OTI log part 2
========== Chrome ==========
CHR - homepage:
http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\maaldridge\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\maaldridge\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\maaldridge\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\maaldridge\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\maaldridge\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
O1 HOSTS File: ([2012/07/26 15:46:12 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli64.dll (Cisco WebEx LLC)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli.dll (Cisco WebEx LLC)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:
64bit: - HKLM\..\Toolbar: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli64.dll (Cisco WebEx LLC)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli.dll (Cisco WebEx LLC)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:
64bit: - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4:
64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:
64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [MsmqIntCert] C:\Windows\SysNative\mqrt.dll (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [NVHotkey] C:\Windows\SysNative\nvHotkey.dll (NVIDIA Corporation)
O4:
64bit: - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:
64bit: - HKLM..\Run: [TdmNotify] C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [Communicator] C:\Program Files (x86)\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-73361282-1014109674-949316387-64872..\Run: [Spybot-S&D Cleaning] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-898976328-1975694646-3752162016-1004..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-898976328-1975694646-3752162016-1004..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\maaldridge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun_KL_notset = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-898976328-1975694646-3752162016-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8:
64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\ie_banner_deny.htm ()
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\ie_banner_deny.htm ()
O9:
64bit: - Extra Button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\x64\scieplgn.dll (Kaspersky Lab)
O9 - Extra Button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\scieplgn.dll (Kaspersky Lab)
O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Reg Error: Key error. File not found
O15:
64bit: - ..Trusted Domains: a4healthsystems.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: adp.com ([]https in Trusted sites)
O15:
64bit: - ..Trusted Domains: allscripts.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: allscripts.com ([]https in Trusted sites)
O15:
64bit: - ..Trusted Domains: allscripts.com ([clarity.corp] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: allscripts.com ([servicedesk.corp] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: books24x7.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: brainshark.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: clarity ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: codecorrect.com ([]https in Trusted sites)
O15:
64bit: - ..Trusted Domains: delvenetworks.com ([assets] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: diagnostix.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: eclipsnet.com ([]* in Local intranet)
O15:
64bit: - ..Trusted Domains: employee ([]http in Local intranet)
O15:
64bit: - ..Trusted Domains: eternal ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: force.com ([]https in Trusted sites)
O15:
64bit: - ..Trusted Domains: force.com ([*.na0.visual] https in Trusted sites)
O15:
64bit: - ..Trusted Domains: fpx.com ([od1] https in Trusted sites)
O15:
64bit: - ..Trusted Domains: global.ad ([*.misys] http in Local intranet)
O15:
64bit: - ..Trusted Domains: global.ad ([servicedesk.misys] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: globalsaleskickoff.com ([]http in Local intranet)
O15:
64bit: - ..Trusted Domains: gotrain.net ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: insideallscripts.com ([]http in Local intranet)
O15:
64bit: - ..Trusted Domains: insidemisys.com ([]http in Local intranet)
O15:
64bit: - ..Trusted Domains: intersourcing.com ([www] https in Trusted sites)
O15:
64bit: - ..Trusted Domains: intra ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: llnwd.net ([*.fcod] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: microsoft.com ([*.windowsupdate] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: misys.com ([clarity] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: misys.com ([servicedesk] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: misysgold ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: misyshealthcare.com ([]http in Local intranet)
O15:
64bit: - ..Trusted Domains: misyshealthcare.com ([]https in Trusted sites)
O15:
64bit: - ..Trusted Domains: misyshealthcare.com ([kb] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: misysimentor.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: mlv-ris-app-e ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: mlv-ris-app-f ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: mlv-ris-app-o ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: on24.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: onemisys.com ([]http in Local intranet)
O15:
64bit: - ..Trusted Domains: onemisys.com ([clarity] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: onemisys.com ([eternal] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: onemisys.com ([intra] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: onemisys.com ([misysgold] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: payerpath.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: payerpath.com ([]https in Trusted sites)
O15:
64bit: - ..Trusted Domains: salesforce.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: salesforce.com ([]https in Trusted sites)
O15:
64bit: - ..Trusted Domains: servicedesk ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: skilldialogue.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: skillport.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: skillport.com ([library] http in Trusted sites)
O15:
64bit: - ..Trusted Domains: skillsoft.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: skillsoftcompliance.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: skillwsa.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: symantecliveupdate.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: symantecliveupdate.com ([]https in Trusted sites)
O15:
64bit: - ..Trusted Domains: velaro.com ([]http in Trusted sites)
O15:
