here is the start of the Gmer log of the W7 box, it's still running so I will let it run during the night & post the log when done.
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-06 22:25:52
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0001
Running: gmer.exe; Driver: C:\Users\admin\AppData\Local\Temp\aglorpod.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwSaveKey + 13CD 830729C9 1 Byte [06]
.text ntoskrnl.exe!KiDispatchInterrupt + 5A2 830924E2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text C:\windows\system32\DRIVERS\atikmdag.sys section is writeable [0x92C04000, 0x2DEB7A, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\windows\SYSTEM32\Rezip.exe[280] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\SYSTEM32\Rezip.exe[280] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Spybot - Search & Destroy 2\SDHookSvc.exe[392] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\Program Files\Spybot - Search & Destroy 2\SDHookSvc.exe[392] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe[488] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A70F5A
.text C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe[488] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AD0F5A
.text C:\windows\system32\wininit.exe[544] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\wininit.exe[544] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\system32\services.exe[592] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\services.exe[592] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\system32\lsass.exe[616] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\lsass.exe[616] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\system32\lsm.exe[624] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\lsm.exe[624] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\system32\svchost.exe[728] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\svchost.exe[728] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\system32\svchost.exe[792] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\svchost.exe[792] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[820] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[820] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\system32\atiesrxx.exe[844] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\atiesrxx.exe[844] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\system32\winlogon.exe[896] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\winlogon.exe[896] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\System32\svchost.exe[948] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\System32\svchost.exe[948] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\System32\svchost.exe[1012] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\System32\svchost.exe[1012] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\system32\svchost.exe[1064] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\windows\system32\svchost.exe[1064] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\system32\svchost.exe[1184] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\svchost.exe[1184] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\system32\svchost.exe[1272] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\svchost.exe[1272] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[1304] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe[1304] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe[1384] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe[1384] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\System32\spoolsv.exe[1416] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\System32\spoolsv.exe[1416] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\system32\svchost.exe[1444] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\svchost.exe[1444] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\Program Files\LSI SoftModem\agrsmsvc.exe[1548] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\Program Files\LSI SoftModem\agrsmsvc.exe[1548] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1568] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1568] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1600] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[1600] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\system32\atieclxx.exe[1628] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\windows\system32\atieclxx.exe[1628] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\System32\svchost.exe[1652] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\windows\System32\svchost.exe[1652] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1828] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1828] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1848] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1848] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[1908] kernel32.dll!SetUnhandledExceptionFilter 760CF4FB 4 Bytes [C2, 04, 00, 00]
.text C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe[1916] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe[1916] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1928] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\Program Files\ICQ6Toolbar\ICQ Service.exe[1928] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\windows\System32\svchost.exe[1940] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\windows\System32\svchost.exe[1940] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe[1968] KERNEL32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A80F5A
.text C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe[1968] KERNEL32.dll!CreateProcessA 76082082 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe[2112] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe[2112] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe[2320] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe[2320] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\system32\SearchIndexer.exe[2352] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\windows\system32\SearchIndexer.exe[2352] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2548] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2548] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe[2560] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe[2560] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe[2580] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe[2580] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\iPod\bin\iPodService.exe[2620] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\iPod\bin\iPodService.exe[2620] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\system32\svchost.exe[2636] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\windows\system32\svchost.exe[2636] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\servicing\TrustedInstaller.exe[2796] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\windows\servicing\TrustedInstaller.exe[2796] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Windows\system32\WUDFHost.exe[2824] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Windows\system32\WUDFHost.exe[2824] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\system32\svchost.exe[2880] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\windows\system32\svchost.exe[2880] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe[3084] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe[3084] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3092] KERNEL32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3092] KERNEL32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Users\admin\Desktop\gmer.exe[3148] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Users\admin\Desktop\gmer.exe[3148] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3340] KERNEL32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3340] KERNEL32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3488] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3488] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\system32\Dwm.exe[3500] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\windows\system32\Dwm.exe[3500] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\system32\taskhost.exe[3508] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\windows\system32\taskhost.exe[3508] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\system32\taskeng.exe[3608] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\windows\system32\taskeng.exe[3608] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3712] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3712] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\system32\svchost.exe[3912] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\windows\system32\svchost.exe[3912] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\windows\Explorer.EXE[3992] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\windows\Explorer.EXE[3992] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe[4056] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe[4056] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[4072] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[4072] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4292] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4292] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\iTunes\iTunesHelper.exe[4388] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\iTunes\iTunesHelper.exe[4388] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[4948] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\ESET\ESET Smart Security\egui.exe[4948] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Windows\WindowsMobile\wmdc.exe[5156] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Windows\WindowsMobile\wmdc.exe[5156] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
.text C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe[5904] kernel32.dll!CreateProcessW 7608204D 6 Bytes JMP 71A90F5A
.text C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe[5904] kernel32.dll!CreateProcessA 76082082 6 Bytes JMP 71AF0F5A
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Runtime de l’infrastructure de pilotes en mode noyau/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Runtime de l’infrastructure de pilotes en mode noyau/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004f halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Gestionnaire de filtres de système de fichiers Microsoft/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat eamon.sys (Amon monitor/ESET)
---- Threads - GMER 1.0.15 ----
Thread System [4:4204] A4D0EF2E
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002269ea6bb2
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002269ea93e9
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002269ea6bb2 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002269ea93e9 (not active ControlSet)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update@NextDetectionTime 2011-12-06 18:13:09
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Detect@LastSuccessTime 2011-12-05 20:33:03
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Download@LastSuccessTime 2011-12-03 08:08:24
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP@LastIndex 294