블로그 이미지
CoIN은 Co-(함께)라는 의미와 IN(人)의 사람이라는 의미 CoInz

카테고리

분류 전체보기 (502)
[보안] 취약점 (2)
[보안] 악성코드 (83)
[보안] 리버싱 (94)
[운영체제] (49)
[컴퓨터] (89)
잡스런내용 (135)
사적인내용 (7)
[보안] 허니팟 (4)
[기타] 주식 (4)
[보안] 무선 (8)
[보안] 암호학 (10)
[보안] 기타 (17)
Total354,303
Today12
Yesterday64

달력

« » 2014.09
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30        
크리에이티브 커먼즈 라이선스
Creative Commons License
이 프로그램은 악성이라기 보다는 애드웨어로 분류될 수 있기에 해당 카테고리에 넣었다.

설치 과정에서 번들 설치가 이루어진다.



설치 파일들은 아래와 같다.

[ 생성되는 파일 목록 ]

C:\Documents and Settings\All Users\시작 메뉴\프로그램\백신Plus
C:\Documents and Settings\All Users\시작 메뉴\프로그램\백신Plus\라이센스.url
C:\Documents and Settings\All Users\시작 메뉴\프로그램\백신Plus\백신Plus.lnk
C:\Documents and Settings\All Users\시작 메뉴\프로그램\백신Plus\백신Plus삭제.lnk
C:\Documents and Settings\All Users\시작 메뉴\프로그램\백신Plus\홈페이지.url
C:\Documents and Settings\current\Application Data\Microsoft\Internet Explorer\Quick Launch\G마켓 바로가기.lnk
C:\Documents and Settings\current\Favorites\G마켓 바로가기.url
C:\Documents and Settings\current\바탕 화면\G마켓 바로가기.lnk
C:\Documents and Settings\current\시작 메뉴\G마켓 바로가기.lnk
C:\Program Files\pocketsearch
C:\Program Files\pocketsearch\PocketSearch.dll
C:\Program Files\pocketsearch\PocketSearchUpdate.exe
C:\Program Files\pocketsearch\PSUninstall.exe
C:\Program Files\QuickDownloadService
C:\Program Files\QuickDownloadService\conf
C:\Program Files\QuickDownloadService\conf\data2.cfg
C:\Program Files\QuickDownloadService\conf\data3.cfg
C:\Program Files\QuickDownloadService\conf\data4.cfg
C:\Program Files\QuickDownloadService\conf\Version.cfg
C:\Program Files\QuickDownloadService\qdownagent.exe
C:\Program Files\QuickDownloadService\qdownservice.exe
C:\Program Files\QuickDownloadService\qdownupdate.exe
C:\Program Files\QuickDownloadService\unins000.dat
C:\Program Files\QuickDownloadService\unins000.exe
C:\Program Files\SBoxPoint
C:\Program Files\SBoxPoint\SBoxPoint.exe
C:\Program Files\SBoxPoint\SBoxPointC.dat
C:\Program Files\SBoxPoint\SBoxPointC.exe
C:\Program Files\SBoxPoint\SBoxPointD.dat
C:\Program Files\SBoxPoint\Uninstall.exe
C:\Program Files\SBoxSearchBar
C:\Program Files\SBoxSearchBar\SBoxSearchBar.exe
C:\Program Files\SBoxSearchBar\SBoxSearchBarC.dat
C:\Program Files\SBoxSearchBar\SBoxSearchBarC.exe
C:\Program Files\SBoxSearchBar\SBoxSearchBarD.dat
C:\Program Files\SBoxSearchBar\SBoxSearchBarHK.dll
C:\Program Files\SBoxSearchBar\Uninstall.exe
C:\Program Files\ShareBox
C:\Program Files\ShareBox\ShareBoxC.exe
C:\Program Files\ShareBox\ShareBoxDown.exe
C:\Program Files\ShareBox\ShareBoxDown2.exe
C:\Program Files\ShareBox\ShareBoxUp.exe
C:\Program Files\ShareBox\Uninstall.exe
C:\Program Files\ShareBox\version.cab
C:\Program Files\ShareBox\WebhardAddon.dll
C:\Program Files\Vaccine-Plus
C:\Program Files\Vaccine-Plus\vcP.exe
C:\Program Files\Vaccine-Plus\vcPd.dll
C:\Program Files\Vaccine-Plus\vcPdbk.exe
C:\Program Files\Vaccine-Plus\vcPu.exe
C:\Program Files\Vaccine-Plus\vpsdata
C:\WINDOWS\Downloaded Program Files
C:\WINDOWS\Downloaded Program Files\ShareBoxCtrl.dll
C:\WINDOWS\Downloaded Program Files\ShareBoxCtrl.inf
C:\WINDOWS\system32
C:\WINDOWS\system32\gmarket_mone.ico
C:\WINDOWS\system32\ShareBox.ico
C:\WINDOWS\system32\uninst_vcP.exe