64bit: - ..Trusted Domains: windowsupdate.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: a4healthsystems.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: adp.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: allscripts.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: allscripts.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: allscripts.com ([clarity.corp] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: allscripts.com ([servicedesk.corp] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: books24x7.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: brainshark.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: clarity ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: codecorrect.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: delvenetworks.com ([assets] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: diagnostix.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: eclipsnet.com ([]* in Local intranet)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: employee ([]http in Local intranet)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: eternal ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: force.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: force.com ([*.na0.visual] https in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: fpx.com ([od1] https in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: global.ad ([*.misys] http in Local intranet)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: global.ad ([servicedesk.misys] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: globalsaleskickoff.com ([]http in Local intranet)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: gotrain.net ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: insideallscripts.com ([]http in Local intranet)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: insidemisys.com ([]http in Local intranet)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: intersourcing.com ([www] https in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: intra ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: llnwd.net ([*.fcod] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: microsoft.com ([*.windowsupdate] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: misys.com ([clarity] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: misys.com ([servicedesk] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: misysgold ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: misyshealthcare.com ([]http in Local intranet)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: misyshealthcare.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: misyshealthcare.com ([kb] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: misysimentor.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: mlv-ris-app-e ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: mlv-ris-app-f ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: mlv-ris-app-o ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: on24.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: onemisys.com ([]http in Local intranet)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: onemisys.com ([clarity] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: onemisys.com ([eternal] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: onemisys.com ([intra] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: onemisys.com ([misysgold] http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: payerpath.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: payerpath.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: salesforce.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: salesforce.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: servicedesk ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: skilldialogue.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: skillport.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: skillsoft.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: skillsoftcompliance.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: skillwsa.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: symantecliveupdate.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: symantecliveupdate.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: velaro.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-73361282-1014109674-949316387-64872\..Trusted Domains: windowsupdate.com ([]http in Trusted sites)
O16:
64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16:
64bit: - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16:
64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809}
http://www.walmartphotocentre.ca/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F}
https://ssl3.eclipsnet.com/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.141.1.33 10.141.1.34 10.131.1.77 10.101.224.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = corp.allscripts.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{06C4AC5A-53E8-43CC-9777-16FF9D813CAA}: DhcpNameServer = 10.131.1.15 10.131.1.59 10.101.224.52 10.101.224.181
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{829CCC39-CBEB-4C8C-97CA-011ADB61935A}: DhcpNameServer = 10.141.1.33 10.141.1.34 10.131.1.77 10.101.224.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D82732A-BEEA-4171-A7E8-6EB94ACFFE15}: DhcpNameServer = 10.141.1.33 10.141.1.34 10.131.1.77 10.101.224.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EFB12861-64CB-4296-9F76-0B8D6D8B641C}: DhcpNameServer = 10.141.1.33 10.141.1.34 10.131.1.77 10.101.224.100
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:
64bit: - Winlogon\Notify\spba: DllName - (C:\Program Files\Common Files\SPBA\homefus2.dll) - C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/07/26 17:04:11 | 000,597,504 | ---- | C] (OldTimer Tools) -- C:\Users\maaldridge\Desktop\OTL.exe
[2012/07/26 15:46:13 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/07/26 14:26:51 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/07/26 14:26:51 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/07/26 14:26:51 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/07/26 14:25:11 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/07/26 14:25:01 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/07/26 14:01:53 | 004,719,912 | R--- | C] (Swearware) -- C:\Users\maaldridge\Desktop\ComboFix.exe
[2012/07/26 11:07:19 | 000,000,000 | ---D | C] -- C:\FRST
[2012/07/25 14:18:39 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\maaldridge\Desktop\aswMBR.exe
[2012/07/25 14:15:44 | 000,000,000 | ---D | C] -- C:\Users\maaldridge\Desktop\RK_Quarantine
[2012/07/25 12:29:03 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2012/07/25 12:09:23 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\maaldridge\Desktop\dds.scr
[2012/07/25 10:35:41 | 000,000,000 | ---D | C] -- C:\Users\maaldridge\AppData\Roaming\Malwarebytes
[2012/07/25 10:35:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/25 10:35:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/07/25 10:35:35 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/07/25 10:35:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/07/25 10:35:15 | 010,652,120 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\maaldridge\Desktop\mbam-setup-1.62.0.1300.exe
[2012/07/25 07:22:42 | 000,479,744 | ---- | C] (Allscripts Healthcare Solutions, Inc.) -- C:\Windows\SysWow64\RTFConv.dll
[2012/07/24 23:20:49 | 000,000,000 | ---D | C] -- C:\Users\maaldridge\Documents\ProcAlyzer Dumps
[2012/07/24 22:05:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012/07/24 22:05:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2012/07/24 22:05:23 | 000,017,272 | ---- | C] (Safer Networking Limited) -- C:\Windows\SysNative\sdnclean64.exe
[2012/07/24 22:05:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2012/07/24 14:32:32 | 000,000,000 | ---D | C] -- C:\Users\maaldridge\AppData\Local\visi_coupon
[2012/07/24 14:30:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo!
