Logfile of random's system information tool 1.09 (written by random/random)
Run by DangerAge at 2011-09-07 17:16:54
Microsoft® Windows Vista™ Ultimate
System drive C: has 21 GB (29%) free of 71 GB
Total RAM: 8190 MB (80% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:10:23, on 7.9.2011
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\AASP\1.00.40\aaCenter.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Windows\SysWOW64\conime.exe
C:\Users\DANGER~1\AppData\Local\Temp\winhifem.exe
C:\Users\DANGER~1\AppData\Local\Temp\winpqiur.exe
C:\PROGRA~2\MOZILL~1\firefox.exe
C:\PROGRA~2\MOZILL~1\plugin-container.exe
C:\PROGRA~1\TRENDM~1\DANGER~1.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundTray] "C:\Program Files (x86)\Analog Devices\SoundMAX\SoundTray.exe"
O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files (x86)\ASUS\AI Suite\AiNap\AiNap.exe"
O4 - HKLM\..\Run: [CPU Power Monitor] "C:\Program Files (x86)\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe"
O4 - HKLM\..\Run: [Cpu Level Up help] "C:\Program Files (x86)\ASUS\AI Suite\CpuLevelUpHelp.exe"
O4 - HKLM\..\Run: [Launch Direct Link] "C:\Program Files (x86)\ASUS\AI Direct Link\AsShare.exe"
O4 - HKLM\..\Run: [Launch As Cmd Runner] "C:\Program Files (x86)\ASUS\AI Direct Link\AsCmd.exe" -reg
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Unknown owner - C:\Windows\system32\AEADISRV.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Performance Driver Service - Unknown owner - C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\SysWOW64\PSIService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6124 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
winlogon.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\system32\Dwm.exe"
taskeng.exe {6A76331D-9187-4EF4-8D34-2BF78166CB70}
"C:\Program Files (x86)\ASUS\AASP\1.00.40\aaCenter.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\conime.exe
C:\PROGRA~2\Intel\INTELM~1\IAAnotif.exe
C:\PROGRA~2\Corel\CORELS~1\CORELP~1.EXE
C:\PROGRA~1\WICC9F~1\sidebar.exe /autoRun
C:\PROGRA~2\LOGMEI~1\HAMACH~2.EXE --auto-start
C:\Windows\system32\AEADISRV.EXE
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe"
"C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\SysWOW64\PSIService.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-459f64a5-3881-4b46-8f69-668f07b7c4a1 -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-29648760-21d2-4233-ba5b-b603787780ad -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-1d903361-2b08-4b98-a75d-820fc683d56c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:cad7d23d-a158-4e95-a76b-eb7c8d637d47
taskeng.exe {F5D6869D-C434-4134-BA24-4351B2E5A58F}
C:\Windows\System32\mobsync.exe -Embedding
"C:\Program Files\Windows Media Player\wmpnscfg.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\PROGRA~2\MOZILL~1\firefox.exe
"C:\PROGRA~2\MOZILL~1\plugin-container.exe" --channel=3560.9213020.157043362 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" - -greomni "C:\PROGRA~2\MOZILL~1\omni.jar" 3560 "\\.\pipe\gecko-crash-server-pipe.3560" plugin
C:\Users\DANGER~1\AppData\Local\Temp\rqhfja.exe
C:\Users\DANGER~1\AppData\Local\Temp\winmygu.exe
C:\Users\DANGER~1\DOWNLO~1\RSITX6~1.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\PROGRA~1\TRENDM~1\DANGER~1.EXE /silentautolog
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"=C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2011-09-06 174872]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2009-12-16 1712232]
"Corel Photo Downloader"=C:\PROGRA~2\Corel\CORELS~1\CORELP~1.EXE [2011-09-06 478800]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2011-09-04 1554432]
"WindowsWelcomeCenter"=oobefldr.dll,ShowWelcomeCenter []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [2011-09-07 1753600]
"SoundTray"=C:\Program Files (x86)\Analog Devices\SoundMAX\SoundTray.exe [2011-09-07 578560]
"Ai Nap"=C:\Program Files (x86)\ASUS\AI Suite\AiNap\AiNap.exe [2011-09-07 2329600]
"CPU Power Monitor"=C:\Program Files (x86)\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe [2011-09-07 1413120]
"Cpu Level Up help"=C:\Program Files (x86)\ASUS\AI Suite\CpuLevelUpHelp.exe [2011-09-07 1402880]
"Launch Direct Link"=C:\Program Files (x86)\ASUS\AI Direct Link\AsShare.exe [2011-09-06 1441280]
"Launch As Cmd Runner"=C:\Program Files (x86)\ASUS\AI Direct Link\AsCmd.exe [2011-09-07 717312]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-08-15 1955208]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
"DisableRegistryTools"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\PROGRA~2\ANALOG~1\SoundMAX\SOUNDT~1.EXE"="C:\PROGRA~2\ANALOG~1\SoundMAX\SOUNDT~1.EXE:*:Enabled:ipsec"
"C:\Program Files (x86)\ASUS\AI Suite\CpuLevelUpHookLaunch.exe"="C:\Program Files (x86)\ASUS\AI Suite\CpuLevelUpHookLaunch.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\xxbqhm.exe"="C:\Users\DANGER~1\AppData\Local\Temp\xxbqhm.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winfwxvja.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winfwxvja.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\tumb.exe"="C:\Users\DANGER~1\AppData\Local\Temp\tumb.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winksein.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winksein.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\3582-490\PEV.exe"="C:\Users\DANGER~1\AppData\Local\Temp\3582-490\PEV.exe:*:Enabled:ipsec"
