&N) - {D09CFF09-A42A-4EDC-9804-E61224F59CA1} - C:\Program Files\naver\NaverToolbar\NaverTB_3_0_1_56.dll
O3 - Toolbar: ¶óµð¿À(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] ctfmon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] ctfmon.exe (User 'Default user')
O8 - Extra context menu item: Microsoft Excel·Î ³»º¸³»±â(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: ³×À̹ö °Ë»ö - res://C:\Program Files\naver\NaverToolbar\NaverTB_3_0_1_56.dll /SEARCH.HTML
O8 - Extra context menu item: ³×À̹ö ºÏ¸¶Å©Çϱâ - res://C:\Program Files\naver\NaverToolbar\NaverTB_3_0_1_56.dll /BOOKMARK.HTML
O8 - Extra context menu item: ³×À̹ö ºí·Î±× ´ã±â - res://C:\Program Files\naver\NaverToolbar\NaverTB_3_0_1_56.dll /BLOG.HTML
O8 - Extra context menu item: ³×À̹ö »çÀü °Ë»ö - res://C:\Program Files\naver\NaverToolbar\NaverTB_3_0_1_56.dll /DIC.HTML
O8 - Extra context menu item: ³×À̹ö ÀÏÇÑ ¹ø¿ª - res://C:\Program Files\naver\NaverToolbar\NaverTB_3_0_1_56.dll /JKTRANS.HTML
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: *.samsungfire.com
O15 - Trusted Zone: http://*.suhyup-bank.com
O16 - DPF: FnWPro001 - http://www.samsungfn.com/applet/FnWPro001.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://singo.ncomservice.co.kr/include/font/fontserver.cab
O16 - DPF: {02FE7E8D-9DBD-4F77-8824-26C45D56CA9A} (CHZERO MAP CTRL) - http://gisweb4.chzero.com/zeromap/IMAPOCX_WEB.CAB
O16 - DPF: {042D97DD-E197-411A-8298-6EE85F1C1421} (mkdsfwCtrl Class) - http://ahnlabdownload.nefficient.co.kr/asp/cab/mkdsfw.cab
O16 - DPF: {044123B5-35DF-4C4E-BAED-26B8ED964342} (HLiveRobotWeb Control) - http://fx.hauri.net/HProduct/livesuite/shinhan/CLIENT/LiveSuite/web/HLiveRobotWeb.cab
O16 - DPF: {0C2955F4-8400-4EDB-BA3E-6960865CCC0E} (SecureSession Class) - http://www.samsungnetwork.com:5000/PKI/SecuiSecContractIE.cab
O16 - DPF: {0CD2EC08-3CF6-4BC4-BF48-824F4C1994F1} (SecureSession Class) - http://www.samsungfn.com/contents/trustnet/TNWebToolkit.cab
O16 - DPF: {0DAF3967-7DBB-4A85-8CA7-F143483F09CD} (GISWareClient Control) - http://road.moct.go.kr/webserver/GisWared.Cab
O16 - DPF: {162C9EF4-C989-4A60-A465-8D0E8F25A3B7} (FileDownLoadObj Class) - http://mall-etax.interpark.com/interpark/FileDownLoad_vista.cab
O16 - DPF: {1A29905C-C082-11D4-9376-00AA00BFFB71} (checkVerX Control) - http://download.hts.nefficient.co.kr/hts/wcom/cab/checkVer.cab
O16 - DPF: {1AC030E0-4571-483F-A6E0-5DBEB1150AD7} (MAWS_NHIC Class) - http://222.239.77.94/viewer30_new/MARKANY/MAOnFPS_NHIC.cab
O16 - DPF: {1B3E813B-EF11-4CE2-93E7-9A033CB3E336} (PsAction Control) - http://toolbar.pressian.com/toolbar/setup/psAction.cab
O16 - DPF: {1BC0F715-34E2-4C99-A6EF-CDBC7508374A} (SecureSession Class) - https://partnerlogin.samsungelectronics.com/ko/secui/SecuiB2BIE-ko.cab
O16 - DPF: {1CC26E3F-F20A-4074-8BB0-F34242591459} (ReportExpress.Viewer) - http://ipsi.snu.ac.kr/rpt/instRE/reportexpress.cab
O16 - DPF: {1CD4FAEE-09F6-4B77-8A49-EF2A9EBC8D46} (RSUpCtrl Control) - http://203.254.193.247/cab/rsupctrl.cab
O16 - DPF: {1D4FC3AF-3253-43A4-B346-5D1198D1EB8E} (CINIWebPlus Class) - http://img.shinhan.com/rib/common/INISWebPlus/INISWebPlus10.cab
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
