OK here it is... Thanks for your help, btw.
ComboFix 08-12-21.04 - Calvin 2008-12-23 8:36:48.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3325.2256 [GMT -8:00]
Running from: c:\users\Calvin\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\windows\system32\drivers\msqpdxcfotvqpp.sys
c:\windows\system32\msqpdxuvfntpsc.dll
D:\resycled
d:\resycled\boot.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_MSQPDXSERV.SYS
-------\Service_RelevantKnowledge
((((((((((((((((((((((((( Files Created from 2008-11-23 to 2008-12-23 )))))))))))))))))))))))))))))))
.
2008-12-22 21:14 . 2008-12-22 21:14 <DIR> d-------- c:\users\Calvin\AppData\Roaming\Plogue
2008-12-22 20:52 . 2008-12-22 20:52 <DIR> d-------- c:\users\Calvin\AppData\Roaming\Garritan
2008-12-22 20:52 . 2008-12-22 20:52 <DIR> d-------- c:\program files\Plogue
2008-12-22 20:52 . 2008-12-22 20:52 <DIR> d-------- c:\program files\Garritan
2008-12-22 20:50 . 2008-12-22 22:01 <DIR> d-------- c:\program files\Finale 2009
2008-12-22 16:53 . 2008-12-22 16:53 <DIR> d-------- c:\users\All Users\TomTom
2008-12-22 16:53 . 2008-12-22 16:53 <DIR> d-------- c:\progra~2\TomTom
2008-12-22 09:40 . 2008-12-22 09:40 <DIR> d-------- c:\program files\Bonjour
2008-12-21 10:30 . 2008-12-21 10:30 <DIR> d-------- c:\program files\Trend Micro
2008-12-20 07:13 . 2008-12-20 07:13 <DIR> d-------- c:\program files\Kontakt Player 2
2008-12-20 07:09 . 2008-12-22 21:43 <DIR> d-------- c:\program files\Finale 2008
2008-12-19 10:53 . 2008-12-19 10:53 <DIR> d-------- C:\PSFONTS
2008-12-19 10:53 . 2008-12-22 20:54 <DIR> d-------- c:\program files\Finale SongWriter 2007
2008-12-19 09:30 . 2008-12-19 09:30 <DIR> d-------- c:\users\All Users\Musicnotes
2008-12-19 09:30 . 2008-12-19 09:30 <DIR> d-------- c:\progra~2\Musicnotes
2008-12-17 23:08 . 2008-12-17 23:08 <DIR> d-------- c:\program files\Sun
2008-12-17 21:49 . 2008-12-17 21:49 <DIR> d-------- c:\windows\System32\Profiles
2008-12-17 18:18 . 2008-12-17 18:20 <DIR> d-------- c:\program files\RegCure
2008-12-17 16:45 . 2008-12-12 22:23 1,659,392 --a------ c:\windows\System32\mshtml.tlb
2008-12-14 23:13 . 2008-12-14 23:13 <DIR> d-------- c:\users\Guest\AppData\Roaming\Apple Computer
2008-12-14 12:50 . 2008-12-14 12:50 <DIR> d-------- c:\users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-14 12:50 . 2008-12-14 12:50 <DIR> d-------- c:\program files\iTunes
2008-12-14 12:50 . 2008-12-14 12:50 <DIR> d-------- c:\program files\iPod
2008-12-14 12:50 . 2008-12-14 12:50 <DIR> d-------- c:\progra~2\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-14 12:47 . 2008-12-14 12:50 <DIR> d-------- c:\program files\Common Files\Apple
2008-12-12 21:17 . 2008-12-12 21:17 <DIR> d-------- c:\users\Guest\AppData\Roaming\InstallShield
2008-12-12 13:39 . 2008-12-12 14:54 <DIR> d-------- c:\users\All Users\WINPENJR
2008-12-12 13:39 . 2008-12-12 13:39 <DIR> d-------- c:\program files\WINPENJR
2008-12-12 13:39 . 2008-12-12 14:54 <DIR> d-------- c:\progra~2\WINPENJR
2008-12-12 13:39 . 2003-04-04 20:07 4,795,092 --------- c:\windows\DFSCSK5U.TTE
2008-12-12 13:39 . 2003-04-04 20:05 3,639,720 --------- c:\windows\DFSCSM3U.TTE
2008-12-12 13:39 . 2003-04-04 20:21 2,581,314 --------- c:\windows\DFSCSM3U.EUF
2008-12-12 13:39 . 2003-04-04 20:20 2,581,314 --------- c:\windows\DFSCSK5U.EUF
2008-12-12 13:39 . 2006-09-08 10:16 131,072 --------- c:\windows\System32\PPWORDW.DLL
2008-12-12 13:39 . 2007-01-26 15:01 53,248 --------- c:\windows\System32\PPadApi.dll