"C:\Program Files (x86)\ASUS\AI Direct Link\AsCmd.exe"="C:\Program Files (x86)\ASUS\AI Direct Link\AsCmd.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winmuwh.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winmuwh.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\uvggi.exe"="C:\Users\DANGER~1\AppData\Local\Temp\uvggi.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\oimmxe.exe"="C:\Users\DANGER~1\AppData\Local\Temp\oimmxe.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winlrgk.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winlrgk.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\windvpwtl.exe"="C:\Users\DANGER~1\AppData\Local\Temp\windvpwtl.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\eacks.exe"="C:\Users\DANGER~1\AppData\Local\Temp\eacks.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winxqdeja.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winxqdeja.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\windtud.exe"="C:\Users\DANGER~1\AppData\Local\Temp\windtud.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winhumutb.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winhumutb.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winvgox.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winvgox.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\gppms.exe"="C:\Users\DANGER~1\AppData\Local\Temp\gppms.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\phrhne.exe"="C:\Users\DANGER~1\AppData\Local\Temp\phrhne.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winmsnge.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winmsnge.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winlumrh.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winlumrh.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\xdrla.exe"="C:\Users\DANGER~1\AppData\Local\Temp\xdrla.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winklap.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winklap.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\jxsijl.exe"="C:\Users\DANGER~1\AppData\Local\Temp\jxsijl.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winplxxx.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winplxxx.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winccyo.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winccyo.exe:*:Enabled:ipsec"
"C:\beruska.com\PEV.exe"="C:\beruska.com\PEV.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winkxuwd.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winkxuwd.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winonnmd.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winonnmd.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\qbdtai.exe"="C:\Users\DANGER~1\AppData\Local\Temp\qbdtai.exe:*:Enabled:ipsec"
"C:\Program Files (x86)\ASUS\AASP\1.00.40\aaCenter.exe"="C:\Program Files (x86)\ASUS\AASP\1.00.40\aaCenter.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winslkh.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winslkh.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winellp.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winellp.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\gxykew.exe"="C:\Users\DANGER~1\AppData\Local\Temp\gxykew.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winwypfsi.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winwypfsi.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winpuqk.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winpuqk.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\qutm.exe"="C:\Users\DANGER~1\AppData\Local\Temp\qutm.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\wintdbosu.exe"="C:\Users\DANGER~1\AppData\Local\Temp\wintdbosu.exe:*:Enabled:ipsec"
"C:\Users\DangerAge\Desktop\OTM.exe"="C:\Users\DangerAge\Desktop\OTM.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winhmhmox.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winhmhmox.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winesecjx.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winesecjx.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winmtse.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winmtse.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winfxublf.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winfxublf.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\cinlja.exe"="C:\Users\DANGER~1\AppData\Local\Temp\cinlja.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\wjeiko.exe"="C:\Users\DANGER~1\AppData\Local\Temp\wjeiko.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winudoygc.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winudoygc.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\jeai.exe"="C:\Users\DANGER~1\AppData\Local\Temp\jeai.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winwamckg.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winwamckg.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winqrdx.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winqrdx.exe:*:Enabled:ipsec"