[ 레지스트리 항목 ]

[HKEY_LOCAL_MACHINE\software\Classes\AppID\ShareBoxCtrl.DLL]
"AppID"="{9B832821-E151-4EBD-8B41-8234EE64211E}"

[HKEY_LOCAL_MACHINE\software\Classes\AppID\{9209B1A6-964A-11D0-9372-00A0C9034910}]

[HKEY_LOCAL_MACHINE\software\Classes\AppID\{9B832821-E151-4EBD-8B41-8234EE64211E}]
@="ShareBoxCtrl"
"DllSurrogate"=""

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{000F369E-A063-40A3-B9CF-F49C3EF14C85}]
@="PSearchB Class"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{000F369E-A063-40A3-B9CF-F49C3EF14C85}\InprocServer32]
@="C:\\Program Files\\pocketsearch\\PocketSearch.dll"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{000F369E-A063-40A3-B9CF-F49C3EF14C85}\ProgID]
@="PocketSearch.PSearchB.1"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{000F369E-A063-40A3-B9CF-F49C3EF14C85}\Programmable]

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{000F369E-A063-40A3-B9CF-F49C3EF14C85}\TypeLib]
@="{E1B1BF47-85CA-43AE-9034-858354D8F9C0}"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{000F369E-A063-40A3-B9CF-F49C3EF14C85}\VersionIndependentProgID]
@="PocketSearch.PSearchB"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}]
@="ShareBox Class"
"AppID"="{9B832821-E151-4EBD-8B41-8234EE64211E}"
"LocalizedString"="@C:\\WINDOWS\\Downloaded Program Files\\ShareBoxCtrl.dll,-101"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\Control]

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\Implemented Categories]

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\ShareBoxCtrl.dll"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\MiscStatus]
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\MiscStatus\1]
@="131473"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\ProgID]
@="ShareBoxCtrl.ShareBox.1"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\Programmable]

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\ToolboxBitmap32]
@="C:\\WINDOWS\\Downloaded Program Files\\ShareBoxCtrl.dll, 103"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\TypeLib]
@="{9F2A6F97-A797-46EF-89D9-69CD12AAC632}"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{180C8380-22BA-4A62-A0E8-79F8DCE56B19}\VersionIndependentProgID]
@="ShareBoxCtrl.ShareBox"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{A5507F86-5D14-459D-96FE-471E1B3D1C23}]
@="PocketSearch"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{A5507F86-5D14-459D-96FE-471E1B3D1C23}\Implemented Categories]

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{A5507F86-5D14-459D-96FE-471E1B3D1C23}\Implemented Categories\{00021494-0000-0000-C000-000000000046}]

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{A5507F86-5D14-459D-96FE-471E1B3D1C23}\InprocServer32]
@="C:\\Program Files\\pocketsearch\\PocketSearch.dll"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{A5507F86-5D14-459D-96FE-471E1B3D1C23}\ProgID]
@="PocketSearch.PSearchC.1"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{A5507F86-5D14-459D-96FE-471E1B3D1C23}\Programmable]

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{A5507F86-5D14-459D-96FE-471E1B3D1C23}\TypeLib]
@="{E1B1BF47-85CA-43AE-9034-858354D8F9C0}"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{A5507F86-5D14-459D-96FE-471E1B3D1C23}\VersionIndependentProgID]
@="PocketSearch.PSearchC"

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{DBC80044-A445-435B-BC74-9C25C1C588A9}]

[HKEY_LOCAL_MACHINE\software\Classes\clsid\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

