Ok, so after a few hours it's finally done.
GMER 1.0.15.15640 -
http://www.gmer.net
Rootkit scan 2011-07-06 22:53:45
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3250410AS rev.3.AAC
Running: 8eipcc2j.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\pwldipob.sys
---- System - GMER 1.0.15 ----
SSDT 89F45C50 ZwAlertResumeThread
SSDT 89F3DC18 ZwAlertThread
SSDT 89EF1B20 ZwAllocateVirtualMemory
SSDT 89FF6E68 ZwAssignProcessToJobObject
SSDT 898FC8C0 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xB366E710]
SSDT 89EEAD60 ZwCreateMutant
SSDT 89EE0958 ZwCreateSymbolicLinkObject
SSDT 89ECE050 ZwCreateThread
SSDT 8A06C4D8 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xB366E990]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xB366EEF0]
SSDT 89F42078 ZwDuplicateObject
SSDT 89EBCCC0 ZwFreeVirtualMemory
SSDT 89EE0060 ZwImpersonateAnonymousToken
SSDT 89F50038 ZwImpersonateThread
SSDT 89E96DC8 ZwLoadDriver
SSDT 89EDFB50 ZwMapViewOfSection
SSDT 89ED9E08 ZwOpenEvent
SSDT 89FD7800 ZwOpenProcess
SSDT 89F8F8A0 ZwOpenProcessToken
SSDT 89ED5F30 ZwOpenSection
SSDT 89FA85A0 ZwOpenThread
SSDT 89FFA220 ZwProtectVirtualMemory
SSDT 89F7CE08 ZwResumeThread
SSDT 89F872C0 ZwSetContextThread
SSDT 8A129C78 ZwSetInformationProcess
SSDT 89839160 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xB366F140]
SSDT 89ED93F8 ZwSuspendProcess
SSDT 89F52DF8 ZwSuspendThread
SSDT 89F76A70 ZwTerminateProcess
SSDT 89F82DF8 ZwTerminateThread
SSDT 89F893A8 ZwUnmapViewOfSection
SSDT 89EEC0B8 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2CE0 8050457C 4 Bytes JMP D2DAF8E7
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB5F543A0, 0x59FFE5, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\SearchIndexer.exe[2472] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----