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe"="C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe:*:Enabled:ipsec"
"C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe"="C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe:*:Enabled:ipsec"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"="C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\wincglicb.exe"="C:\Users\DANGER~1\AppData\Local\Temp\wincglicb.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\uydplq.exe"="C:\Users\DANGER~1\AppData\Local\Temp\uydplq.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winkoof.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winkoof.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winpkdoiv.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winpkdoiv.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winmpqce.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winmpqce.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\wintmvop.exe"="C:\Users\DANGER~1\AppData\Local\Temp\wintmvop.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winmpbru.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winmpbru.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\wqxquc.exe"="C:\Users\DANGER~1\AppData\Local\Temp\wqxquc.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\ltfvqr.exe"="C:\Users\DANGER~1\AppData\Local\Temp\ltfvqr.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\bwuyft.exe"="C:\Users\DANGER~1\AppData\Local\Temp\bwuyft.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\segdh.exe"="C:\Users\DANGER~1\AppData\Local\Temp\segdh.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\utkh.exe"="C:\Users\DANGER~1\AppData\Local\Temp\utkh.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\kmuys.exe"="C:\Users\DANGER~1\AppData\Local\Temp\kmuys.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winuruso.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winuruso.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winndhiuc.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winndhiuc.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\uder.exe"="C:\Users\DANGER~1\AppData\Local\Temp\uder.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winjcrnnl.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winjcrnnl.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winqgfwio.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winqgfwio.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winixqgg.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winixqgg.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winymrya.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winymrya.exe:*:Enabled:ipsec"
"C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe"="C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe:*:Enabled:ipsec"
"C:\Program Files (x86)\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe"="C:\Program Files (x86)\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winhifem.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winhifem.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\windihe.exe"="C:\Users\DANGER~1\AppData\Local\Temp\windihe.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\hisok.exe"="C:\Users\DANGER~1\AppData\Local\Temp\hisok.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winpqiur.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winpqiur.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winkqrqqq.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winkqrqqq.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winavut.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winavut.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winepvxkf.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winepvxkf.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winexvvg.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winexvvg.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winegetye.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winegetye.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\juvgh.exe"="C:\Users\DANGER~1\AppData\Local\Temp\juvgh.exe:*:Enabled:ipsec"
"C:\Program Files (x86)\ASUS\AASP\1.00.40\AsLoader.exe"="C:\Program Files (x86)\ASUS\AASP\1.00.40\AsLoader.exe:*:Enabled:ipsec"
"C:\PROGRA~2\MOZILL~1\uninstall\helper.exe"="C:\PROGRA~2\MOZILL~1\uninstall\helper.exe:*:Enabled:ipsec"
"C:\PROGRA~2\Corel\CORELS~1\CORELP~1.EXE"="C:\PROGRA~2\Corel\CORELS~1\CORELP~1.EXE:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\rqhfja.exe"="C:\Users\DANGER~1\AppData\Local\Temp\rqhfja.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\elth.exe"="C:\Users\DANGER~1\AppData\Local\Temp\elth.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\qpyjb.exe"="C:\Users\DANGER~1\AppData\Local\Temp\qpyjb.exe:*:Enabled:ipsec"
"C:\Users\DANGER~1\AppData\Local\Temp\winmygu.exe"="C:\Users\DANGER~1\AppData\Local\Temp\winmygu.exe:*:Enabled:ipsec"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]