[HKEY_LOCAL_MACHINE\software\Classes\Component Categories]

[HKEY_LOCAL_MACHINE\software\Classes\Component Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]
"409"="Controls that are safely scriptable"

[HKEY_LOCAL_MACHINE\software\Classes\Component Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]
"409"="Controls safely initializable from persistent data"

[HKEY_LOCAL_MACHINE\software\Classes\CompressedFolder]

[HKEY_LOCAL_MACHINE\software\Classes\CompressedFolder\shell]

[HKEY_LOCAL_MACHINE\software\Classes\CompressedFolder\shell\open]

[HKEY_LOCAL_MACHINE\software\Classes\CompressedFolder\shell\open\ddeexec]

[HKEY_LOCAL_MACHINE\software\Classes\Interface]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{34B361DC-7E4A-4111-B982-C616CDDDBA4E}]
@="IPSearchC"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{34B361DC-7E4A-4111-B982-C616CDDDBA4E}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{34B361DC-7E4A-4111-B982-C616CDDDBA4E}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{34B361DC-7E4A-4111-B982-C616CDDDBA4E}\TypeLib]
@="{E1B1BF47-85CA-43AE-9034-858354D8F9C0}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{3F56DB04-8357-49B1-992F-F4191D247081}]
@="IShareBox"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{3F56DB04-8357-49B1-992F-F4191D247081}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{3F56DB04-8357-49B1-992F-F4191D247081}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{3F56DB04-8357-49B1-992F-F4191D247081}\TypeLib]
@="{9F2A6F97-A797-46EF-89D9-69CD12AAC632}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{83900949-7639-480A-A98C-C111D51ADE6F}]
@="_IShareBoxEvents"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{83900949-7639-480A-A98C-C111D51ADE6F}\ProxyStubClsid]
@="{00020420-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{83900949-7639-480A-A98C-C111D51ADE6F}\ProxyStubClsid32]
@="{00020420-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{83900949-7639-480A-A98C-C111D51ADE6F}\TypeLib]
@="{9F2A6F97-A797-46EF-89D9-69CD12AAC632}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E6495D2D-BD9F-4998-9738-3736A1F946E7}]
@="IPSearchB"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E6495D2D-BD9F-4998-9738-3736A1F946E7}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E6495D2D-BD9F-4998-9738-3736A1F946E7}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E6495D2D-BD9F-4998-9738-3736A1F946E7}\TypeLib]
@="{E1B1BF47-85CA-43AE-9034-858354D8F9C0}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\PocketSearch.PSearchB]
@="PSearchB Class"

[HKEY_LOCAL_MACHINE\software\Classes\PocketSearch.PSearchB\CLSID]
@="{000F369E-A063-40A3-B9CF-F49C3EF14C85}"

[HKEY_LOCAL_MACHINE\software\Classes\PocketSearch.PSearchB\CurVer]
@="PocketSearch.PSearchB.1"

[HKEY_LOCAL_MACHINE\software\Classes\PocketSearch.PSearchB.1]
@="PSearchB Class"

[HKEY_LOCAL_MACHINE\software\Classes\PocketSearch.PSearchB.1\CLSID]
@="{000F369E-A063-40A3-B9CF-F49C3EF14C85}"

[HKEY_LOCAL_MACHINE\software\Classes\PocketSearch.PSearchC]
@="PocketSearch"

[HKEY_LOCAL_MACHINE\software\Classes\PocketSearch.PSearchC\CLSID]
@="{A5507F86-5D14-459D-96FE-471E1B3D1C23}"

[HKEY_LOCAL_MACHINE\software\Classes\PocketSearch.PSearchC\CurVer]
@="PocketSearch.PSearchC.1"

[HKEY_LOCAL_MACHINE\software\Classes\PocketSearch.PSearchC.1]
@="PocketSearch"

[HKEY_LOCAL_MACHINE\software\Classes\PocketSearch.PSearchC.1\CLSID]
@="{A5507F86-5D14-459D-96FE-471E1B3D1C23}"

[HKEY_LOCAL_MACHINE\software\Classes\ShareBoxCtrl.ShareBox]
@="ShareBox Class"

[HKEY_LOCAL_MACHINE\software\Classes\ShareBoxCtrl.ShareBox\CLSID]
@="{180C8380-22BA-4A62-A0E8-79F8DCE56B19}"

