Since I posted, did a little more searching... GMER found the following Rootkit activity...
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-03-14 14:33:52
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort1 ST980813ASG rev.3.ADD
Running: h2ys02r2.exe; Driver: C:\DOCUME~1\mabraun\LOCALS~1\Temp\kwlyraod.sys
---- System - GMER 1.0.15 ----
SSDT 89FF3F10 ZwAlertResumeThread
SSDT 89FF3FD0 ZwAlertThread
SSDT 8A073F00 ZwAllocateVirtualMemory
SSDT 8A05D670 ZwConnectPort
SSDT Lbd.sys ZwCreateKey [0xBA0F887E]
SSDT 89FFAE78 ZwCreateMutant
SSDT 89FFA610 ZwCreateThread
SSDT 8A127118 ZwFreeVirtualMemory
SSDT 89FFAF48 ZwImpersonateAnonymousToken
SSDT 89FF3E50 ZwImpersonateThread
SSDT 8A0672B8 ZwMapViewOfSection
SSDT 8A06ED40 ZwOpenEvent
SSDT 8A073FD0 ZwOpenProcessToken
SSDT 8A39F590 ZwOpenThreadToken
SSDT 8A6B67D8 ZwResumeThread
SSDT 8A39F4D0 ZwSetContextThread
SSDT 8A4B4058 ZwSetInformationProcess
SSDT 8A064D28 ZwSetInformationThread
SSDT Lbd.sys ZwSetValueKey [0xBA0F8BFE]
SSDT 8A06EC80 ZwSuspendProcess
SSDT 8A063E10 ZwSuspendThread
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xA773B640]
SSDT 8A064C68 ZwTerminateThread
SSDT 8A4B4128 ZwUnmapViewOfSection
SSDT 8A05B328 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
? Lbd.sys The system cannot find the file specified. !
? Combo-Fix.sys The system cannot find the file specified. !
? C:\ComboFix\catchme.sys The system cannot find the path specified. !
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS The system cannot find the file specified. !
? C:\DOCUME~1\mabraun\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[1436] kernel32.dll!WriteFile 7C810E27 5 Bytes JMP 0092000C
.text C:\WINDOWS\System32\svchost.exe[1436] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 020D000A
.text C:\WINDOWS\System32\svchost.exe[1436] USER32.dll!WindowFromPoint 7E429766 5 Bytes JMP 0266000A
.text C:\WINDOWS\System32\svchost.exe[1436] USER32.dll!GetForegroundWindow 7E429823 5 Bytes JMP 031E000A
.text C:\WINDOWS\System32\svchost.exe[1436] ole32.dll!CoCreateInstance 774FF1BC 5 Bytes JMP 00B6000A
.text C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe[4164] kernel32.dll!WriteFile 7C810E27 5 Bytes JMP 00B3000C
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 8A58E2C6
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-3 8A58E2C6
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 8A58E2C6
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-e 8A58E2C6
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)
---- Processes - GMER 1.0.15 ----
Library C:\Program (*** hidden *** ) @ C:\WINDOWS\explorer.exe [2268] 0x03AC0000
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 TDL4@MBR code has been found <-- ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior
---- EOF - GMER 1.0.15 ----
will post more if I find a solution before someone else gets to helping.
thanks for your assistance