OK, I did all of those steps (thanks for the java uninstall tip - I had no idea!)
Here is the Combofix log:
ComboFix 10-07-12.02 - shebagrl 07/12/2010 20:55:46.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.387 [GMT -4:00]
Running from: c:\documents and settings\shebagrl\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\shebagrl\My Documents\Downloads\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FILE ::
"c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgp.zip"
"c:\windows\Bdanitubalikoqa.bin"
"c:\windows\Hmuvasoyuyebi.dat"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgp.zip
c:\documents and settings\LocalService\UserData
c:\documents and settings\LocalService\UserData\index.dat
c:\documents and settings\LocalService\UserData\TGWJXPG1\pmocntr[1].xml
c:\documents and settings\NetworkService\Local Settings\Application Data\ppggwhjei
c:\documents and settings\shebagrl\Local Settings\Application Data\qrxxbvjmy
c:\windows\Bdanitubalikoqa.bin
c:\windows\Hmuvasoyuyebi.dat
.
((((((((((((((((((((((((( Files Created from 2010-06-13 to 2010-07-13 )))))))))))))))))))))))))))))))
.
2010-07-10 20:50 . 2010-07-10 20:50 -------- d-----w- c:\program files\ESET
2010-07-10 14:16 . 2010-07-10 14:16 217180 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-07-10 14:16 . 2010-07-10 14:16 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-07-10 14:16 . 2010-07-10 14:16 217180 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-07-10 14:15 . 2010-06-07 23:57 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-07-10 14:15 . 2010-06-07 23:57 10256384 ----a-w- c:\windows\system32\nvcompiler.dll
2010-07-09 16:35 . 2010-07-09 16:35 -------- d-----w- c:\documents and settings\shebagrl\Application Data\Malwarebytes
2010-07-09 16:35 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-09 16:35 . 2010-07-12 16:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-09 16:35 . 2010-07-09 16:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-09 16:35 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-08 23:18 . 2010-07-08 23:19 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-07-08 18:53 . 2010-07-08 18:53 -------- d-----w- c:\documents and settings\shebagrl\Local Settings\Application Data\{2C062FEB-6192-4838-AF45-F5216B3FD845}
2010-07-01 21:17 . 2010-07-01 21:17 -------- d-----w- c:\program files\iPod
2010-07-01 21:17 . 2010-07-01 21:18 -------- d-----w- c:\program files\iTunes
2010-07-01 21:17 . 2010-07-01 21:18 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-01 21:10 . 2010-07-01 21:10 -------- d-----w- c:\program files\Bonjour
2010-07-01 21:05 . 2010-07-01 21:05 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-20 21:26 . 2001-08-18 02:36 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-06-20 21:26 . 2001-08-18 02:36 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2010-06-20 21:26 . 2001-08-18 02:36 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-06-20 21:26 . 2001-08-18 02:36 8192 ----a-w- c:\windows\system32\kbdkor.dll
2010-06-20 21:26 . 2001-08-17 18:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-06-20 21:26 . 2001-08-17 18:55 6144 ----a-w- c:\windows\system32\kbd101c.dll
2010-06-20 21:26 . 2001-08-17 18:55 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll
2010-06-20 21:26 . 2001-08-17 18:55 5632 ----a-w- c:\windows\system32\kbd103.dll
2010-06-20 21:26 . 2001-08-17 18:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-06-20 21:26 . 2001-08-17 18:55 6144 ----a-w- c:\windows\system32\kbd101b.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-13 00:52 . 2008-02-11 02:03 -------- d-----w- c:\program files\Symantec AntiVirus
2010-07-10 14:17 . 2009-05-09 22:53 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-07-10 14:16 . 2009-08-24 22:52 -------- d-----w- c:\program files\NVIDIA Corporation
2010-07-09 19:58 . 2008-01-18 18:58 -------- d-----w- c:\program files\Google
2010-07-09 19:57 . 2008-11-26 17:55 -------- d-----w- c:\program files\Acro Software
2010-07-09 19:56 . 2008-12-10 17:06 -------- d-----w- c:\program files\Common Files\ArcSoft
2010-07-09 19:56 . 2007-05-10 00:55 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-09 17:18 . 2008-12-10 17:06 720 ----a-w- c:\documents and settings\All Users\Application Data\ArcSoft\kodak-printcreations-22-080812-oem\acforall.dll
2010-07-08 23:19 . 2009-09-24 01:54 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-08 23:19 . 2007-05-10 00:38 1100 ----a-w- c:\windows\system32\d3d8caps.dat
2010-07-01 21:27 . 2009-12-30 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-01 21:26 . 2007-11-24 01:47 -------- d-----w- c:\program files\Apple Software Update
2010-07-01 21:17 . 2007-11-24 01:47 -------- d-----w- c:\program files\Common Files\Apple
2010-07-01 21:14 . 2008-02-11 00:34 -------- d-----w- c:\program files\QuickTime
2010-06-08 13:56 . 2010-06-08 13:56 -------- d-----w- c:\program files\TweetDeck
2010-06-07 23:57 . 2009-09-24 02:18 600680 ----a-w- c:\windows\system32\nvudisp.exe
2010-06-07 23:57 . 2009-08-17 04:57 2632296 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-06-07 23:57 . 2009-08-17 04:57 2186342 ----a-w- c:\windows\system32\nvdata.bin
2010-06-07 23:57 . 2009-08-17 04:57 2165352 ----a-w- c:\windows\system32\nvcuvid.dll