2008-12-12 11:18 . 2008-12-12 11:18 87,336 --a------ c:\windows\System32\dns-sd.exe
2008-12-12 11:11 . 2008-12-12 11:11 61,440 --a------ c:\windows\System32\dnssd.dll
2008-12-10 17:25 . 2008-12-10 17:25 <DIR> d-------- c:\users\All Users\Electronic Arts
2008-12-10 17:25 . 2008-12-10 17:25 <DIR> d-------- c:\program files\Electronic Arts
2008-12-10 17:25 . 2008-12-10 17:25 <DIR> d-------- c:\progra~2\Electronic Arts
2008-12-10 17:15 . 2008-12-10 17:15 <DIR> d-------- c:\users\Calvin\AppData\Roaming\Leadertech
2008-12-10 17:15 . 2008-12-10 17:15 1,830 --a------ c:\windows\System32\ealregsnapshot1.reg
2008-12-10 17:09 . 2006-07-28 09:30 236,824 --a------ c:\windows\System32\xactengine2_3.dll
2008-12-10 17:09 . 2006-07-28 09:30 62,744 --a------ c:\windows\System32\xinput1_2.dll
2008-12-10 07:26 . 2008-12-10 07:26 <DIR> d-------- c:\program files\PowerISO
2008-12-09 12:56 . 2008-10-21 17:22 2,048 --a------ c:\windows\System32\tzres.dll
2008-12-09 10:14 . 2008-10-31 17:21 4,240,384 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-09 10:14 . 2008-10-28 22:29 2,927,104 --a------ c:\windows\explorer.exe
2008-12-09 10:14 . 2008-06-22 17:59 2,868,736 --a------ c:\windows\System32\mf.dll
2008-12-09 10:14 . 2008-06-22 17:59 996,352 --a------ c:\windows\System32\WMNetMgr.dll
2008-12-09 10:14 . 2008-10-20 21:25 296,960 --a------ c:\windows\System32\gdi32.dll
2008-12-09 10:14 . 2008-06-22 17:58 94,720 --a------ c:\windows\System32\logagent.exe
2008-12-09 10:14 . 2008-10-31 19:44 28,672 --a------ c:\windows\System32\Apphlpdm.dll
2008-12-08 14:17 . 2008-12-08 14:17 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2008-12-08 12:14 . 2008-12-08 12:14 <DIR> d-------- c:\users\Mom.Calvin-PC\AppData\Roaming\InstallShield
2008-12-07 09:25 . 2008-12-07 17:07 <DIR> d-------- c:\program files\Motorola Phone Tools
2008-12-07 09:25 . 2008-12-07 09:25 <DIR> d-------- c:\program files\Common Files\Motorola Shared
2008-12-07 08:00 . 2008-01-18 23:34 1,788,928 --ah---t- c:\windows\System32\146b59f8.dll
2008-12-07 08:00 . 2008-01-18 23:34 1,788,928 --ah---t- c:\windows\System32\1274a8ca.dll
2008-12-07 08:00 . 2008-01-18 23:37 179,200 --ah---t- c:\windows\System32\2fa598e9.dll
2008-12-07 08:00 . 2008-01-18 23:37 179,200 --ah---t- c:\windows\System32\1b11fa18.dll
2008-12-06 16:08 . 2008-12-06 17:23 <DIR> d-------- c:\users\Guest\AppData\Roaming\MiniDm
2008-12-06 09:03 . 2008-12-06 09:03 <DIR> d--hs---- c:\users\Calvin\E3FEC7F416167B67
2008-12-06 09:03 . 2008-12-06 09:03 <DIR> d--hs---- c:\users\Calvin\DDE87BF4A91B1F47
2008-12-04 19:58 . 2008-12-04 19:58 <DIR> d-------- c:\users\Calvin\AppData\Roaming\TomTom
2008-12-04 19:56 . 2008-12-04 19:56 <DIR> d-------- c:\program files\TomTom HOME 2
2008-12-03 19:33 . 2008-12-09 11:38 <DIR> d-------- c:\users\Guest\AppData\Roaming\FrostWire
2008-12-03 19:33 . 2008-12-03 19:33 <DIR> d-------- c:\users\Guest\AppData\Roaming\DivX
2008-12-02 01:49 . 2008-12-02 01:54 <DIR> d-------- c:\users\Mom.Calvin-PC\AppData\Roaming\MiniDm
2008-11-29 22:54 . 2008-12-06 09:08 <DIR> d-------- c:\users\Calvin\AppData\Roaming\MiniDm
2008-11-29 22:22 . 2008-12-15 12:37 <DIR> d-------- c:\users\Mom.Calvin-PC\AppData\Roaming\FrostWire
2008-11-26 15:13 . 2008-11-26 15:13 69,632 --a------ c:\windows\System32\MSDATLST.oca
2008-11-26 15:13 . 2008-11-26 15:13 65,536 --a------ c:\windows\System32\MSDATGRD.oca
2008-11-26 15:13 . 2008-11-26 15:13 44,032 --a------ c:\windows\System32\MSDATREP.oca