[2012/07/24 14:30:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yahoo!
[2012/07/24 13:54:06 | 000,000,000 | ---D | C] -- C:\Users\maaldridge\AppData\Local\Microsoft_Corporation
[2012/07/23 09:59:00 | 000,000,000 | ---D | C] -- C:\Users\maaldridge\AppData\Roaming\Apple Computer
[2012/07/22 15:41:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012/07/22 15:40:38 | 000,000,000 | ---D | C] -- C:\Users\maaldridge\AppData\Local\Apple
[2012/07/22 15:40:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2012/07/12 21:33:52 | 000,114,176 | ---- | C] (Allscripts Healthcare Solutions, Inc.) -- C:\Windows\SysWow64\Eclipsys.Platform.LdapReader.dll
[2012/07/12 15:16:32 | 000,000,000 | -H-D | C] -- C:\Windows\AxInstSV
[2011/12/21 14:50:31 | 000,110,080 | ---- | C] (Infragistics, Inc.) -- C:\Users\maaldridge\AppData\Local\sslcra32.exe
========== Files - Modified Within 30 Days ==========
File not found -- C:\Windows\SysNative\
[2012/07/26 17:04:13 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\maaldridge\Desktop\OTL.exe
[2012/07/26 16:43:19 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-73361282-1014109674-949316387-64872UA.job
[2012/07/26 16:01:06 | 000,871,340 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/26 16:01:06 | 000,727,052 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/26 16:01:06 | 000,144,060 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/26 16:00:01 | 000,012,608 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/26 16:00:01 | 000,012,608 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/26 15:53:19 | 000,000,462 | ---- | M] () -- C:\Windows\SMSCFG.ini
[2012/07/26 15:52:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/26 15:52:14 | 3127,558,144 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/26 15:46:12 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/07/26 14:56:45 | 000,004,142 | ---- | M] () -- C:\Windows\mozyent.blk
[2012/07/26 14:56:45 | 000,003,748 | ---- | M] () -- C:\Windows\mozyent.flt
[2012/07/26 14:21:14 | 004,719,912 | R--- | M] (Swearware) -- C:\Users\maaldridge\Desktop\ComboFix.exe
[2012/07/25 14:29:30 | 000,000,512 | ---- | M] () -- C:\Users\maaldridge\Desktop\MBR.dat
[2012/07/25 14:18:39 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\maaldridge\Desktop\aswMBR.exe
[2012/07/25 14:15:29 | 001,552,384 | ---- | M] () -- C:\Users\maaldridge\Desktop\RogueKiller.exe
[2012/07/25 12:09:26 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\maaldridge\Desktop\dds.scr
[2012/07/25 12:06:23 | 000,000,000 | ---- | M] () -- C:\Users\maaldridge\Desktop\t6de78yz.reg
[2012/07/25 12:06:14 | 000,000,000 | ---- | M] () -- C:\Users\maaldridge\Desktop\t6de78yz.bat
[2012/07/25 11:27:28 | 000,302,592 | ---- | M] () -- C:\Users\maaldridge\Desktop\t6de78yz.exe
[2012/07/25 10:35:36 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/25 10:35:19 | 010,652,120 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\maaldridge\Desktop\mbam-setup-1.62.0.1300.exe
[2012/07/25 10:19:37 | 000,007,597 | ---- | M] () -- C:\Users\maaldridge\AppData\Local\Resmon.ResmonCfg
[2012/07/25 09:43:02 | 000,000,876 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-73361282-1014109674-949316387-64872Core.job
[2012/07/25 07:22:42 | 000,479,744 | ---- | M] (Allscripts Healthcare Solutions, Inc.) -- C:\Windows\SysWow64\RTFConv.dll
[2012/07/24 22:25:03 | 000,000,121 | ---- | M] () -- C:\Windows\wininit.ini
[2012/07/24 22:05:49 | 000,002,179 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2012/07/24 20:36:28 | 040,095,152 | -H-- | M] () -- C:\Users\maaldridge\Documents\sdo_gb.pdf.2d92.part
[2012/07/24 14:35:32 | 000,040,165 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2012/07/23 09:50:32 | 000,153,053 | ---- | M] () -- C:\Windows\SysNative\drivers\klin.dat
[2012/07/23 09:50:32 | 000,107,384 | ---- | M] () -- C:\Windows\SysNative\drivers\klick.dat
[2012/07/20 14:37:51 | 000,011,278 | RHS- | M] () -- C:\Users\maaldridge\ntuser.pol