O16 - DPF: {2022EE84-1E1F-45B0-8D35-FF9DA75366BC} (ExpressViewer Class) - http://download.softforum.com/Published/XecureExpressI/v2.4.0.5/xei_install2.cab
O16 - DPF: {20BBA18F-5BC8-47B5-8FC9-5DFCA8E56A4B} (XacsPop Control) - http://mpi.dacom.net/XMPI/js/xmpi2007.cab
O16 - DPF: {270EC7A6-4096-469B-865C-F9678A2C742B} (EasyPayX Control) - http://www.payzone.co.kr/EasyPayX/EasyPayX.cab
O16 - DPF: {286A75C3-11FB-4FB4-AC4A-4DD1B0750050} (INISAFEWeb6 V6 Class) - http://img.shinhan.com/initech/plugin/ver6106/down/INIS60.cab
O16 - DPF: {2882C368-D508-11D4-A2AB-000102598CE4} (LProtect Control) - http://fx.hauri.net/CLIENT/LiveSuite/livecall/livecall.cab
O16 - DPF: {293834C7-05B9-418C-A7DC-B59B08C8716C} (IntraMap2DXSeBIS Control) - http://210.96.13.83/ActiveX/IntraMap2DXSeBIS.cab
O16 - DPF: {2EF3C53E-E0C0-4076-9A7B-51D7B2D1549E} (KDownLoadExec Class) - http://sims-ebook.kia.co.kr/goods/component/kdlexec.cab
O16 - DPF: {2F8A9AB6-4A0B-47F1-95D9-2A0F100064E1} (MAGETDATA Class) - http://mpi.dacom.net/XMPI/js/XACSDATA.cab
O16 - DPF: {39461460-2552-4D51-A062-3AB6A7B902E9} (INISAFE Updater Control) - http://img.shinhan.com/shttp/install/down/INIS70.cab
O16 - DPF: {39FC0CF9-86F3-4502-B773-D16706EDEC83} (SCSK Control) - http://img.shinhan.com/rib/common/keyStroke/SoftCamp/402011/scsk4.cab
O16 - DPF: {3A90D051-E921-4741-8288-D1B6747A8A51} (Yessign5 Control) - http://www.giro.or.kr/html/yessign/cab/yessign5.cab
O16 - DPF: {3B56E5F0-7B20-48BF-B439-A995BE5191EF} (SessionControl Control) - http://pib.wooribank.com/com/common/SessionControl.cab
O16 - DPF: {3C36DCBE-5CDF-4C35-9D0B-4A1882B2EB0A} (AllatPayREAtl Class) - https://tx.allatpay.com/component/AllatPayRE.cab
O16 - DPF: {3D17B84E-BCB2-49E0-B7CC-6732425B2A7F} (Qubi Install Control) - http://local.qubi.com/activex/Install.CAB
O16 - DPF: {3DDB716E-8BA8-43B5-A926-6FB04193FFA0} (Maws_KRail Class) - http://ret.qubi.com/qubi/markany/client/MAOnFPS_KORAIL.cab
O16 - DPF: {42E8651D-C437-4203-93F5-24E20C2C4465} (KvpVCardCtl Control) - https://www.vpay.co.kr/kvpfiles/KVPCyberCard.cab
O16 - DPF: {447F9423-2046-4267-9B93-11626D001183} (RewardNetwork amLauncher Class) - http://affiliate.rewardnetwork.net/codebase/launcher/WShani.cab
O16 - DPF: {45091AA2-1574-4EC8-B520-4C27E29CF889} (GifFreezerCtrl Class) - http://www.gmarket.co.kr/challenge/neo_goods/dlls/gifFreezer.cab
O16 - DPF: {4646547A-22E8-485F-95BC-B4C76835BF80} (RSAutoUp Control) - http://rsup.net/cab/rsautoup.cab
O16 - DPF: {48ECCD73-123C-4C25-A64C-76E8E8A30CAF} (XPayMPIOCX Control) - https://mpi.dacom.net/XPayMPI/Xecure_LiveUpdate_XPayMPIOCX.cab
O16 - DPF: {4B48CEDD-EB09-4FD3-AA22-5BDE98EDEF90} (EZXSActiveX Control) - http://www.globalwindow.org/wps/ezxssso/install/ezxsactivex.cab
O16 - DPF: {4C68DACE-E6BC-4650-9C7E-D036720CA729} (Nps Control) - http://update.nprotect.net/npcore/npav/nps.cab
O16 - DPF: {4E8B516E-94F7-4E23-BBA8-794EED477AD5} (MPReg Control) - http://www.sbs.co.kr/new/mplay/movie_cp/pmang_players/SBSiMPReg.cab
O16 - DPF: {4F7C1FA4-2588-4233-90DF-B3EDB16DE222} (SPEngine Class) - http://222.239.77.94/viewer30_new/BCQRE/SPSetup.cab
