These are the results:
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-04-13 03:20:56
Windows 5.1.2600 Service Pack 2
Running: 1turhjlg.exe; Driver: C:\DOCUME~1\SHANON~1.000\LOCALS~1\Temp\pgldqpoc.sys
---- System - GMER 1.0.15 ----
SSDT 838F0248 ZwConnectPort
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB6B54320]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[1064] ntdll.dll!NtProtectVirtualMemory 7C90DEB6 5 Bytes JMP 0079000A
.text C:\WINDOWS\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory 7C90EA32 5 Bytes JMP 007A000A
.text C:\WINDOWS\System32\svchost.exe[1064] ntdll.dll!KiUserExceptionDispatcher 7C90EAEC 5 Bytes JMP 0078000C
.text C:\WINDOWS\System32\svchost.exe[1064] ole32.dll!CoCreateInstance 774FFAC3 5 Bytes JMP 01F1000A
.text C:\WINDOWS\Explorer.EXE[1752] ntdll.dll!NtProtectVirtualMemory 7C90DEB6 5 Bytes JMP 00A0000A
.text C:\WINDOWS\Explorer.EXE[1752] ntdll.dll!NtWriteVirtualMemory 7C90EA32 5 Bytes JMP 00A6000A
.text C:\WINDOWS\Explorer.EXE[1752] ntdll.dll!KiUserExceptionDispatcher 7C90EAEC 5 Bytes JMP 009F000C
.text C:\WINDOWS\system32\wuauclt.exe[3000] ntdll.dll!NtProtectVirtualMemory 7C90DEB6 5 Bytes JMP 00A2000A
.text C:\WINDOWS\system32\wuauclt.exe[3000] ntdll.dll!NtWriteVirtualMemory 7C90EA32 5 Bytes JMP 00A3000A
.text C:\WINDOWS\system32\wuauclt.exe[3000] ntdll.dll!KiUserExceptionDispatcher 7C90EAEC 5 Bytes JMP 003C000C
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device ACPI.sys (ACPI Driver for NT/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device -> \Driver\atapi \Device\Harddisk0\DR0 83AF6AC8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{67D4DB5C-683F-353F-36F9-D5D712ACD602}\InprocServer32@ C:\WINDOWS\System32\MFC40.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{9A8D95E5-AF9F-4126-9B18-5765AA944847}\InprocServer32@ %SystemRoot%\System32\msoeacct.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{9A8D95E5-AF9F-4126-9B18-5765AA944847}\InprocServer32@ThreadingModel Apartment
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
---- EOF - GMER 1.0.15 ----