2008-11-26 15:13 . 2008-11-26 15:13 35,840 --a------ c:\windows\System32\MSADODC.oca
2008-11-26 08:23 . 2008-12-22 22:03 <DIR> d-------- c:\users\Calvin\Incomplete
2008-11-25 10:14 . 2008-10-20 21:25 1,645,568 --a------ c:\windows\System32\connect.dll
2008-11-25 10:14 . 2008-08-27 19:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-11-25 10:14 . 2008-08-27 19:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-11-25 10:14 . 2008-08-27 19:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-11-25 10:14 . 2008-10-21 19:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-11-24 15:58 . 2008-11-24 15:58 <DIR> d-------- c:\users\Calvin\AppData\Roaming\teamspeak2
2008-11-24 15:57 . 2008-11-24 15:57 34,064 --a------ c:\windows\System32\lhacm.acm
2008-11-23 10:20 . 2007-09-17 00:07 134,270 --a------ c:\windows\System32\nvapps.xml
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-23 16:26 --------- d-----w c:\program files\Dl_cats
2008-12-23 07:38 --------- d-----w c:\users\Calvin\AppData\Roaming\FrostWire
2008-12-23 05:50 --------- d-----w c:\program files\EA Sports
2008-12-23 05:02 --------- d---a-w c:\users\Calvin\AppData\Roaming\U3
2008-12-22 16:28 --------- d-----w c:\progra~2\Spybot - Search & Destroy
2008-12-22 16:21 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-18 14:53 --------- d-----w c:\progra~2\Microsoft Help
2008-12-18 07:07 --------- d-----w c:\program files\Java
2008-12-17 02:42 --------- d-----w c:\program files\Dell
2008-12-15 07:12 --------- d-----w c:\program files\McAfee
2008-12-12 22:45 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-10 00:21 --------- d-----w c:\program files\Windows Mail
2008-12-04 04:37 --------- d-----w c:\program files\NCH Swift Sound
2008-12-03 23:43 --------- d--h--w c:\users\Guest\AppData\Roaming\GTek
2008-11-24 01:35 --------- d-----w c:\program files\FrostWire
2008-11-23 18:39 --------- d-----w c:\progra~2\NVIDIA
2008-11-23 18:03 --------- d-----w c:\program files\MSECACHE
2008-11-23 05:33 --------- d-----w c:\program files\Common Files\Microsoft Games
2008-11-23 05:05 --------- d-----w c:\program files\Microsoft Games
2008-11-20 16:53 --------- d-----w c:\program files\Windows Live
2008-11-20 16:45 --------- d-----w c:\progra~2\WLInstaller
2008-11-20 16:44 --------- d-----w c:\program files\Windows Live Safety Center
2008-11-20 05:39 --------- d-----w c:\program files\Common Files\Windows Live
2008-11-18 15:10 --------- d-----w c:\program files\ToniArts
2008-11-18 02:17 --------- d-----w c:\program files\Microsoft Silverlight
2008-11-17 05:12 --------- d-----w c:\program files\DivX
2008-11-16 06:43 891,448 ----a-w c:\windows\system32\drivers\tcpip.sys
2008-11-07 22:23 32,000 ----a-w c:\windows\system32\drivers\usbaapl.sys
2008-11-06 01:39 --------- d-----w c:\progra~2\NCH Swift Sound
2008-11-06 01:13 --------- d-----w c:\program files\NCH Software
2008-11-04 13:37 --------- d-----w c:\program files\DVDVideoSoft
2008-11-04 13:37 --------- d-----w c:\program files\Common Files\DVDVideoSoft
2008-11-03 12:44 --------- d-----w c:\users\Calvin\AppData\Roaming\NCH Swift Sound
2008-11-02 08:44 56,572 ----a-w c:\windows\system32\drivers\scdemu.sys
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-10-25 11:50 --------- d-----w c:\users\Calvin\AppData\Roaming\DivX
2008-05-23 02:33 174 --sha-w c:\program files\desktop.ini
2008-04-20 16:33 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