O16 - DPF: {523E756E-9A65-45C4-A438-4C5522F59CE8} (ShellBTM20Com Class) - https://ansim.suhyup.co.kr/PkiCube/BtCxBTM20.cab
O16 - DPF: {53EED863-B547-40F8-B24A-2D6DE807CFE8} (Printmade Control) - http://img.shinhan.com/rib//ko/print/Printmade.cab
O16 - DPF: {57979411-BD4D-4896-9A89-415A902430B6} (eKSys SmartMapGX SDK 4.0) - http://map.visitkorea.or.kr/Scripts/Common/MapData/SmartMapGXW.cab
O16 - DPF: {5797A411-BD4D-4896-9A89-415A902430B6} (eKSys SmartMapGX SDK 3.0) - http://update.speednavi.co.kr/Whereis/MapCommon/SmartMapGX.cab
O16 - DPF: {5797C411-BD4D-4896-9A89-415A902430B6} (KSys SmartMapGX SDK 3.0 for Mozen, HMC, KMC) - http://www.kia.co.kr/common/SmartMapGX_Mozen.cab
O16 - DPF: {5CA5E00D-80A8-475A-BF08-816FD56DBC38} (KTCtrl Class) - http://support.kornet.net/sw5/order/Speed/cab/KTSpeedNewCtrl.cab
O16 - DPF: {5DAEF053-DEF0-4752-A963-CCE9B49B0B79} (Gogs Class) - http://bridge.item2.naver.com/music/cab/nbgm.cab
O16 - DPF: {5E582BD1-6FAA-40F2-87A8-130AD325DABB} (Kdfense7 Control) - http://www.samsungfn.com/contents/kdefense/cab/04121518/kdfense7.cab
O16 - DPF: {6531D99C-0D0E-4293-B3CB-A3E1D0D41847} (AhnASP Control) - http://ahnlabdownload.nefficient.co.kr/asp/cab/AhnASP.cab
O16 - DPF: {66413DC2-F891-40BC-822D-B7EEC8ADC281} (ProWorksGrid Control) - http://img.shinhan.com/cib/common/ProWorksGrid_78.cab
O16 - DPF: {67090735-D541-4FF9-B466-8778676ECD31} (WebPriKotra Control) - http://www.kotra.or.kr/webpri/WebPri_Kotra.cab
O16 - DPF: {67169E1F-5405-4780-8419-DA342168429C} (MAWS_SMFIRE Class) - http://globaltps.samsungfire.com/aireport/AIViewer/MAOnFPS_SMFire.cab
O16 - DPF: {68253470-5D4F-4CDF-8D9C-353C14A2F013} (SVPorsche Control) - http://img.yahoo.co.kr/multi/2005/tool/player/20060116/SVPorsche.cab
O16 - DPF: {6A2E758A-028B-46BB-A11D-0608AB5A4ED3} (DaumBGMCtrl Class) - http://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab
O16 - DPF: {6A599FB1-6CF1-42D8-9293-88B6FCC89E78} (CyberInstaller Control) - http://www.cybermed.co.kr/~distribution/CyberInstaller.cab
O16 - DPF: {6AD54F1E-D241-48B4-ACFF-37BA1B1BF7AD} (SMInstallCom Class) - http://ax.spymedic.co.kr/control/SpyMedicWebInst.cab
O16 - DPF: {6CE20149-ABE3-462E-A1B4-5B549971AA38} (XecureCKKB Class) - http://www.nhic.or.kr/XecureCK/CKKeyPro.cab
O16 - DPF: {70EE0AA4-5A3A-4052-8FFA-2EEDA43F7942} (Innotive Cibrowser Control 1.1) - http://www.congnamul.com/bluebird/ActiveX/cibrowser_1_1_1_148.cab
O16 - DPF: {7114AB1F-A8FE-4EB8-8AEB-0D0C47E866AD} (MA_POP Class) - https://mpi.dacom.net/XMPI/js/XacsPlugin.cab
O16 - DPF: {7876A60C-6116-4AD9-B0EE-C53A06C08747} (IPCheckerX Control) - http://203.248.245.162:8080/ftth/ftth/popup/IPCheckerX.cab
O16 - DPF: {79C871A6-F9C8-44DA-B2C9-CD9438D9642C} (EZXSInstaller Control) - http://www.globalwindow.org/wps/ezxssso/install/ezxsinstaller.cab
O16 - DPF: {7C65E65F-5ACA-409E-9D44-79AD833919F8} (ExpressViewer Class) - http://download.softforum.co.kr/XecureExpressI/xei_install.cab
O16 - DPF: {7E9FDB80-5316-11D4-B02C-00C04F0CD404} (XecureWeb 4.0 Client Control) - http://download.softforum.co.kr/Published/XecureWeb/v7.2.1.2/xw_install.cab
O16 - DPF: {87150955-C8C8-4693-B8E3-69E9B4EC23EC} (Yessign5 CMP Control) - http://www.yessign.or.kr/yessignCert5/yesCMP5.cab
