Here is my gmer log as well....
GMER 1.0.15.15163 -
http://www.gmer.net
Rootkit scan 2009-10-28 09:52:03
Windows 5.1.2600 Service Pack 2
Running: fwpg5f68.exe; Driver: C:\DOCUME~1\Steven\LOCALS~1\Temp\uxtdypob.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAA1466B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xAA146574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xAA146A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAA14614C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAA14664E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAA14608C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAA1460F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAA14676E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAA14672E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xAA1468AE]
---- Kernel code sections - GMER 1.0.15 ----
.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF739C380]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip MpFirewall.sys (McAfee Personal Firewall Driver/McAfee)
AttachedDevice \Driver\Tcpip \Device\Ip ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp MpFirewall.sys (McAfee Personal Firewall Driver/McAfee)
AttachedDevice \Driver\Tcpip \Device\Tcp ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F738F9F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdePort0 [F738F9F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdePort1 [F738F9F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F738F9F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
AttachedDevice \Driver\Tcpip \Device\Udp MpFirewall.sys (McAfee Personal Firewall Driver/McAfee)
AttachedDevice \Driver\Tcpip \Device\Udp ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp MpFirewall.sys (McAfee Personal Firewall Driver/McAfee)
AttachedDevice \Driver\Tcpip \Device\RawIp ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4@khjeh 0x06 0x2C 0x57 0x22 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001@khjeh 0xFF 0x30 0xFF 0x17 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001\0Jf40@khjeh 0xD1 0xC5 0xFF 0x4E ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001\0Jf41@khjeh 0x9D 0xF8 0x17 0x97 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4@khjeh 0x06 0x2C 0x57 0x22 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001@khjeh 0xFF 0x30 0xFF 0x17 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001\0Jf40@khjeh 0xD1 0xC5 0xFF 0x4E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001\0Jf41@khjeh 0x9D 0xF8 0x17 0x97 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4@khjeh 0x06 0x2C 0x57 0x22 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4\00000001@khjeh 0xFF 0x30 0xFF 0x17 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4\00000001\0Jf40@khjeh 0xD1 0xC5 0xFF 0x4E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4\00000001\0Jf41@khjeh 0x9D 0xF8 0x17 0x97 ...
---- Files - GMER 1.0.15 ----
File C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\fr.lproj\SoftwareUpdateLocalized.dll 26112 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\ja.lproj\SoftwareUpdateLocalized.dll 24064 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\zh_TW.lproj\SoftwareUpdateLocalized.dll 24064 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\da.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\da.lproj\SoftwareUpdateFilesLocalized. dll 4608 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\de.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\de.lproj\SoftwareUpdateFilesLocalized. dll 5120 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\en.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\en.lproj\SoftwareUpdateFilesLocalized. dll 4096 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\es.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\es.lproj\SoftwareUpdateFilesLocalized. dll 4608 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\fi.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\fi.lproj\SoftwareUpdateFilesLocalized. dll 4608 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\fr.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\fr.lproj\SoftwareUpdateFilesLocalized. dll 5120 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\it.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\it.lproj\SoftwareUpdateFilesLocalized. dll 5120 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ja.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ja.lproj\SoftwareUpdateFilesLocalized. dll 4608 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ko.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ko.lproj\SoftwareUpdateFilesLocalized. dll 4608 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\nb.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\nb.lproj\SoftwareUpdateFilesLocalized. dll 4608 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\nl.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\nl.lproj\SoftwareUpdateFilesLocalized. dll 5120 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ru.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ru.lproj\SoftwareUpdateFilesLocalized. dll 5120 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\sv.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\sv.lproj\SoftwareUpdateFilesLocalized. dll 4608 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\zh_CN.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\zh_CN.lproj\SoftwareUpdateFilesLocaliz ed.dll 4608 bytes executable
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\zh_TW.lproj 0 bytes
File C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\zh_TW.lproj\SoftwareUpdateFilesLocaliz ed.dll 4608 bytes executable
File C:\Program Files\AWS\WeatherBug 0 bytes
File C:\Program Files\Azureus\plugins 0 bytes
File C:\Program Files\Azureus\plugins\azplugins 0 bytes
File C:\Program Files\Azureus\plugins\azplugins\azplugins_2.1.1.jar 307835 bytes
File C:\Program Files\Azureus\plugins\azrating 0 bytes
File C:\Program Files\Azureus\plugins\azrating\azrating_1.3.1.jar 38172 bytes
File C:\Program Files\Azureus\plugins\azupdater 0 bytes
File C:\Program Files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.3.jar 5567 bytes
File C:\Program Files\Azureus\plugins\azupdater\plugin.properties 190 bytes
File C:\Program Files\Azureus\plugins\azupdater\Updater.jar 17703 bytes
File C:\Program Files\Azureus\Uninstall.exe 55391 bytes executable
File C:\Program Files\BAE\BAE.dll 94208 bytes
File C:\Program Files\BitLord\Downloads\531\531 Manual.pdf 7716370 bytes
File C:\Program Files\BitLord\Downloads\531\Torrent downloaded from Demonoid.com.txt 47 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\3. Hip Hop is dead skit.mp3 2526485 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\1. Guess Who's Back-Intro Produced By Play & Skills.mp3 4980961 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\10. game gonna cost a fee break.mp3 3718739 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\11. Ridin Overseas Feat. Akon Produced by Akon.mp3 3841506 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\12. Show Me What Ya Got Feat. Famous.mp3 5759431 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\13. Answer Machine 2.mp3 2624707 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\14. Chamillitary Radio Skit.mp3 2987823 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\15. International Money.mp3 2928256 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\16. I Run It.mp3 2700968 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\17. Get Ya Umbrellas Out.mp3 4191017 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\18. Get Ya Umbrella Break.mp3 2375504 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\19.Man Hold Up.mp3 4801742 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\2. Hip Hop Warning.mp3 4500293 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\20. Roll Call Reloaded.mp3 7393102 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\21. Outro.mp3 2102236 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\4. She Gonna Already Know.mp3 3572438 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\5. Let Em Know Produced By Kane.mp3 5054604 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\6. Tryin to Change me.mp3 3229179 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\7. Picture Me Rollin.mp3 3640869 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\8. Chamillionaire Speaks.mp3 2010314 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\9. Game Gonna Cost a Fee.mp3 3552063 bytes
File C:\Program Files\BitLord\Downloads\Chamillionaire - Mixtape Messiah pt 2\chamillionare-mixtape_messiah-sm-.jpg 4908 bytes
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
---- EOF - GMER 1.0.15 ----