2008-06-15 03:08 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-06-15 03:08 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-06-15 03:08 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-08-19 21:00 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
2008-08-19 21:00 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008081920080820\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Google Update"="c:\users\Calvin\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-12-08 133104]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dlcqmon.exe"="c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-06-29 292080]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-17 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8497696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"DLCQCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-15 106496]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-17 136600]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 c:\windows\RtHDVCpl.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
c:\users\Mom.Calvin-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-18 23:33 202240 c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" /startup
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe"
"EA Core"=c:\program files\Electronic Arts\EADM\Core.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 966\memcard.exe"
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe"
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"Windows Mobile-based device management"=%windir%\WindowsMobile\wmdSync.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C40A1CDE-3524-47EB-AB86-D043632CF06D}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{95A5E1FA-64AB-4ADB-AC4D-3DF2E0B735B6}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{3FE2B734-5BFA-4A80-84A8-87DC826F8C00}c:\\windows\\explorer.exe"= UDP:c:\windows\explorer.exe:Windows Explorer
"UDP Query User{5FD30CFD-6BAB-4702-9497-098A7B9A67B4}c:\\windows\\explorer.exe"= TCP:c:\windows\explorer.exe:Windows Explorer
"{ECEF8CF6-AFE4-4A65-A2EF-8691D9A93C3E}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{79C9CF6E-0E9A-41AB-861D-8EAE4CF907B2}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{24BECBA1-8C8C-4B02-9916-4EEB02766C48}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{39FBCFD1-2DF2-4251-AF7F-3C3685B06BB7}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{CB551BCF-FF61-435D-A80D-803693620C35}"= UDP:c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{BBD75391-A0DC-47C2-9821-47E61C7E212E}"= TCP:c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{0AA4CB1A-C026-4777-AB0D-26B0E8C4F83E}"= UDP:c:\program files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{F12EB92A-1930-47BF-A3FD-728C657F1501}"= TCP:c:\program files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{D4C3A691-D7F9-44A7-8EFD-B572AA6E55BD}"= UDP:c:\program files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{E91FAA2D-12B0-43F8-B2DC-D06E76678598}"= TCP:c:\program files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{916FABEE-914F-4826-B5B6-1F8593C95026}"= UDP:c:\windows\System32\dlcqcoms.exe:Dell Communications System
"{52987BB2-9EE3-490F-905B-6245E9C27E94}"= TCP:c:\windows\System32\dlcqcoms.exe:Dell Communications System
"{ED28BE93-1FAA-4D8C-A7D1-0257C567F0DD}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{625BF72C-6185-4D8F-B800-F26772BBEA96}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{7FDCC7F9-7C63-4F32-A0FD-967282029470}"= UDP:3703:Adobe Version Cue CS3 Server