[2012/07/20 14:36:57 | 000,423,888 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/13 16:25:00 | 000,002,006 | -H-- | M] () -- C:\Users\maaldridge\Documents\Default.rdp
[2012/07/13 15:13:49 | 000,002,390 | ---- | M] () -- C:\Users\maaldridge\Desktop\Google Chrome.lnk
[2012/07/12 21:33:52 | 000,114,176 | ---- | M] (Allscripts Healthcare Solutions, Inc.) -- C:\Windows\SysWow64\Eclipsys.Platform.LdapReader.dll
[2012/07/11 11:53:03 | 000,000,000 | ---- | M] () -- C:\Windows\BulkUnld.INI
[2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/07/03 09:27:23 | 000,865,556 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
========== Files Created - No Company Name ==========
File not found -- C:\Windows\SysNative\
[2012/07/26 14:26:51 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/07/26 14:26:51 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/07/26 14:26:51 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/07/26 14:26:51 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/07/26 14:26:51 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/07/25 14:29:30 | 000,000,512 | ---- | C] () -- C:\Users\maaldridge\Desktop\MBR.dat
[2012/07/25 14:15:29 | 001,552,384 | ---- | C] () -- C:\Users\maaldridge\Desktop\RogueKiller.exe
[2012/07/25 12:06:18 | 000,000,000 | ---- | C] () -- C:\Users\maaldridge\Desktop\t6de78yz.reg
[2012/07/25 12:06:14 | 000,000,000 | ---- | C] () -- C:\Users\maaldridge\Desktop\t6de78yz.bat
[2012/07/25 11:27:27 | 000,302,592 | ---- | C] () -- C:\Users\maaldridge\Desktop\t6de78yz.exe
[2012/07/25 10:35:36 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/25 10:19:37 | 000,007,597 | ---- | C] () -- C:\Users\maaldridge\AppData\Local\Resmon.ResmonCfg
[2012/07/24 22:25:03 | 000,000,121 | ---- | C] () -- C:\Windows\wininit.ini
[2012/07/24 22:05:49 | 000,002,191 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2012/07/24 22:05:49 | 000,002,179 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2012/07/24 20:34:12 | 040,095,152 | -H-- | C] () -- C:\Users\maaldridge\Documents\sdo_gb.pdf.2d92.part
[2012/07/11 11:53:03 | 000,000,000 | ---- | C] () -- C:\Windows\BulkUnld.INI
[2011/11/03 21:17:45 | 000,000,000 | ---- | C] () -- C:\Windows\hvct.INI
[2011/10/19 09:32:24 | 000,011,278 | RHS- | C] () -- C:\Users\maaldridge\ntuser.pol
[2011/10/18 14:16:31 | 000,040,165 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/09/19 07:32:57 | 000,960,940 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011/09/19 07:32:55 | 000,207,376 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011/09/19 07:32:52 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011/04/14 08:16:48 | 000,000,411 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/04/12 09:18:42 | 000,080,368 | ---- | C] () -- C:\Windows\SysWow64\pbadrvdll.dll
[2011/04/12 09:17:16 | 000,865,556 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/12 09:17:16 | 000,004,764 | ---- | C] () -- C:\Windows\SysWow64\CcmFramework.ini
[2011/04/12 09:17:03 | 000,000,462 | ---- | C] () -- C:\Windows\SMSCFG.ini
[2010/11/20 14:01:03 | 000,000,051 | ---- | C] () -- C:\Windows\smsts.ini
[2010/08/19 17:18:20 | 001,008,640 | ---- | C] () -- C:\Windows\SysWow64\DemoLicense.dll
========== LOP Check ==========
[2011/09/19 08:28:35 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Wave Systems Corp
[2011/09/19 13:10:51 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\WirelessManager
[2012/07/01 22:23:38 | 000,000,000 | ---D | M] -- C:\Users\maaldridge\AppData\Roaming\BSW
[2011/10/25 12:35:33 | 000,000,000 | ---D | M] -- C:\Users\maaldridge\AppData\Roaming\Juniper Networks
[2012/01/17 12:54:31 | 000,000,000 | ---D | M] -- C:\Users\maaldridge\AppData\Roaming\webex
[2011/10/27 11:00:44 | 000,000,000 | ---D | M] -- C:\Users\maaldridge\AppData\Roaming\Western Digital
[2012/01/03 14:49:36 | 000,000,000 | ---D | M] -- C:\Users\maaldridge\AppData\Roaming\Xerox
[2009/07/13 22:08:49 | 000,027,426 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >