ok here are the combofix logs...
ComboFix 09-03-26.03 - user 2009-03-27 16:55:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.453 [GMT 0:00]
Running from: c:\documents and settings\user\Desktop\ComboFix.exe
AV: Norton AntiVirus *On-access scanning enabled* (Updated)
FW: Norton AntiVirus *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\user\Application Data\svchost32.exe
c:\windows\IE4 Error Log.txt
c:\windows\system32\nsprs.dll
c:\windows\system32\ssprs.dll
----- BITS: Possible infected sites -----
hxxp://loyaltube10.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MSUPDATE
((((((((((((((((((((((((( Files Created from 2009-02-27 to 2009-03-27 )))))))))))))))))))))))))))))))
.
2009-03-26 23:40 . 2009-03-26 23:40 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-26 23:40 . 2009-03-26 23:40 <DIR> d-------- c:\documents and settings\user\Application Data\Malwarebytes
2009-03-26 23:40 . 2009-03-26 23:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-26 23:40 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 23:40 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-26 23:22 . 2009-03-26 23:22 <DIR> d-------- c:\program files\Trend Micro
2009-03-26 15:40 . 2009-03-25 23:38 11,264 --a------ c:\documents and settings\user\Application Data\nSvcAppFlt.exe
2009-03-25 16:30 . 2009-03-26 14:48 <DIR> d-------- C:\Casino
2009-03-08 12:05 . 2009-03-22 13:42 <DIR> d-------- c:\program files\Yahoo!
2009-03-08 12:05 . 2009-03-22 13:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2009-03-07 19:17 . 2009-03-07 19:18 <DIR> d-------- c:\program files\QuickTime
2009-03-07 19:16 . 2009-03-07 19:16 <DIR> d-------- c:\program files\Apple Software Update
2009-03-07 19:16 . 2009-03-07 19:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2009-03-07 15:56 . 2009-03-07 18:14 <DIR> d-------- c:\windows\SxsCaPendDel
2009-03-07 15:56 . 2009-03-07 15:57 <DIR> d-------- C:\21b622dbefd5b3008733
2009-03-05 12:45 . 2009-03-05 12:45 <DIR> d-------- c:\documents and settings\user\Application Data\ZoomBrowser EX
2009-03-03 17:31 . 2009-03-03 17:31 <DIR> d-------- c:\program files\GiPo@Utilities
2009-03-03 17:31 . 2009-03-03 17:31 <DIR> d-------- c:\program files\Common Files\Gibinsoft Shared
2009-03-03 17:30 . 2009-03-03 17:30 <DIR> d-------- c:\windows\Downloaded Installations
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-26 20:40 --------- d-----w c:\documents and settings\user\Application Data\uTorrent
2009-03-22 13:41 --------- d-----w c:\program files\Sony Ericsson
2009-03-20 13:49 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-03-20 13:49 7,386 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-20 13:49 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-20 13:49 --------- d-----w c:\program files\Symantec
2009-03-11 15:30 --------- d-----w c:\program files\Winamp
2009-03-11 15:29 --------- d-----w c:\documents and settings\user\Application Data\Winamp
2009-03-08 00:33 --------- d--h--w c:\program files\Creative Installation Information
2009-03-08 00:30 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-08 00:29 --------- d-----w c:\program files\Creative
2009-03-07 19:17 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-05 12:45 --------- d-----w c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-02-27 11:02 36,400 ----a-r c:\windows\system32\drivers\SymIM.sys
2009-01-29 23:50 --------- d-----w c:\documents and settings\user\Application Data\CyberLink
2009-01-29 23:50 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2009-01-29 23:48 --------- d-----w c:\program files\CyberLink
2009-01-29 23:44 --------- d-----w c:\program files\WinAce
2009-01-29 23:12 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-29 22:59 --------- d-----w c:\documents and settings\user\Application Data\Sonic
2009-01-29 22:56 --------- d-----w c:\documents and settings\user\Application Data\Leadertech
2009-01-29 22:54 --------- d-----w c:\program files\Sonic
2009-01-29 22:54 --------- d-----w c:\program files\Common Files\Sonic Shared
2009-01-29 22:52 --------- d-----w c:\program files\Common Files\Sonic
2008-11-02 13:09 1,096,536 ----a-w c:\documents and settings\user\aidmie.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-03-15 15360]
"CTZDetec.exe"="c:\program files\Creative\Creative Media Lite\CTZDetec.exe" [2008-04-24 368640]
"SoftAuto.exe"="c:\program files\Creative\Software Update 3\SoftAuto.exe" [2008-08-13 405504]
"mount.exe"="c:\program files\GiPo@Utilities\FileUtilities.3\mount.exe" [2008-04-11 374272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"wltray.exe"="c:\windows\system32\wltray.exe" [2006-01-20 1236992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"SetIcon"="c:\program files\Generic\Seticon.exe" [2003-07-29 40960]
"VX3000"="c:\windows\vVX3000.exe" [2006-12-05 707360]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 275800]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-10 67488]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-01-08 451896]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-04 185872]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2008-04-09 87336]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2008-02-22 62760]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2007-11-16 91432]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"P17Helper"="SPIRun.dll" [2006-07-03 c:\windows\system32\SPIRun.dll]
"nwiz"="nwiz.exe" [2008-09-17 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-15 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless Utility.lnk - c:\program files\Belkin\F5D7001v2000\Belkinwcui.exe [2008-06-22 1572864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Documents and Settings\\user\\Application Data\\nSvcAppFlt.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP

HCP Discovery Service
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1005000.086\SymEFA.sys [2009-03-20 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1005000.086\BHDrvx86.sys [2009-03-20 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1005000.086\cchpx86.sys [2009-03-20 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090318.001\IDSXpx86.sys [2009-03-23 276344]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\
000.fcl [2008-05-07 16:51:10 61424]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-10 124832]
R2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [2008-03-31 204800]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe [2009-03-20 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936]
S2 Network Connections (Netman) ;Network Connections (Netman) ; [x]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-06-22 13352]
S4 fasttrak;fasttrak; [x]
S4 iteraid;iteraid; [x]
S4 m5287;m5287; [x]
S4 m5289;m5289; [x]
S4 Si3112r;Si3112r; [x]
S4 viasraid;viasraid; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\Enterprise_Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-03-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-06-22 c:\windows\Tasks\Microsoft_Hardware_Launch_setup_exe.job
- D:\setup.exe []
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Sonic RecordNow! - (no file)
HKLM-Run-AutoConnect - c:\documents and settings\user\Local Settings\Temp\{DDB34076-B82D-4B20-A65D-ADEB6BCFD47E}\{80CD64AA-7406-4508-BFDF-2DFE7F1F8EF0}\AutoConnect.exe
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyServer = http=127.0.0.1:9090
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\21bap5ib.default\
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-27 16:59:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
P17Helper = Rundll32 SPIRun.dll,RunDLLEntry?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Norton AntiVirus\Engine\16.5.0.134\diMaster.dll\" /prefetch:1"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\
000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1308)
c:\windows\system32\BCMLogon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\wltrysvc.exe
c:\windows\system32\bcmwltry.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Creative\Shared Files\CTDevSrv.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\java.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\windows\system32\nvsvc32.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\windows\system32\rundll32.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2009-03-27 17:02:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-27 17:02:15
Pre-Run: 125,091,561,472 bytes free
Post-Run: 126,341,414,912 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[Boot Loader]
Timeout=2
Default=c:\$win_nt$.~bt\BOOTSECT.DAT
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
c:\$win_nt$.~bt\BOOTSECT.DAT="Microsoft Windows XP Professional Setup"
233 --- E O F --- 2009-03-11 12:01:52