Kevin,
I have run Combofix once, according to the first part of your instructions. The second part of the instructions seemed to be a second note, that I wasn't sure applied to me. I am happy to run Combofix a second time using the second part of the instructions if you wish.
The Combofix ran to completion and produced a report which outline some deletes it had done. It did not re-boot my system.
One odd thing, on step 50, a small window appeared saying "pex.#XE had stopped working" and that I had to click cancel or search for a solution, I chose to cancel. Combofix kept running, but didn't execute any new steps, just went into the file deletes and produced the report.
=====================================
ComboFix 12-04-28.01 - Jay 04/28/2012 18:17:54.3.4 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3327.2032 [GMT -4:00]
Running from: c:\users\Jay\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Jay\AppData\Roaming\.#
c:\users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\n5jmtqjl.default\weave\toFetch
c:\users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\n5jmtqjl.default\weave\toFetch\clients.json
c:\users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\n5jmtqjl.default\weave\toFetch\tabs.json
c:\windows\system32\aac_parser.ax
c:\windows\system32\ac3DX.ax
c:\windows\system32\AVCDX.ax
c:\windows\system32\bdaplgin.ax
c:\windows\system32\cero.rs
c:\windows\system32\CoreAAC.ax
c:\windows\system32\csrr.rs
c:\windows\system32\DiracSplitter.ax
c:\windows\system32\esrb.rs
c:\windows\system32\FLACDX.ax
c:\windows\system32\g711codc.ax
c:\windows\system32\grb.rs
c:\windows\system32\iac25_32.ax
c:\windows\system32\ir41_32.ax
c:\windows\system32\ivfsrc.ax
c:\windows\system32\ksproxy.ax
c:\windows\system32\kstvtune.ax
c:\windows\system32\Kswdmcap.ax
c:\windows\system32\ksxbar.ax
c:\windows\system32\MatroskaDX.ax
c:\windows\system32\MPCDx.ax
c:\windows\system32\Mpeg2Data.ax
c:\windows\system32\mpg2splt.ax
c:\windows\system32\MSDvbNP.ax
c:\windows\system32\MSNP.ax
c:\windows\system32\oflc.rs
c:\windows\system32\pegi-fi.rs
c:\windows\system32\pegi-pt.rs
c:\windows\system32\pegi.rs
c:\windows\system32\pegibbfc.rs
c:\windows\system32\psisrndr.ax
c:\windows\system32\RealMediaDX.ax
c:\windows\system32\RLAPEDec.ax
c:\windows\system32\RLMPCDec.ax
c:\windows\system32\RLOgg.ax
c:\windows\system32\RLSpeexDec.ax
c:\windows\system32\RLTheoraDec.ax
c:\windows\system32\RLVorbisDec.ax
c:\windows\system32\TAKDSDecoder.ax
c:\windows\system32\TTADSDecoder.ax
c:\windows\system32\TTADSSplitter.ax
c:\windows\system32\usk.rs
c:\windows\system32\VBICodec.ax
c:\windows\system32\vbisurf.ax
c:\windows\system32\vidcap.ax
c:\windows\system32\WEB.rs
c:\windows\system32\WSTPager.ax
c:\windows\system32\xvid.ax
.
.
((((((((((((((((((((((((( Files Created from 2012-03-28 to 2012-04-28 )))))))))))))))))))))))))))))))
.
.
2012-04-28 22:35 . 2012-04-28 22:35 -------- d-----w- c:\users\Jay\AppData\Local\temp
2012-04-28 22:35 . 2012-04-28 22:35 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-04-28 22:35 . 2012-04-28 22:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-28 20:11 . 2012-04-28 20:11 9310 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2012-04-28 20:11 . 2012-04-28 20:11 8646 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2012-04-28 20:11 . 2012-04-28 20:11 6429 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2012-04-28 20:11 . 2012-04-28 20:11 63115 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2012-04-28 20:11 . 2012-04-28 20:11 4599 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2012-04-28 20:11 . 2012-04-28 20:11 8613 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS
2012-04-28 20:11 . 2012-04-28 20:11 5927 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS
2012-04-28 20:11 . 2012-04-28 20:11 1651 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS
2012-04-28 20:11 . 2012-04-28 20:11 6910 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS
2012-04-28 20:11 . 2012-04-28 20:11 8288 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS
2012-04-28 20:11 . 2012-04-28 20:11 6208 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS
2012-04-28 20:11 . 2012-04-28 20:11 18541 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS
2012-04-28 20:10 . 2012-04-28 20:10 51852 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
2012-04-28 20:10 . 2012-04-28 20:10 20719 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2012-04-28 20:10 . 2012-04-28 20:10 8782 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2012-04-28 20:10 . 2012-04-28 20:10 7271 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2012-04-28 20:10 . 2012-04-28 20:10 23327 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2012-04-28 18:36 . 2012-04-28 18:36 -------- d-----w- C:\_OTM
2012-04-23 23:00 . 2012-04-28 12:07 -------- d-----w- c:\windows\system32\drivers\N360\0602000.009
2012-04-22 14:18 . 2011-11-24 02:23 35960 ----a-r- c:\windows\system32\drivers\SymIMV.sys
2012-04-22 01:40 . 2012-03-01 05:46 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-22 01:40 . 2012-03-01 05:37 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-04-22 01:40 . 2012-03-01 05:33 159232 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-22 01:40 . 2012-03-01 05:29 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-22 01:40 . 2012-03-06 05:59 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-22 01:40 . 2012-03-06 05:59 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-06 19:42 . 2012-04-21 18:50 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-01 21:11 . 2012-04-23 22:39 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-01 21:11 . 2012-04-22 15:44 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe
2012-04-01 21:11 . 2012-04-22 15:44 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-21 18:50 . 2011-05-20 01:09 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-04 19:56 . 2010-10-11 17:38 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-24 18:02 . 2012-03-04 17:57 141944 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-02-17 05:34 . 2012-03-13 23:27 826880 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 04:14 . 2012-03-13 23:27 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:13 . 2012-03-13 23:27 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-12 02:35 . 2010-09-10 19:56 231760 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2012-02-10 05:38 . 2012-03-13 23:27 1077248 ----a-w- c:\windows\system32\DWrite.dll
2012-02-03 03:54 . 2012-03-13 23:27 2343424 ----a-w- c:\windows\system32\win32k.sys
2012-04-22 15:44 . 2012-03-03 19:02 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2006-05-03 16:06 163328 --sha-r- c:\windows\System32\flvDX.dll
2007-02-21 17:47 31232 --sha-r- c:\windows\System32\msfDX.dll
2008-03-16 19:30 216064 --sha-r- c:\windows\System32\nbDX.dll
2010-01-07 04:00 107520 --sha-r- c:\windows\System32\TAKDSDecoder.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotkeyMon"="AsusSender.exe" [2011-07-13 34728]
"HotkeyService"="AsusSender.exe" [2011-07-13 34728]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-09-29 7744032]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-07 13797920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"SuperHybridEngine"="AsusSender.exe" [2011-07-13 34728]
"LivCam"="c:\program files\ASUS\LivCam\LivCam.exe" [2009-10-17 284160]
"LiveUpdate"="AsusSender.exe" [2011-07-13 34728]
"SynAsusAcpi"="c:\program files\Synaptics\SynTP\SynAsusAcpi.exe" [2009-11-20 83240]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-11-20 1594664]
"Eraser"="c:\progra~1\Eraser\Eraser.exe" [2010-11-05 980368]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"Daemon for Mouse Suite"="c:\program files\Lenovo\Lenovo Mouse Suite\ICO.EXE" [2010-07-28 69632]
"vmware-tray"="c:\program files\VMware\VMware Workstation\vmware-tray.exe" [2011-09-24 129648]
"PDFPrint"="c:\program files\PDF24\pdf24.exe" [2011-12-16 220744]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
.
c:\users\Jay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-8-2 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 AsusService;Asus Launcher Service;c:\windows\System32\AsusService.exe [2009-08-19 219136]
R2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 D-Link SharePort Helper;D-Link SharePort Helper;c:\program files\D-Link\SharePort Utility\Spnuhelper.exe [2009-12-11 40960]
R2 PelService;Session Launcher Service;c:\program files\Lenovo\Lenovo Mouse Suite\PelService.exe [2010-04-22 184320]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-21 253088]
R3 bmdrvr;Modified Clusters Tracking Driver;c:\windows\system32\drivers\bmdrvr.sys [2011-03-15 54384]
R3 ILPUTXJWWD;ILPUTXJWWD;c:\users\Jay\AppData\Local\Temp\ILPUTXJWWD.exe
R3 MEMOQDRV;MemoQ Voice Recorder;c:\windows\system32\DRIVERS\memoqdrv.sys [2010-01-22 25664]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-22 129976]
R3 NNI;NNI;c:\users\Jay\AppData\Local\Temp\NNI.exe
S1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2011-02-09 11832]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\BASHDefs\20120413.001\BHDrvx86.sys [2012-04-02 821880]
S1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360\0602000.009\ccSetx86.sys [2011-11-04 132744]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\IPSDefs\20120427.001\IDSvix86.sys [2012-03-09 368248]
S1 pelmoubt;Mouse Suite Bluetooth Driver;c:\windows\system32\DRIVERS\pelmoubt.sys [2009-04-23 18432]
S2 N360;Norton 360;c:\program files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe [2012-03-27 138232]
S2 OberonGameConsoleService;Oberon Media Game Console service;c:\program files\Asus\Game Park\GameConsole\OberonGameConsoleService.exe [2009-09-15 44312]
S3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-11-25 43944]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-11-25 29472]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-03-03 106104]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-08-11 66592]
S3 pelbtm;Bluetooth Mouse Filter Driver;c:\windows\system32\DRIVERS\pelbtm.sys [2007-09-20 13312]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-06 18:50]
.
2012-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2272782862-793588217-2826545157-1000Core.job
- c:\users\Jay\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-02 00:57]
.
2012-04-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2272782862-793588217-2826545157-1000UA.job
- c:\users\Jay\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-02 00:57]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
LSP: c:\program files\VMware\VMware Workstation\vsocklib.dll
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
FF - ProfilePath - c:\users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\n5jmtqjl.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/?pc=Z007&form=ZGAPHP
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-Mouse Suite 98 Daemon - ICO.EXE
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\6.2.0.9\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2272782862-793588217-2826545157-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*o*m*_*9*b*4*c*a*e*5*a*5*a*c*γ²y\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2272782862-793588217-2826545157-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*o*m*_*c*4*7*b*c*2*7*4*3*2*2*Wñúr\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2272782862-793588217-2826545157-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*f*l*v*j†÷1\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
Completion time: 2012-04-28 18:39:59
ComboFix-quarantined-files.txt 2012-04-28 22:39
.
Pre-Run: 23,711,469,568 bytes free
Post-Run: 23,524,847,616 bytes free
.
- - End Of File - - 0D8E844220DF66F9D765E72DFA858518