O16 - DPF: {8871DC33-DFB8-4A36-9DF1-E3CD3334ABA5} (JUploadLib Class) - http://ktdom.com/ActiveX/KTdomUpload.cab
O16 - DPF: {8FA8D5F7-7CBA-46D4-9568-68D70C5280E8} (NoPhishingX Control) - http://www.nophishing.co.kr/softrun/SR02/SRNPSH.cab
O16 - DPF: {90227A18-E482-47B8-83F2-146CABA6ABF7} - http://update.nprotect.net/nprotect/kb/npws/npwsx.cab
O16 - DPF: {91A6D076-F1AA-44DC-9825-9F7DE41E2398} (WooricyMap Control) - http://traffic.local.naver.com/Traffic_browser/map/Objects/WooricyMap(1,0,0,25).cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} - http://cafeimg.hanmail.net/cab9_1/dmcc2.cab
O16 - DPF: {95660C51-0E11-4133-AA4C-492E62F2D123} (AX_KTX_eTicket Control) - http://ret.qubi.com/tk/Ax_KTX_eTicket.cab
O16 - DPF: {95ECBC00-7121-4379-BD64-69B42A0F1123} (MapID Control) - http://www.mapid.net/ActiveX/MapID_V15.cab
O16 - DPF: {9730FE74-2ADD-4AB4-BB46-9C4B6978C6B9} (WebPriGiro Control) - http://biz.giro.or.kr/webpri/WebPri_Giro.cab
O16 - DPF: {97533519-FBD3-42D5-BB07-C49F022B39EE} (MAWS_NTS Class) - http://download.hts.nefficient.co.kr/hts/yesone/cab/MAOnFPS_NTS.cab
O16 - DPF: {999257DE-B873-4E51-9478-F015EE1F76B2} (BTTrustSite Class) - http://download.banktown.com/suhyup/BTTrustSite.cab
O16 - DPF: {99C709C7-4F58-46C1-855B-90213C760395} (v3d Class) - https://secure.kcp.co.kr/webpay/v3d/file/kcp_ansimclick.cab
O16 - DPF: {9AEBAA67-8B4D-4884-9EB7-8C6BEA20CE5C} (FileManager Control) - http://img.anycall.com/cab/NetEditor.cab
O16 - DPF: {9BDBC41E-C335-4263-83C0-ECE78EE28A33} (SysMonOCX Control) - http://ahnlabdownload.nefficient.co.kr/plugin/myfirewall/myfirewall20.cab
O16 - DPF: {9CDD57AC-CA86-464C-B920-3228A388CC78} (NaverFileControl Control) - http://file.naver.com/activex/NaverFile.cab
O16 - DPF: {9DEFEDFC-8193-4BE6-AA60-B6375AB7C8BE} (Launcher Class) - http://patch.mnet.com/NaverMusic/ActiveX/naverx.cab
O16 - DPF: {9FC84F7D-D177-4A75-A7BB-429DA5BD0A3E} (SG_CAppAtx Control) - http://download.signgate.com/download/common/ews/release/ewsinstaller.cab
O16 - DPF: {A1832535-5218-42F9-8959-19E2BCABFABF} (INIwallet50 Control) - http://plugin.inicis.com/wallet50/INIwallet50.cab
O16 - DPF: {A1D886C6-4039-4451-97A9-515F5BE5D4C2} (mkdplusCtrl Class) - http://ahnlabdownload.nefficient.co.kr/asp/cab/mkdplus.cab
O16 - DPF: {A349609D-1864-443A-AD48-EE577A17264A} (AIIntegratedGenCtrl Class) - http://www.samsungfire.com/aireport/AIViewer/AIIntegratedGen.cab
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} (Kdfense8 Control) - http://kings.nefficient.co.kr/kings/kdfx/kdfx308/kdfense8.cab
O16 - DPF: {A47D74C2-CB98-4692-BF7C-32CE695AF689} (FreeMap Control) - http://map.isuperpage.co.kr/ocx/FreeMap.cab
O16 - DPF: {A88BBD0A-5C41-4014-B447-1FDAB89C8BBB} (GISClientITS Control) - http://road.moct.go.kr/webserver/GisWare.cab
O16 - DPF: {A8917DCC-6DBE-4562-99DE-62D633DE412D} (MLInstaller Class) - http://www.dla.go.kr/magicline/setup/MLInstaller.cab
O16 - DPF: {A9F090E5-FC80-4772-AFEE-D102AB6E77D6} (IssacWebProCMS Class) - http://pgdownload.lgdacom.net/dacom/IssacWebProCMS_4_2_6_8_DACOM.cab
O16 - DPF: {B0A75875-3622-48BA-B5FF-45AD77AC2D0E} (BankPayEFTCtrl Control) - http://www.bankpay.or.kr/BankPayEFT.cab
