ok i tried what you said and it said something about "no system modifications" so i tried running a normal scan a few more times and eventually managed to save it
here it is:
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-05-08 15:53:33
Windows 5.1.2600 Service Pack 3
Running: 4qixu050.exe; Driver: C:\DOCUME~1\keebs\LOCALS~1\Temp\uxtdqpog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xACDFFC08]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xACDFFAC4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xACE00078]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xACDFFFA2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xACDFF69A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xACDFFB9E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xACDFF5DA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xACDFF63E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xACDFFCBE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xACE00146]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xACDFFC7E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xACDFFDFE]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xACF63900]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xACE0C50A]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xACE0C32E]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xACE0C468]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
PAGE ntkrnlpa.exe!ZwLoadDriver 8058413A 7 Bytes JMP ACE0C46C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!NtCreateSection 805AB38E 7 Bytes JMP ACE0C332 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC502 5 Bytes JMP ACE084AA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObInsertObject 805C2F86 5 Bytes JMP ACE0997E \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1134 7 Bytes JMP ACE0C50E \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xB9616000, 0x22F0B7, 0xE8000020]
.text C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl section is writeable [0xA9954000, 0x2892, 0xE8000020]
.vmp2 C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl entry point in ".vmp2" section [0xA9977050]
---- User code sections - GMER 1.0.15 ----
.text c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[168] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00B22862
.text c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[168] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00B226EE
.text c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[168] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00B227E0
.text c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[168] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00B22726
.text c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[168] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00B2275E
.text C:\WINDOWS\Explorer.EXE[408] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00C42862
.text C:\WINDOWS\Explorer.EXE[408] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C426EE
.text C:\WINDOWS\Explorer.EXE[408] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00C427E0
.text C:\WINDOWS\Explorer.EXE[408] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00C42726
.text C:\WINDOWS\Explorer.EXE[408] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00C4275E
.text C:\WINDOWS\system32\wuauclt.exe[856] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 02B62862
.text C:\WINDOWS\system32\wuauclt.exe[856] WS2_32.dll!send 71AB4C27 5 Bytes JMP 02B626EE
.text C:\WINDOWS\system32\wuauclt.exe[856] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 02B627E0
.text C:\WINDOWS\system32\wuauclt.exe[856] WS2_32.dll!recv 71AB676F 5 Bytes JMP 02B62726
.text C:\WINDOWS\system32\wuauclt.exe[856] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 02B6275E
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1384] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 06C12862
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1384] WS2_32.dll!send 71AB4C27 5 Bytes JMP 06C126EE
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1384] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 06C127E0
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1384] WS2_32.dll!recv 71AB676F 5 Bytes JMP 06C12726
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1384] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 06C1275E
.text C:\Program Files\Bonjour\mDNSResponder.exe[1912] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E02862
.text C:\Program Files\Bonjour\mDNSResponder.exe[1912] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E026EE
.text C:\Program Files\Bonjour\mDNSResponder.exe[1912] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E027E0
.text C:\Program Files\Bonjour\mDNSResponder.exe[1912] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E02726
.text C:\Program Files\Bonjour\mDNSResponder.exe[1912] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E0275E
.text C:\Program Files\iTunes\iTunesHelper.exe[2112] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 02CD2862
.text C:\Program Files\iTunes\iTunesHelper.exe[2112] WS2_32.dll!send 71AB4C27 5 Bytes JMP 02CD26EE
.text C:\Program Files\iTunes\iTunesHelper.exe[2112] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 02CD27E0
.text C:\Program Files\iTunes\iTunesHelper.exe[2112] WS2_32.dll!recv 71AB676F 5 Bytes JMP 02CD2726
.text C:\Program Files\iTunes\iTunesHelper.exe[2112] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 02CD275E
.text C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2220] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01E02862
.text C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2220] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01E026EE
.text C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2220] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01E027E0
.text C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2220] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01E02726
.text C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2220] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01E0275E
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2296] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 03FF2862
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2296] WS2_32.dll!send 71AB4C27 5 Bytes JMP 03FF26EE
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2296] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 03FF27E0
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2296] WS2_32.dll!recv 71AB676F 5 Bytes JMP 03FF2726
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2296] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 03FF275E
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[3180] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 04612862
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[3180] WS2_32.dll!send 71AB4C27 5 Bytes JMP 046126EE
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[3180] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 046127E0
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[3180] WS2_32.dll!recv 71AB676F 5 Bytes JMP 04612726
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[3180] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 0461275E
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3420] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00F22862
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3420] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00F226EE
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3420] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00F227E0
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3420] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00F22726
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3420] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00F2275E
.text C:\WINDOWS\System32\alg.exe[4064] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00C92862
.text C:\WINDOWS\System32\alg.exe[4064] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C926EE
.text C:\WINDOWS\System32\alg.exe[4064] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00C927E0
.text C:\WINDOWS\System32\alg.exe[4064] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00C92726
.text C:\WINDOWS\System32\alg.exe[4064] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00C9275E
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[800] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[800] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\ACPI \Device\00000060 8AC8C578
Device \Driver\ACPI \Device\00000047 8AC8C578
Device \Driver\ACPI \Device\00000048 8AC8C578
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\ACPI \Device\00000070 8AC8C578
Device \Driver\ACPI \Device\00000063 8AC8C578
Device \Driver\ACPI \Device\00000071 8AC8C578
Device \Driver\ACPI \Device\00000074 8AC8C578
Device \Driver\ACPI \Device\00000075 8AC8C578
Device \Driver\ACPI \Device\00000069 8AC8C578
Device \Driver\ACPI \Device\0000004d 8AC8C578
Device \Driver\ACPI \Device\0000004e 8AC8C578
Device \Driver\ACPI \Device\0000004f 8AC8C578
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\ACPI \Device\0000005d 8AC8C578
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\ACPI \Device\0000006a 8AC8C578
Device \Driver\ACPI \Device\0000006c 8AC8C578
Device \Driver\ACPI \Device\0000006d 8AC8C578
Device \Driver\ACPI \Device\0000006e 8AC8C578
Device \Driver\ACPI \Device\0000006f 8AC8C578
---- EOF - GMER 1.0.15 ----
Edited by k33ba, 08 May 2010 - 07:41 PM.