[HKEY_LOCAL_MACHINE\software\Classes\ShareBoxCtrl.ShareBox\CurVer]
@="ShareBoxCtrl.ShareBox.1"

[HKEY_LOCAL_MACHINE\software\Classes\ShareBoxCtrl.ShareBox.1]
@="ShareBox Class"

[HKEY_LOCAL_MACHINE\software\Classes\ShareBoxCtrl.ShareBox.1\CLSID]
@="{180C8380-22BA-4A62-A0E8-79F8DCE56B19}"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{9F2A6F97-A797-46EF-89D9-69CD12AAC632}]

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{9F2A6F97-A797-46EF-89D9-69CD12AAC632}\1.0]
@="ShareBoxCtrl 1.0 Type Library"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{9F2A6F97-A797-46EF-89D9-69CD12AAC632}\1.0\0]

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{9F2A6F97-A797-46EF-89D9-69CD12AAC632}\1.0\0\win32]
@="C:\\WINDOWS\\Downloaded Program Files\\ShareBoxCtrl.dll"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{9F2A6F97-A797-46EF-89D9-69CD12AAC632}\1.0\FLAGS]
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{9F2A6F97-A797-46EF-89D9-69CD12AAC632}\1.0\HELPDIR]
@=""

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{E1B1BF47-85CA-43AE-9034-858354D8F9C0}]

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{E1B1BF47-85CA-43AE-9034-858354D8F9C0}\1.0]
@="PocketSearch 1.0 Type Library"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{E1B1BF47-85CA-43AE-9034-858354D8F9C0}\1.0\0]

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{E1B1BF47-85CA-43AE-9034-858354D8F9C0}\1.0\0\win32]
@="C:\\Program Files\\pocketsearch\\PocketSearch.dll"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{E1B1BF47-85CA-43AE-9034-858354D8F9C0}\1.0\FLAGS]
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{E1B1BF47-85CA-43AE-9034-858354D8F9C0}\1.0\HELPDIR]
@="C:\\Program Files\\pocketsearch\\"

[HKEY_LOCAL_MACHINE\software\microsoft\Internet Explorer\AboutURLs]
"ntick46"="2487312"

[HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000F369E-A063-40A3-B9CF-F49C3EF14C85}]
@=""
"NoExplorer"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run]
"PocketSearchUpdate"="C:\\Program Files\\pocketsearch\\PocketSearchUpdate.exe"
"vccplus"="C:\\Program Files\\Vaccine-Plus\\vcPu.exe /8L"

[HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\PocketSearch]
"DisplayName"="Pocket-Search"
"UninstallString"="C:\\Program Files\\pocketsearch\\PSUninstall.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Vaccine-Plus]
"DisplayName"="백신Plus(vaccine-plus)"
"DisplayVersion"="1.2"
"HelpLink"="http://www.vaccine-plus.co.kr"
"URLInfoAbout"="http://www.vaccine-plus.co.kr"
"UninstallString"="C:\\WINDOWS\\system32\\uninst_vcP.exe"
"DisplayIcon"="C:\\WINDOWS\\system32\\uninst_vcP.exe"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\{F44CB7E4-870C-4021-B1F9-0CF352200519}_is1]
"Inno Setup: Setup Version"="5.2.3"
"Inno Setup: App Path"="C:\\Program Files\\QuickDownloadService"
"InstallLocation"="C:\\Program Files\\QuickDownloadService\\"
"Inno Setup: Icon Group"="QuickDownloadService"
"Inno Setup: User"="cosrah"
"DisplayName"="QuickDownloadService"
"UninstallString"="\"C:\\Program Files\\QuickDownloadService\\unins000.exe\""
"QuietUninstallString"="\"C:\\Program Files\\QuickDownloadService\\unins000.exe\" /SILENT"
"Publisher"="QuickDownloadService"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"InstallDate"="20090901"

