It looks like Polonus was right with the Vundo call, but it may be a new variant protected by a rootkit that the Symantec tool cannot touch. DP.sys certainly indicates this:

http://wiki.castlecops.com/Vundo_Rootkit_Detection_and_Removal_Procedure

spookytone: you need to download the VundoFix.exe tooland run it as described in section 8 of the link above.