The thread your link directs to is amazingly helpful ... thanks!
I've downloaded a few of the applications and already Zone Alarm has blocked things trying to access my pc that Norton didnt see ... silly that a free programme works better than the £50 one *rolls eyes*
Here's the combofix log:
"Sarah" - 07-02-12 1:44:50 Service Pack 2
ComboFix 07-02-07 - Running from: "C:\Documents and Settings\Sarah\Desktop\Tools"
((((((((((((((((((((((((((((((( Files Created from 2007-01-12 to 2007-02-12 ))))))))))))))))))))))))))))))))))
2007-02-12 01:41 d-------- C:\Program Files\SpywareBlaster
2007-02-12 01:24 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-02-12 01:23 75,512 --a------ C:\WINDOWS\zllsputility.exe
2007-02-12 01:23 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-02-12 01:23 1,087,216 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-02-12 01:23 d-------- C:\WINDOWS\system32\ZoneLabs
2007-02-12 01:22 d-------- C:\WINDOWS\Internet Logs
2007-02-12 01:17 d-------- C:\Program Files\Windows Defender
2007-02-12 01:17 d-------- C:\c58930f38af91c528bd17fd98596
2007-02-12 01:11 d-------- C:\fdaece98d2545f4a96d51c3c021f
2007-02-12 01:09 d-------- C:\e4921abaf5aedb7fbea089a357
2007-02-12 01:00 0 --a------ C:\WINDOWS\nsreg.dat
2007-02-12 00:59 d-------- C:\Program Files\Mozilla Firefox
2007-02-12 00:40 d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Windows Genuine Advantage
2007-02-12 00:39 d-------- C:\c564f63a9ea55401b21fe240afe2
2007-02-11 03:00 d-------- C:\8e81fadbf7e0f8bf22d93104ad7055
2007-02-10 23:10 d-------- C:\7c652e128e8e716b536d907205
2007-02-10 20:02 d-------- C:\fixwareout
2007-02-10 03:32 d-------- C:\d6c62d58e7cfc427e8a9c890af9263
2007-02-10 03:00 d-------- C:\8d384b3b473eb6b49490036e6b57
2007-02-09 20:46 d-------- C:\Program Files\Norton Internet Security
2007-02-09 20:45 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-02-09 20:45 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-02-09 20:43 d-------- C:\Program Files\Symantec
2007-02-09 03:31 d-------- C:\4d5f43340c34e8b320ae0bdeb970
2007-02-09 03:18 d-------- C:\VundoFix Backups
2007-02-09 03:02 d-------- C:\Program Files\MSXML 4.0
2007-02-09 03:02 d-------- C:\9146e9fb82a2f646cd1c
2007-02-08 21:28 d-------- C:\HJT
2007-02-08 20:57 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-08 20:57 d-------- C:\Program Files\Grisoft
2007-02-08 20:34 d--h----- C:\DOCUME~1\Sarah\Application Data\yahoo!
2007-02-08 19:51 d-------- C:\DOCUME~1\ALLUSE~1\Application Data\yahoo!
2007-02-08 19:40 d-------- C:\Program Files\Yahoo!
2007-02-08 18:36 23,040 --------- C:\WINDOWS\kb913800.exe
2007-02-08 18:20 d-------- C:\Program Files\MSN Messenger
2007-02-08 18:18 d-------- C:\WINDOWS\system32\PreInstall
2007-02-08 18:07 d---s---- C:\DOCUME~1\Sarah\UserData
2007-02-08 17:53 d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-02-08 17:39 70,688 --a------ C:\WINDOWS\system32\drivers\alcaudsl.sys
2007-02-08 17:39 53,600 --a------ C:\WINDOWS\system32\drivers\alcan5wn.sys
2007-02-08 17:39 5,606 --a------ C:\WINDOWS\system32\stci.dll
2007-02-08 17:39 5,280 --a------ C:\WINDOWS\system32\drivers\alcawh.sys
2007-02-08 17:39 3,968 --a------ C:\WINDOWS\system32\drivers\alcacr.sys
2007-02-08 17:39 d-------- C:\Program Files\Thomson
2007-02-05 03:04 d-------- C:\WINDOWS\Performance
2007-02-05 03:03 d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Microsoft Corporation
2007-02-05 02:52 d-------- C:\Program Files\Encore
2007-02-04 02:51 d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Trymedia
2007-02-03 20:02 d-------- C:\Downloads
2007-02-03 03:17 d-------- C:\SIERRA
2007-02-03 03:07 d-------- C:\DOCUME~1\Sarah\WINDOWS
2007-02-01 23:49 d--hs---- C:\WINDOWS\ftpcache
2007-02-01 15:07 104 --a------ C:\WINDOWS\system32\attfd42.dll
2007-02-01 14:42 d-------- C:\WINDOWS\Profiles
2007-02-01 00:13 d-------- C:\DOCUME~1\Sarah\Application Data\Ahead
2007-02-01 00:12 89,184 -ra------ C:\WINDOWS\system32\drivers\imagedrv.sys
2007-02-01 00:11 569,344 -ra------ C:\WINDOWS\system32\imagr5.dll
2007-02-01 00:11 544,768 -ra------ C:\WINDOWS\system32\imagx5.dll
2007-02-01 00:11 38,912 -ra------ C:\WINDOWS\system32\picn20.dll
2007-02-01 00:11 283,920 -ra------ C:\WINDOWS\system32\ImagXpr5.dll
2007-02-01 00:10 155,648 -ra------ C:\WINDOWS\system32\NeroCheck.exe
2007-02-01 00:10 d-------- C:\Program Files\Common Files\Ahead