2010-06-07 23:57 . 2008-08-01 18:48 6300544 ----a-w- c:\windows\system32\nv4_disp.dll
2010-06-07 23:57 . 2008-08-01 18:48 4554752 ----a-w- c:\windows\system32\nvcuda.dll
2010-06-07 23:57 . 2008-08-01 18:48 232040 ----a-w- c:\windows\system32\nvcodins.dll
2010-06-07 23:57 . 2008-08-01 18:48 232040 ----a-w- c:\windows\system32\nvcod.dll
2010-06-07 23:57 . 2008-08-01 18:48 15192064 ----a-w- c:\windows\system32\nvoglnt.dll
2010-06-07 23:57 . 2008-08-01 18:48 1359872 ----a-w- c:\windows\system32\nvapi.dll
2010-06-07 23:57 . 2008-08-01 18:48 10531200 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-06-07 21:34 . 2010-06-07 21:34 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-06-07 21:34 . 2010-06-07 21:34 277608 ----a-w- c:\windows\system32\nvmccs.dll
2010-06-07 21:34 . 2010-06-07 21:34 13902440 ----a-w- c:\windows\system32\nvcpl.dll
2010-06-07 21:34 . 2010-06-07 21:34 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-06-07 21:34 . 2010-06-07 21:34 154728 ----a-w- c:\windows\system32\nvsvc32.exe
2010-06-07 21:34 . 2010-06-07 21:34 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-06-02 14:28 . 2010-06-09 16:15 865792 ----a-w- c:\documents and settings\shebagrl\Application Data\Mozilla\Firefox\Profiles\zuwji7ux.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\WINNT_x86-msvc\components\pagespeed.dll
2010-05-28 16:58 . 2009-09-24 02:18 600680 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-05-21 19:26 . 2009-12-30 22:53 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-05-20 15:37 . 2010-05-20 15:37 -------- d-----w- c:\documents and settings\shebagrl\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-18 13:43 . 2009-05-06 17:54 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-05-16 13:24 . 2010-05-12 15:31 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-05-02 05:22 . 2004-08-10 11:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-10 11:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-16 16:09 . 2006-03-04 03:33 667136 ----a-w- c:\windows\system32\wininet.dll
2010-04-16 16:09 . 2004-08-10 11:00 81920 ----a-w- c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-05-04 64512]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-06-03 1753192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-06-07 13902440]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-06-07 110696]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SMCWUSB-G 802.11g Wireless USB Utility.lnk - c:\dell\drivers\SMCWGUTI.exe [2006-1-18 442368]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2006-07-20 00:26 52896 ----a-w- c:\program files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-08-05 17:56 64512 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-06-15 20:33 141624 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-19 02:16 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-12-12 13:58 136600 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 06:00 90112 ------w- c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\HKO\\HKODM.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/28/2010 8:05 PM 102448]
R3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);c:\windows\system32\drivers\SMCWGU.sys [2/7/2010 6:20 PM 408064]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/6/2010 1:40 PM 135664]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/27/2006 9:33 PM 116464]
.
Contents of the 'Scheduled Tasks' folder
2010-07-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]
2010-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb0c1bce8628f0.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-06 17:40]
2010-07-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-1425521274-725345543-1003Core1cb0c1bd980f896.job
- c:\documents and settings\shebagrl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-14 04:47]
2010-07-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-746137067-1425521274-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
2010-07-01 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-746137067-1425521274-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.gmail.com/
uInternet Settings,ProxyServer = http=127.0.0.1:5577
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\shebagrl\Application Data\Mozilla\Firefox\Profiles\zuwji7ux.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
FF - component: c:\documents and settings\shebagrl\Application Data\Mozilla\Firefox\Profiles\zuwji7ux.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\WINNT_x86-msvc\components\pagespeed.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\shebagrl\Application Data\Mozilla\Firefox\Profiles\zuwji7ux.default\extensions\support@ancestry.com\plugins\npImgCtl.dll
FF - plugin: c:\documents and settings\shebagrl\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: XULRunner: {2C062FEB-6192-4838-AF45-F5216B3FD845} - c:\documents and settings\shebagrl\Local Settings\Application Data\{2C062FEB-6192-4838-AF45-F5216B3FD845}\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-12 21:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-07-12 21:02:44
ComboFix-quarantined-files.txt 2010-07-13 01:02
ComboFix2.txt 2010-07-12 16:53
ComboFix3.txt 2010-07-10 20:44
Pre-Run: 68,535,689,216 bytes free
Post-Run: 68,529,446,912 bytes free
- - End Of File - - 6E29AD84441742061157B7AB3DF97A46