Okay, some questions and some housekeeping:
1. Do you have a security suite from Symantec/Norton? Most have a firewall included. I see you are also running Comodo. so if Norton is current, you need to remove the Comodo firewall.
2. Did you miss my instructions to temporarily disable the Real Time Protection of TeaTimer and Symantec Endpoint Protection in Post #11? Having this kind of protection running can affect the scans. And in the Combofix program, you were also instructed to shut dow all security programs.
3. Did you delete the entries Norton put in quaranting? If not, please do that, then the following:
4.
TFC (Temp File Cleaner)
Download
TFC to your desktop
- Open the file and close any other windows.
- It will close all programs itself when run, make sure to let it run uninterrupted.
- Click the Start button to begin the process. The program should not take long to finish its job
- Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail.
TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC.
TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder.
When through, please
Empty the Recycle Bin
5.
Old versions of Java and Adobe Reader present another vulnerability and they should be updated:
- Visit this site[Adobe Reader often and make sure you have the most current update. Uninstall any earlier updates as they are vulnerabilities.
- Check this site often.Java Updates Stay current as most updates are for security. Uninstall any earlier versions in Add/Remove Programs.
It is important the you uninstall the outdated versions of Adobe v7 and Java v1.5.11.
6. Please reopen HijcackThis to 'do system scan only'. Check the following entry:
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_SG&c=Q106&bd=pavilion&pf=laptop
Close all Windows except hijackThis cna click on
"Fix Checked."
Do you have any ide what 'Promo' is here? It's a particular port open in the firewall.
53:UDP"= 53:UDP

romo
When you get this done- including deleting all the entries Norton has quarantined, please do this:
Run Eset NOD32 Online AntiVirus Scanner HERE
Note: You will need to use Internet Explorer for this scan.
- Tick the box next to YES, I accept the Terms of Use.
- Click Start
- When asked, allow the Active X control to install
- Disable your current Antivirus software. You can usually do this with its Notification Tray icon near the clock.
- Click Start
- Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is checked
- Click Scan
- Wait for the scan to finish
- Re-enable your Antivirus software.
- A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please include this on your post.
Save the log and
attach it in next reply.
Rescan with HijackThis and
paste the new log in next reply.
A NOTE: Please do not use the System Restore feature. There is malware in the restore points. I will have you dropp the old restore points and create a new clean on when we finish.