2007-02-01 00:10 d-------- C:\Program Files\Ahead
2007-01-31 11:42 0 --a------ C:\DOCUME~1\Sarah\Application Data\wklnhst.dat
2007-01-31 11:42 d-------- C:\DOCUME~1\Sarah\Application Data\Template
2007-01-30 12:51 d-------- C:\DOCUME~1\Sarah\Application Data\AdobeUM
2007-01-25 12:43 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-01-24 19:37 d-------- C:\Program Files\Atari
2007-01-22 18:28 d-------- C:\DOCUME~1\Sarah\Application Data\Logitech
2007-01-22 18:25 13,440 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.SYS
2007-01-22 18:25 d-------- C:\Program Files\MUSICMATCH
2007-01-22 18:24 68,864 --a------ C:\WINDOWS\system32\drivers\LMouKE.Sys
2007-01-22 18:24 55,040 --a------ C:\WINDOWS\system32\drivers\L8042MOU.SYS
2007-01-22 18:24 28,160 --a------ C:\WINDOWS\KHALMNPR.Exe
2007-01-22 18:24 26,112 --a------ C:\WINDOWS\system32\drivers\LHidKE.Sys
2007-01-22 18:24 258,352 --a------ C:\WINDOWS\system32\unicows.dll
2007-01-22 18:24 d-------- C:\Program Files\Logitech
2007-01-22 18:24 d-------- C:\Program Files\Common Files\Logitech
2007-01-22 18:19 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-01-12 18:01 276,792 --a------ C:\WINDOWS\system32\drivers\srtspl.sys
2007-01-12 18:01 25,400 --a------ C:\WINDOWS\system32\drivers\srtspx.sys
2007-01-12 18:01 247,608 --a------ C:\WINDOWS\system32\drivers\srtsp.sys
2007-01-12 13:13 d-------- C:\Program Files\KONAMI
2007-01-12 12:37 d-------- C:\Program Files\Game Graphic Studio
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-02-12 01:48 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-02-12 01:00 -------- d-------- C:\DOCUME~1\Sarah\Application Data\mozilla
2007-02-10 20:26 -------- d-------- C:\Program Files\java
2007-02-08 19:55 -------- d-------- C:\DOCUME~1\Sarah\Application Data\macromedia
2007-02-08 18:21 -------- d---s---- C:\DOCUME~1\Sarah\Application Data\microsoft
2007-02-08 17:39 -------- d--h----- C:\Program Files\installshield installation information
2007-02-04 03:05 -------- d-------- C:\Program Files\dkz studio
2007-01-08 02:10 -------- d-------- C:\Program Files\sports interactive
2007-01-05 12:36 21840 --a----t- C:\WINDOWS\system32\sintfnt.dll
2007-01-05 12:36 17212 --a----t- C:\WINDOWS\system32\sintf32.dll
2007-01-05 12:36 12067 --a----t- C:\WINDOWS\system32\sintf16.dll
2007-01-04 11:41 -------- d-------- C:\Program Files\winuha
2007-01-03 19:37 -------- d-------- C:\Program Files\7-zip
2007-01-01 13:06 737280 --a------ C:\WINDOWS\iun6002.exe
2006-12-27 23:17 -------- d-------- C:\Program Files\fox
2006-12-27 13:39 98304 --a------ C:\WINDOWS\system32\cmdlineext.dll
2006-12-27 13:36 -------- d-------- C:\Program Files\vid_0e8f&pid_0003
2006-12-26 15:08 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2006-12-25 20:20 -------- d-------- C:\DOCUME~1\Sarah\Application Data\intervideo
2006-12-21 11:40 -------- d-------- C:\Program Files\ea games
2006-12-15 11:11 21275 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2006-12-15 11:11 -------- d-------- C:\Program Files\intel
2006-12-15 11:11 -------- d-------- C:\DOCUME~1\Sarah\Application Data\intel
2006-12-07 04:14 2330624 --a------ C:\WINDOWS\system32\wmvcore.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"TOSCDSPD"="C:\\Program Files\\TOSHIBA\\TOSCDSPD\\toscdspd.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"nwiz"="nwiz.exe /installquiet"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"Toshiba Hotkey Utility"="\"C:\\Program Files\\Toshiba\\Windows Utilities\\Hotkey.exe\" /lang en"
"SmoothView"="C:\\Program Files\\TOSHIBA\\TOSHIBA Zooming Utility\\SmoothView.exe"
"DLA"="C:\\WINDOWS\\System32\\DLA\\DLACTRLW.EXE"
"IntelZeroConfig"="\"C:\\Program Files\\Intel\\Wireless\\bin\\ZCfgSvc.exe\""
"IntelWireless"="\"C:\\Program Files\\Intel\\Wireless\\Bin\\ifrmewrk.exe\" /tf Intel PROSet/Wireless"
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
"NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Thomson\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_SRESCAN
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_VSMON
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Sarah.job
********************************************************************
catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-02-12 1:50:28
C:\ComboFix2.txt ... 07-02-09 13:48
Thanks! :)