"{A54138F7-585B-45C2-B398-2708C437E641}"= UDP:3704:Adobe Version Cue CS3 Server
"{88F3E162-3910-4B5C-81C9-26A4EF828D5F}"= UDP:50900:Adobe Version Cue CS3 Server
"{CF41B43C-48BF-45B6-A844-345E7BD558F2}"= UDP:50901:Adobe Version Cue CS3 Server
"{E9035596-E03B-4100-8521-8ACD9A3F79FD}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{940BD430-EBCF-4C4B-83D7-C7AF61054A01}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{59007D0B-3B78-41DA-85DC-CBC43F6857C4}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{F8D65109-5A54-4613-BE57-2860958BD620}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{EBF5BCD1-808E-4CE6-A528-ED1154649141}"= UDP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{F0BB254B-2B56-4670-A0F8-D6A91169DE26}"= TCP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{59BF8A74-AD16-4AB4-B2C3-67F7E805C283}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6D85EE90-91B7-47CC-B708-5A0DD1A806F9}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{673533C1-1567-476B-B0CA-880A5E0613A7}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{17B6B88C-9ED5-4BAF-A064-7C3DC77EF063}"= UDP:c:\program files\FrostWire\FrostWire.exe:FrostWire
"{3B655E75-3E4B-4939-B38C-1A8B805B52BE}"= TCP:c:\program files\FrostWire\FrostWire.exe:FrostWire
"{E30B1ED6-3B27-4017-859A-73625F16C14B}"= UDP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{A5272FB4-B372-4E5B-8044-3F64CF915C5B}"= TCP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{F7DB8495-1B2A-48A4-A937-0457EADA98C2}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{736BCF32-1B55-4D28-B487-4A116A0DBA6C}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{D74796E9-F28D-4A12-9FC5-52CF837FFC3C}"= UDP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{76C60FB8-9515-4942-BD58-DCF4DEBBF8F0}"= TCP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{9F4618AB-AA21-4387-B49D-032F6F4351ED}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{D58E6597-A2F9-4BD8-9CCB-ABAEF7C6402A}"= TCP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{A64B97B6-82CE-4781-B074-0FCDB62DEF67}"= UDP:c:\program files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{7933A23F-CCC4-43AC-8854-891062504CD7}"= TCP:c:\program files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{27EAFB26-AD02-4DA7-A1C1-42ACB79D9BFD}"= UDP:c:\windows\System32\dlcqcoms.exe:Lexmark Communications System
"{2837EF02-5155-406F-83D4-AC9CA54B2E72}"= TCP:c:\windows\System32\dlcqcoms.exe:Lexmark Communications System
"{8DB4D979-8B52-45D7-9B71-D00095952AF3}"= UDP:c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{CD5E6279-511E-4EFF-A1DD-C2ABE970394B}"= TCP:c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{57D1B8F0-DC42-498A-AF6A-D23054A5340E}"= UDP:c:\program files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{28A1A368-8650-4792-9A26-66373E947820}"= TCP:c:\program files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{19C938C0-9289-4C04-A2AA-47B1E9FB7336}"= UDP:85:BroadWave Web Server
"{C14A4084-33F4-47D5-9F1B-C929F5E45C64}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{5A217F5D-ABFD-4E5E-A435-66F5452D8175}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{FF05D992-4BAE-43AD-B25D-89B900B4DCAA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{A6593B8D-A94D-4691-BB69-793594987B23}c:\\program files\\microsoft games\\microsoft flight simulator x\\fsx.exe"= UDP:c:\program files\microsoft games\microsoft flight simulator x\fsx.exe:Microsoft Flight Simulator®
"UDP Query User{348C7E6D-1243-42A4-B350-113B89C8D52C}c:\\program files\\microsoft games\\microsoft flight simulator x\\fsx.exe"= TCP:c:\program files\microsoft games\microsoft flight simulator x\fsx.exe:Microsoft Flight Simulator®
"TCP Query User{72819F34-FEDA-4427-BE8E-EB70E0C500AF}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{EA0BAF55-95AF-4E47-8F68-7AEDAB3D5A86}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{7CAA56AD-F950-417F-BDBF-2B4CB5C08216}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{E5571FED-1E30-4A0F-A188-BE56964019EC}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{F321E4C2-1EFD-48C6-B4BF-D9A328A6F6D3}c:\\program files\\ea sports\\nhl 09\\nhl2009.exe"= UDP:c:\program files\ea sports\nhl 09\nhl2009.exe:nhl2009
"UDP Query User{D00C2D17-0E99-4D9E-A4C0-7170EA3B6EB5}c:\\program files\\ea sports\\nhl 09\\nhl2009.exe"= TCP:c:\program files\ea sports\nhl 09\nhl2009.exe:nhl2009
"{54436CA8-E579-4E5A-8238-BE9AACE99214}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{29567BCB-3B27-4C75-B06F-E0D93411E436}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{8E642E5E-539F-4659-9B56-A6A32A0D634D}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{8A64FD1C-3824-45CB-AACA-72A2660C912E}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Nexon\\Combat Arms\\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\\Nexon\\Combat Arms\\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Program Files\\Combat Arms\\CombatArms.exe"= c:\program files\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\\Program Files\\Combat Arms\\Engine.exe"= c:\program files\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Program Files\\Nexon\\Combat Arms\\CombatArms.exe"= c:\program files\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\\Program Files\\Nexon\\Combat Arms\\Engine.exe"= c:\program files\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-11-21 809296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - BEEP
.
Contents of the 'Scheduled Tasks' folder
2008-12-23 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 08:09]
2008-12-23 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\users\Calvin\AppData\Local\Google\Update\GoogleUpdate.exe [2008-12-08 07:09]
2008-12-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-12-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-12-23 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 09:20]
2008-12-18 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 09:20]
2008-12-23 c:\windows\Tasks\User_Feed_Synchronization-{0FC40BB8-6DE1-4C3A-BFFC-6DC12BF1D332}.job
- c:\windows\system32\msfeedssync.exe [2008-08-22 02:05]
2008-12-23 c:\windows\Tasks\User_Feed_Synchronization-{2B3DF531-795E-4B8F-852D-F9141689C0CD}.job
- c:\windows\system32\msfeedssync.exe [2008-08-22 02:05]
2008-12-23 c:\windows\Tasks\User_Feed_Synchronization-{893D5EE2-FA10-4615-B039-239B29105AB9}.job
- c:\windows\system32\msfeedssync.exe [2008-08-22 02:05]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-23 08:45:03
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\dlcqcoms.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\conime.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\Common Files\McAfee\MNA\McNASvc.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-12-23 8:53:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-23 16:53:00
Pre-Run: 364,595,970,048 bytes free
Post-Run: 364,325,277,696 bytes free
358 --- E O F --- 2008-12-18 21:46:03