O16 - DPF: {B3260660-93AC-48D8-8DDC-2C22192CA2AB} (Naver Mail BigFile Upload Control2) - http://mail.naver.com/activex/NvBigFileUpload2_NT.cab
O16 - DPF: {B45E969D-924F-4C83-ACF3-38CDD115AA2C} (MpiPlugin Class) - https://www.samsungmall.co.kr/order/ilk/ilkactx2006.cab
O16 - DPF: {B5BFFF5D-CA0D-4593-AB84-7F8ACB2AC42A} (MAPntCtrl Class) - http://ret.qubi.com/qubi/markany/client/MAOnFPS_PNT.cab
O16 - DPF: {B640AB04-7C42-49F1-BFBB-1B65AC47B0B2} (CpcFTP Control) - https://cpcex.sec.samsung.net/Windchill/ext/cpcex/auth/CpcFTP1059.cab
O16 - DPF: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} (Daum ActiveX manager Class) - http://cafeimg.hanmail.net/cto/xman.cab?ver=1,2,2,0
O16 - DPF: {BBB0FC2D-1D95-45CA-BDCF-03B53F247FCC} (EwsLoader Class) - http://download.signgate.com/download/ews/ewsinstaller.cab
O16 - DPF: {BD6BB450-7C69-43B8-96F3-689CAE57AB51} (SBSWebPlayer Class) - http://netv.sbs.co.kr/object/player/SBSWebPlayer.cab
O16 - DPF: {C1143E84-B2B1-473B-9F20-E62DD754FCAF} (VineTransfer Control) - http://img.shinhan.com/rib/common/infovine/ver1023/VineTransfer.cab
O16 - DPF: {C2C16510-10F4-46FE-A82C-4846435EBDEB} (p3muzset Class) - http://casx.musiccity.co.kr/empas/dll/p3empasset.cab
O16 - DPF: {C2F50390-8033-4CC2-A0C6-DD7D3E6A9550} (AxTSAPI2 Class) - http://www.ctradeworld.com/tradesign/certcenter/setup/AxTSAPI2.cab
O16 - DPF: {C63E3330-049F-4C31-B47E-425C84A5A725} (EpAdm2 Control) - http://cpc.sec.samsung.net/EpAdm2.cab
O16 - DPF: {C7C7225A-9476-47AC-B0B0-FF3B79D55E67} (ZTransferX Control) - http://222.239.77.94/viewer30_new/ZTransferX.cab
O16 - DPF: {CAB259A5-1873-4D24-B743-AD16B60F6821} (EgiroFileDown Control) - http://e-giro.giro.or.kr/yessign/cab/egiroYessign5.cab
O16 - DPF: {CB5C683C-416A-4701-B018-0F1B21D64D6B} (SKCInst1 Class) - http://cyimg7.cyworld.nate.com/cymusic/package/skcinst.cab
O16 - DPF: {CDF26594-A9E2-4E41-87F9-6E79DD38CFE3} (AutoTrustHTTPControl Control) - http://www.ubistar.co.kr/ir/AutoTrustHTTP.cab
O16 - DPF: {CEB5C2A3-180A-4121-BDAC-B9B92859D652} (MaPrtRail Class) - http://ret.qubi.com/ht/markany/client/MaPrtChk_KRAIL.cab
O16 - DPF: {CEE326E8-7571-4086-B347-3C0ACA9A9DE8} (PcubeSet Class) - http://casx.musiccity.co.kr/empas/dll/p3empasset.cab
O16 - DPF: {CF392830-663F-11D5-89EE-000086551DF6} (PS_NTSATL Class) - http://download.hts.nefficient.co.kr/hts/yesone/cab/yesone_crypto.cab
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://update.nprotect.net/nprotect/module/npx.cab
O16 - DPF: {D26A941D-7E89-4098-B583-43291FC14218} (Pull0PlayerX Control) - http://image.pullbbang.com/images/Pull0Control.ocx
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://update.nprotect.net/keycrypt/kftc/npkcx_vista.cab
O16 - DPF: {D7EBA5BF-69D0-40E4-B513-87078CA7DD87} (Woori Credit Card Class) - http://ccd.wooribank.com/com/common/wooricard.cab
O16 - DPF: {D7EFD319-098B-4918-8ECF-25A8E8EE1940} (Maptopia WindW Control) - http://www.inavi.com/_Lib/Component/WindW_R%20Maptopia%20Control.cab
O16 - DPF: {D912AABC-6CB0-416F-85B6-CABBB86FD558} (INIwallet60 Control) - https://plugin.inicis.com/wallet60/INIwallet60.cab
O16 - DPF: {D923AE0C-190D-4EDF-B07A-76AC571FBFD4} (SCSKEx Control) - http://img.shinhan.com/rib/common/keyStroke/SoftCamp/4091_ex/scskex.cab
O16 - DPF: {D96D2F74-0B74-47D2-964F-B67E9F69F1CD} (CongnamulMap4Asp Control) - http://www.congnamul.com/ActiveX/Release/ASP/CongnamulMap4Asp_V29.cab
O16 - DPF: {DA756535-F523-4414-B167-DBDD8AA8C4A1} (S151AX Control) - http://cryptotelecom.net/S151AX.cab
O16 - DPF: {DA76E8AE-2E7F-49A8-B5F2-D1C4FF70ECD5} (SamsungMap Control) - http://mapsvc.samsung.co.kr/ActiveX/SamsungMap_V25.cab
O16 - DPF: {DC4207CE-C03E-4449-ACB1-032CA4137053} (Npz Control) - https://updates.nprotect.net/nprotect2004/hyundaecard/ansimclick/npz2.cab
O16 - DPF: {DC5C4F1B-8F7A-47CE-ACCA-EBB25D1567C6} (Naver_ZaolMap2Client Control) - http://traffic.local.naver.com/Traffic_browser/Objects/Naver_ZaolMap2Client.1017.cab
O16 - DPF: {DFFD6203-ACAF-4AE3-92EA-E0323FBF4BF3} (SesureSession Class) - http://www.samsungfire.com/download/secui/SecuiFireIE.cab
O16 - DPF: {E0BF7A2B-2F7C-497A-B50F-292D3F317965} (CongnamulMap Control) - http://www.congnamul.com/ActiveX/Release/Congnamul/CongnamulMap_V17.cab
O16 - DPF: {E78928A6-3D2A-4BF7-A100-F3FBAA351B49} (KvpIspCtlD Control) - https://www.vpay.co.kr/kvpfiles/KVPISPCTLD.cab
O16 - DPF: {E831AA9C-C980-4F16-B252-09AAF40D0E9B} (Kdfense9 Control) - http://kings.cachenet.com/kdfx218/kbstar/kdfense9.cab
O16 - DPF: {EA0995BF-45DD-4DB0-ADD5-A39C37397841} (ShbAutoTrustSite Control) - http://img.shinhan.com/rib/common/TrustSite/20041202/ShbAutoTrustSiteX.cab
O16 - DPF: {EC5D5118-9FDE-4A3E-84F3-C2B711740E70} (SKCommAX Control) - http://www.samsungfn.com/skcab/SKCommAX.cab
O16 - DPF: {ED698244-D3B6-4016-95AB-7FF6BA95FF5E} (CMMapASP Control) - http://cybermap.co.kr/cm2000/company/hanaro-club/CMHANARO2.cab
O16 - DPF: {EF648869-6D94-4ED9-8426-FAABDACB9604} (EZXSVistaX Control) - http://www.globalwindow.org/wps/ezxssso/install/ezxsvistax.cab
O16 - DPF: {F1149E8A-79EB-4859-835E-95432B72FEA2} (AnycallLAND_DownCheck Control) - http://img.anycall.com/anycall/support/activex/AnycallLAND_DownCheckProj1.cab
O16 - DPF: {F1F07506-6CB4-44AC-8615-66D1234EFD05} (WebCtl Class) - http://www.shinhancard.com/initech/plugin/down/INIS50.cab
O16 - DPF: {F2B794F5-B8F0-4378-B05C-E26C310D9CE2} (Viewer Control) - http://www.yes24.com/home/openinside/yes24preview.cab
O16 - DPF: {F3222ADD-F760-4ACC-A70F-3839AD82FF88} (mkdsecuiCtrl Class) - http://ahnlabdownload.nefficient.co.kr/asp/cab/mkdsecui.cab
O16 - DPF: {F4A1D5E2-AF49-47A7-A945-23038106F3A4} (Pandora_SetUp Control) - http://imgcdn.pandora.tv/pan_img/launcher/codebase/Pandora_SetUpAX.cab
O16 - DPF: {F9143948-F472-4397-8B9F-237B6CB07C48} (DSProxyX Class) - http://dla.go.kr/magicline/setup/DSProxyX.cab
O16 - DPF: {FB49C5D6-ABCC-47ED-AC05-B80E578183B0} (DSCertManagerX Class) - http://www.dla.go.kr/magicline/setup/DSCertManagerX.cab
O18 - Protocol: s-http - {D37E6C5F-1C0F-47C0-A3B6-403EEC555402} - C:\Program Files\INITECH\SHTTP\InitechSHTTPInterface.10111.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ALYac_PZSrv - Unknown owner - C:\Program.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcmsvc.exe
O23 - Service: Pml Driver OEM12 - HP - C:\WINDOWS\System32\OEMipm12.exe

--
End of file - 22259 bytes


Autoruns ·Î±× È­ÀÏ.
Àοë
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ AVG7_CC AVG Control Center (Not verified) GRISOFT, s.r.o. c:\program files\grisoft\avg7\avgcc.exe
+ IntelliPoint Point32.exe (Not verified) Microsoft Corporation c:\program files\microsoft intellipoint\point32.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ Skype Skype. Take a deep breath (Verified) Skype Technologies SA c:\program files\skype\phone\skype.exe
HKLM\SOFTWARE\Classes\Protocols\Filter
+ application/octet-stream Microsoft .NET Runtime Execution Engine (Not verified) Microsoft Corporation c:\windows\system32\mscoree.dll
+ application/x-complus Microsoft .NET Runtime Execution Engine (Not verified) Microsoft Corporation c:\windows\system32\mscoree.dll
+ application/x-msdownload Microsoft .NET Runtime Execution Engine (Not verified) Microsoft Corporation c:\windows\system32\mscoree.dll
HKLM\SOFTWARE\Classes\Protocols\Handler
+ cdo Microsoft SharePoint Portal Server Object Model (Not verified) Microsoft Corporation c:\program files\common files\microsoft shared\web folders\pkmcdo.dll
+ s-http INITECH HTTP Wrapper Handler (Not verified) (c) INITECH c:\program files\initech\shttp\initechshttpinterface.10111.dll
+ skype4com Skype for COM API (Verified) Skype Technologies SA c:\program files\common files\skype\skype4com.dll
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ n/a Microsoft .NET IE SECURITY REGISTRATION (Not verified) Microsoft Corporation c:\windows\system32\mscories.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ AVG7 Find Extension AVG Shell Extension (Not verified) GRISOFT, s.r.o. c:\program files\grisoft\avg7\avgse.dll
+ AVG7 Shell Extension AVG Shell Extension (Not verified) GRISOFT, s.r.o. c:\program files\grisoft\avg7\avgse.dll
+ Fusion Cache Microsoft .NET Runtime Execution Engine (Not verified) Microsoft Corporation c:\windows\system32\mscoree.dll
+ IntelliPoint Activities Control Panel Property Page ipcplact.dll (Not verified) Microsoft Corporation c:\program files\microsoft intellipoint\ipcplact.dll
+ IntelliPoint Buttons Control Panel Property Page ipcplbtn.dll (Not verified) Microsoft Corporation c:\program files\microsoft intellipoint\ipcplbtn.dll
+ IntelliPoint Wheel Control Panel Property Page ipcplwhl.dll (Not verified) Microsoft Corporation c:\program files\microsoft intellipoint\ipcplwhl.dll
+ IntelliPoint Wireless Control Panel Property Page ipcplwir.dll (Not verified) Microsoft Corporation c:\program files\microsoft intellipoint\ipcplwir.dll
+ User Accounts File not found: CLSID\{7A9D77BD-5403-11d2-8785-2E0420524153}\InprocServer32
+ Web Folders Microsoft Web Folders (Not verified) Microsoft Corporation c:\program files\common files\microsoft shared\web folders\msonsext.dll
+ WinRAR shell extension c:\program files\winrar\rarext.dll
+ µð½ºÇ÷¹ÀÌ ÆÐ´× CPL È®Àå File not found: deskpan.dll
+ ÀÛ¾÷ Ç¥½ÃÁÙ ¹× ½ÃÀÛ ¸Þ´º File not found: CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}\InprocServer32
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ IWebInterception Class WebInterception Module (Not verified) Realization of Dream c:\program files\click to tweak [basic]\webinterception.dll
+ NoPhishing NoPhishing DLL Module (Not verified) Softrun Inc. c:\program files\softrun\nophishing\nophishing.dll
+ Skype add-on (mastermind) Skype add-on for IE (Verified) Skype Technologies SA c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ NaverToolbar NaverToolbar Module (Verified) NHN corp. c:\program files\naver\navertoolbar\navertb_3_0_1_56.dll
HKLM\System\CurrentControlSet\Services
+ Avg7Alrt AVG Alert Manager (Not verified) GRISOFT, s.r.o. c:\program files\grisoft\avg7\avgamsvr.exe
+ Avg7UpdSvc AVG Update Service (Not verified) GRISOFT, s.r.o. c:\program files\grisoft\avg7\avgupsvc.exe
+ npkcmsvc nProtect KeyCrypt Manager Service (Not verified) INCA Internet Co., Ltd. c:\windows\system32\npkcmsvc.exe
HKLM\System\CurrentControlSet\Services
+ AFPAnsi Windows NT File System Protector Network Edition (Not verified) Alfa Corporation c:\windows\system32\drivers\afpansi.sys
+ Avg7Core AVG Scanning Engine (Not verified) GRISOFT, s.r.o. c:\windows\system32\drivers\avg7core.sys
+ Avg7RsW AVG Resident Shield Unload Helper (Not verified) GRISOFT, s.r.o. c:\windows\system32\drivers\avg7rsw.sys
+ Avg7RsXP AVG Resident Anti-Virus Shield (Not verified) GRISOFT, s.r.o. c:\windows\system32\drivers\avg7rsxp.sys
+ AvgClean AVG7 Clean Driver (Verified) GRISOFT, s.r.o. c:\windows\system32\drivers\avgclean.sys
+ AYDrvNT_ALYAC Kernel Mode Driver (Verified) ESTsoft Corp. c:\program files\estsoft\alyac\aydrvnt.sys
+ Changer File not found: C:\WINDOWS\System32\Drivers\Changer.sys
+ DgiVecp Windows 2k,XP IEEE-1284 parallel class driver for ECP, Byte, and Nibble modes (Not verified) Samsung Electronics Co., Ltd. c:\windows\system32\drivers\dgivecp.sys
+ extdrv File not found: C:\WINDOWS\system32\drivers\extdrv.sys
+ extdrv.sys File not found: C:\WINDOWS\system32\drivers\extdrv.sys
+ i2omgmt File not found: C:\WINDOWS\System32\Drivers\i2omgmt.sys
+ JRSKD24 ClientKeeper KeyPro Keyboard Driver (Not verified) SoftForum Corporation c:\windows\system32\jrskd24.sys
+ JRSUKD24 ClientKeeper KeyPro Keyboard Driver (Not verified) SoftForum Corporation c:\windows\system32\jrsukd24.sys
+ kdss File not found: C:\WINDOWS\system32\Drivers\kdss.sys
+ lbrtfdc File not found: C:\WINDOWS\System32\Drivers\lbrtfdc.sys
+ Mkd2kfNt MyKeyDefense Keyboard Filter Driver (Not verified) AhnLab, Inc. c:\windows\system32\drivers\mkd2kfnt.sys
+ Mkd2Usbf MyKeyDefense USB Keyboard Filter Driver (Not verified) AhnLab, Inc. c:\windows\system32\drivers\mkd2usbf.sys
+ neokdss File not found: system32\Drivers\neokdss.sys
+ NMProPPPoE ACEMan-pro PPP over Ethernet Adapter (Not verified) SITECSOFT Co., Ltd. c:\windows\system32\drivers\netmanp.sys
+ NPFWFLT nProtect Firewall Filter Driver (Not verified) INCA Internet Co., Ltd. c:\windows\system32\npfwflt.sys
+ npkcrypt nProtect KeyCrypt Driver (Verified) INCA Internet Co.,Ltd. c:\windows\system32\npkcrypt.sys
+ NSavFlt Filter Driver (Not verified) NHN c:\windows\system32\drivers\nsavflt.sys
+ PCIDump File not found: C:\WINDOWS\System32\Drivers\PCIDump.sys
+ PDCOMP File not found: C:\WINDOWS\System32\Drivers\PDCOMP.sys
+ PDFRAME File not found: C:\WINDOWS\System32\Drivers\PDFRAME.sys
+ PDRELI File not found: C:\WINDOWS\System32\Drivers\PDRELI.sys
+ PDRFRAME File not found: C:\WINDOWS\System32\Drivers\PDRFRAME.sys
+ scsk5 File not found: system32\drivers\scsk5.sys
+ smgihqap File not found: C:\Program Files\smgihqap.sys
+ SSPORT File not found: C:\WINDOWS\System32\Drivers\SSPORT.sys
+ VRVD212 Virtual Remote Video Driver v2.0 (Not verified) RSupport Corporation c:\windows\system32\drivers\vrvd212.sys
+ VRVD302 Virtual Remote Video Driver(VRVD303) (Verified) Rsupport Co., Ltd. c:\windows\system32\drivers\vrvd302.sys
+ WDICA File not found: C:\WINDOWS\System32\Drivers\WDICA.sys


[ ¸Þ½ÃÁö¼öÁ¤: yoonsangfan ÀϽÃ: 2008-03-02 11:43 ]
´ÙÀ½±Û: windows xp·Î º¹±¸¼­¹ö ¸¦ ¸¸µé¼ö ÀÖ³ª¿ä? (0)44981spcskim2008-06-24
ÀÌÀü±Û: ¹Ìµð¾îÇ÷¹À̾îÀÇ ÄÜÆ®·ÑÀÌ ±úÁý´Ï´Ù (0)4828willun2008-01-08

»õ±Û¾²±â ´ä±Û¾²±â
À̵¿:

¼¼»ó»ç´Â À̾߱â



RSS ±¸µ¶ (À͸í | ȸ¿ø | °­Á | Æ÷·³)
(C) 1996 ~ 2017 QAOS.com All rights reserved.