At last, that took some doing......
here is gmer.txt
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-19 07:22:48
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\bryanc\LOCALS~1\Temp\kgrorpog.sys
---- System - GMER 1.0.15 ----
SSDT 8A67DA80 ZwAlertResumeThread
SSDT 8A681EC0 ZwAlertThread
SSDT 8A483EE8 ZwAllocateVirtualMemory
SSDT 8A42A170 ZwConnectPort
SSDT 8A439D20 ZwCreateMutant
SSDT 8A432918 ZwCreateThread
SSDT 8A5A6EC0 ZwFreeVirtualMemory
SSDT 8A42FEA8 ZwImpersonateAnonymousToken
SSDT 8A67F5F0 ZwImpersonateThread
SSDT 8A6283C8 ZwMapViewOfSection
SSDT 8A42A940 ZwOpenEvent
SSDT 8A5672E8 ZwOpenProcessToken
SSDT 8A403420 ZwOpenThreadToken
SSDT 87C1C4E0 ZwResumeThread
SSDT 8B00D678 ZwSetContextThread
SSDT 8A3F6378 ZwSetInformationProcess
SSDT 87B31910 ZwSetInformationThread
SSDT 8A445BC8 ZwSuspendProcess
SSDT 8B013388 ZwSuspendThread
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB204F0B0]
SSDT 8A67C450 ZwTerminateThread
SSDT 8A67D9A0 ZwUnmapViewOfSection
SSDT 8A48CEE8 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2C08 805044A4 4 Bytes CALL 14DA8CE7
.text ntkrnlpa.exe!ZwCallbackReturn + 2DB0 8050464C 4 Bytes CALL 14DA9CC3
.text ntkrnlpa.exe!ZwCallbackReturn + 3018 805048B4 4 Bytes CALL 68DA9187
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB827E380, 0x381B8D, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\SearchIndexer.exe[1704] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Ext2Fsd.SYS (Ext2 File System Driver for Windows/www.ext2fsd.com)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device rdpdr.sys (Microsoft RDP Device redirector/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
here is gmer.txt
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-19 07:22:48
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\bryanc\LOCALS~1\Temp\kgrorpog.sys
---- System - GMER 1.0.15 ----
SSDT 8A67DA80 ZwAlertResumeThread
SSDT 8A681EC0 ZwAlertThread
SSDT 8A483EE8 ZwAllocateVirtualMemory
SSDT 8A42A170 ZwConnectPort
SSDT 8A439D20 ZwCreateMutant
SSDT 8A432918 ZwCreateThread
SSDT 8A5A6EC0 ZwFreeVirtualMemory
SSDT 8A42FEA8 ZwImpersonateAnonymousToken
SSDT 8A67F5F0 ZwImpersonateThread
SSDT 8A6283C8 ZwMapViewOfSection
SSDT 8A42A940 ZwOpenEvent
SSDT 8A5672E8 ZwOpenProcessToken
SSDT 8A403420 ZwOpenThreadToken
SSDT 87C1C4E0 ZwResumeThread
SSDT 8B00D678 ZwSetContextThread
SSDT 8A3F6378 ZwSetInformationProcess
SSDT 87B31910 ZwSetInformationThread
SSDT 8A445BC8 ZwSuspendProcess
SSDT 8B013388 ZwSuspendThread
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB204F0B0]
SSDT 8A67C450 ZwTerminateThread
SSDT 8A67D9A0 ZwUnmapViewOfSection
SSDT 8A48CEE8 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2C08 805044A4 4 Bytes CALL 14DA8CE7
.text ntkrnlpa.exe!ZwCallbackReturn + 2DB0 8050464C 4 Bytes CALL 14DA9CC3
.text ntkrnlpa.exe!ZwCallbackReturn + 3018 805048B4 4 Bytes CALL 68DA9187
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB827E380, 0x381B8D, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\SearchIndexer.exe[1704] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Ext2Fsd.SYS (Ext2 File System Driver for Windows/www.ext2fsd.com)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device rdpdr.sys (Microsoft RDP Device redirector/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----