[HKEY_LOCAL_MACHINE\software\PocketSearch]
"installpath"="C:\\Program Files\\pocketsearch\\"
"pver"="33"
"uniq"="64CD0346-1802-5B3DBE2F-65E4"
"pid"="sharebox"
"macid"="00ffc7870a3d_001d7d9abecb_"
"counturl"="`GQ/bCnuK2c2cx4va1MqYWQyYVExX1ftX17t`2HuXWAvW1ktXx8ia2UtcFUxKmAnb@<<"
"countver"="pocketsearch"
"keywork"=""
"pmid"="PU8PW/IBW2MnXWIkWyT<"
"cmid"=""
"serverurl"="`GQ/bCnuK2c2cx4y`FExYVIudB4qbh7<"
"timecheck"="1251771854"
"Noresult"=dword:00000000
"Newwindow"=dword:00000000
"AleadyOpen"=dword:00000000
"CMChange"=dword:00000000
"Subwindow"=dword:00000000
"potalmain"=dword:00000000
"BandOpenRequest"=dword:00000000
"LastKeyword"=""

[HKEY_LOCAL_MACHINE\software\Vaccine-Plus]
"code1"="funfun"
"installmode"="1"
"Reboot"="1"
"vccplusNic"="00:FF:C7:87:0A:3D"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QuickDownload Agent]
"Type"=dword:00000010
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"="C:\\Program Files\\QuickDownloadService\\qdownagent.exe"
"SbieProcessId"=dword:000007c0
"SbieCurrentState"=dword:00000004
"SbieControlsAccepted"=dword:00000005
"SbieWin32ExitCode"=dword:00000000
"SbieServiceSpecificExitCode"=dword:00000000
"SbieCheckPoint"=dword:00000000
"SbieWaitHint"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QuickDownload Service]
"Type"=dword:00000010
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"="C:\\Program Files\\QuickDownloadService\\qdownservice.exe"
"SbieProcessId"=dword:00000224
"SbieCurrentState"=dword:00000004
"SbieControlsAccepted"=dword:00000005
"SbieWin32ExitCode"=dword:00000000
"SbieServiceSpecificExitCode"=dword:00000000
"SbieCheckPoint"=dword:00000000
"SbieWaitHint"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QuickDownload Update]
"Type"=dword:00000010
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"="C:\\Program Files\\QuickDownloadService\\qdownupdate.exe"
"SbieProcessId"=dword:00000234
"SbieCurrentState"=dword:00000004
"SbieControlsAccepted"=dword:00000005
"SbieWin32ExitCode"=dword:00000000
"SbieServiceSpecificExitCode"=dword:00000000
"SbieCheckPoint"=dword:00000000
"SbieWaitHint"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\QuickDownloadService\\qdownservice.exe"="C:\\Program Files\\QuickDownloadService\\qdownservice.exe:*:Enabled:QuickDownloadSvc"

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{0D6D4F41-2994-4BA0-8FEF-620E43CD2812}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{0D6D4F41-2994-4BA0-8FEF-620E43CD2812}\Count]
"HRZR_PGYFRFFVBA"=hex:c4,54,51,0e,13,00,00,00

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{000F369E-A063-40A3-B9CF-F49C3EF14C85}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{000F369E-A063-40A3-B9CF-F49C3EF14C85}\iexplore]
"Type"=dword:00000003
"Flags"=dword:00000000
"Count"=dword:00000001
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,1b,00,bd,03

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore]
"Type"=dword:00000002
"Count"=dword:00000389
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,19,00,c9,01

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{234CFBE7-DD40-4694-B3BF-0C6479AED177}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{234CFBE7-DD40-4694-B3BF-0C6479AED177}\iexplore]
"Type"=dword:00000003
"Count"=dword:00000514
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,1c,00,a3,02

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92780B25-18CC-41C8-B9BE-3C9C571A8263}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\iexplore]
"Type"=dword:00000004
"Count"=dword:000006a6
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,1c,00,9d,03

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}\iexplore]
"Type"=dword:00000003
"Count"=dword:00000384
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,1c,00,c3,02

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\iexplore]
"Type"=dword:00000003
"Count"=dword:00000384
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,1c,00,d2,02

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}\iexplore]
"Type"=dword:00000003
"Count"=dword:0000035c
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,1c,00,d2,02

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF819DA3-9882-4944-ADF5-6EF17ECF3C6E}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF819DA3-9882-4944-ADF5-6EF17ECF3C6E}\iexplore]
"Type"=dword:00000004
"Count"=dword:000005c9
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,1c,00,9d,03

