Thanks It actually turned out to be this:
http://securityresponse.symantec.com/avcenter/venc/data/w32.serflog.c.html
For anyone else who manages to get this nasty little trojan it spreads through p2p,e-mail & chat an it closes down anti-virus software it doesn't detect it yet
shame on norton I want my money back
To delete this trojan open the hosts file with notepad
C:\WINDOWS\SYSTEM32\DRIVERS\etc Windows XP Users
an delete the following lines
212.58.240.33
www.symantec.com
212.58.240.33
www.sophos.com
212.58.240.33
www.mcafee.com
212.58.240.33
www.viruslist.com
212.58.240.33
www.f-secure.com
212.58.240.33
www.avp.com
212.58.240.33
www.kaspersky.com
212.58.240.33
www.networkassociates.com
212.58.240.33
www.ca.com
212.58.240.33
www.my-etrust.com
212.58.240.33
www.nai.com
212.58.240.33
www.trendmicro.com
212.58.240.33
www.grisoft.com
212.58.240.33 securityresponse.symantec.com
212.58.240.33 symantec.com
212.58.240.33 sophos.com
212.58.240.33 mcafee.com
212.58.240.33 liveupdate.symantecliveupdate.com
212.58.240.33 viruslist.com
212.58.240.33 f-secure.com
212.58.240.33 kaspersky.com
212.58.240.33 kaspersky-labs.com
212.58.240.33 avp.com
212.58.240.33 networkassociates.com
212.58.240.33 ca.com
212.58.240.33 mast.mcafee.com
212.58.240.33 my-etrust.com
212.58.240.33 download.mcafee.com
212.58.240.33 dispatch.mcafee.com
212.58.240.33 secure.nai.com
212.58.240.33 nai.com
212.58.240.33 update.symantec.com
212.58.240.33 updates.symantec.com
212.58.240.33 us.mcafee.com
212.58.240.33 liveupdate.symantec.com
212.58.240.33 customer.symantec.com
212.58.240.33 rads.mcafee.com
212.58.240.33 trendmicro.com
212.58.240.33 grisoft.com
212.58.240.33 sandbox.norman.no
212.58.240.33
www.pandasoftware.com
212.58.240.33 uk.trendmicro-europe.com
an save this will allow you to vist
http://securityresponse.symantec.com/avcenter/venc/data/w32.serflog.c.html where you can dl the removal tool