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore]
"Type"=dword:00000001
"Count"=dword:0000112d
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,1e,00,a9,01

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore]
"Type"=dword:00000003
"Count"=dword:0000037d
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,1c,00,e2,02

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2E2DD38-D088-4134-82B7-F2BA38496583}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2E2DD38-D088-4134-82B7-F2BA38496583}\iexplore]
"Type"=dword:00000004
"Count"=dword:00000698
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,1c,00,9d,03

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\iexplore]
"Type"=dword:00000003
"Count"=dword:0000037d
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,1c,00,e2,02

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB5F1910-F110-11D2-BB9E-00C04F795683}]

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB5F1910-F110-11D2-BB9E-00C04F795683}\iexplore]
"Type"=dword:00000004
"Count"=dword:000006a9
"Time"=hex:d9,07,09,00,02,00,01,00,02,00,18,00,1c,00,9d,03

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy"=dword:00000001
"ProxyEnable"=dword:00000000

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run]
"ShareBox"="C:\\Program Files\\SBoxPoint\\SBoxPointC.exe"
"SBoxSearchBar"="C:\\Program Files\\SBoxSearchBar\\SBoxSearchBarC.exe"
"SBoxPoint"="C:\\Program Files\\SBoxPoint\\SBoxPointC.exe"

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\쉐어박스]
"DisplayName"="쉐어박스"
"InstallLocation"="C:\\Program Files\\ShareBox"
"UninstallString"="C:\\Program Files\\ShareBox\\Uninstall.exe"
"DisplayIcon"="C:\\Program Files\\ShareBox\\ShareBoxC.exe"
"DisplayVersion"="2.0.0.9"
"URLInfoAbout"="http://sharebox.co.kr"
"Publisher"="MONE"

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\쉐어박스 서치바]
"DisplayName"="쉐어박스 서치바"
"InstallLocation"="C:\\Program Files\\SBoxSearchBar"
"UninstallString"="C:\\Program Files\\SBoxSearchBar\\Uninstall.exe"
"DisplayIcon"="C:\\Program Files\\SBoxSearchBar\\SBoxSearchBarC.exe"
"DisplayVersion"="1.0.0.1"
"URLInfoAbout"="http://sharebox.co.kr"
"Publisher"="MONE"

[HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\쉐어박스 포인트]
"DisplayName"="쉐어박스 포인트"
"InstallLocation"="C:\\Program Files\\SBoxPoint"
"UninstallString"="C:\\Program Files\\SBoxPoint\\Uninstall.exe"
"DisplayIcon"="C:\\Program Files\\SBoxPoint\\SBoxPointC.exe"
"DisplayVersion"="1.0.0.1"
"URLInfoAbout"="http://sharebox.co.kr"
"Publisher"="MONE"

[HKEY_CURRENT_USER\software\Microsoft\Windows\ShellNoRoam]

[HKEY_CURRENT_USER\software\Microsoft\Windows\ShellNoRoam\MUICache]
"D:\\samples\\samples\\Today\\sharebox_setup.exe"="쉐어박스"
"C:\\DOCUME~1\\cosrah\\LOCALS~1\\Temp\\2487187.exe"="쉐어박스 서치바"
"C:\\DOCUME~1\\cosrah\\LOCALS~1\\Temp\\2490937.exe"="쉐어박스 포인트"
"C:\\DOCUME~1\\cosrah\\LOCALS~1\\Temp\\2492250.exe"="쉐어박스 서치바"
"C:\\Program Files\\SBoxSearchBar\\SBoxSearchBar.exe"="SBoxSearchBar"
"C:\\DOCUME~1\\cosrah\\LOCALS~1\\Temp\\2495734.exe"="쉐어박스 포인트"
"C:\\Program Files\\SBoxPoint\\SBoxPoint.exe"="SBoxPoint"

[HKEY_CURRENT_USER\software\SBoxPoint]
"INST_DATE"="1251771872"

[HKEY_CURRENT_USER\software\SBoxSearchBar]
"INST_DATE"="1251771868"

저작자 표시 비영리 변경 금지
Posted by CoInz

최근에 달린 댓글

최근에 받은 트랙백

글 보관함

티스토리 툴바