takže gmer, kompletní test bez files:
GMER 1.0.15.15281 - 
http://www.gmer.net
Rootkit scan 2010-03-25 08:41:15
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Kopecny\LOCALS~1\Temp\pxliafow.sys
---- System - GMER 1.0.15 ----
SSDT            \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys                                                                 ZwClose [0xA1A5888E]
SSDT            \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys                                                                 ZwCreateFile [0xA1A580EC]
SSDT            \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys                                                                 ZwCreateKey [0xA1A57DCE]
SSDT            \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys                                                                 ZwCreateSection [0xA1A59938]
SSDT            \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys                                                                 ZwDeleteKey [0xA1A57ED8]
SSDT            \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys                                                                 ZwDeleteValueKey [0xA1A57FC2]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwDuplicateObject [0xA12EB14C]
SSDT            \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys                                                                 ZwLoadDriver [0xA1A58BBC]
SSDT            \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys                                                                 ZwOpenFile [0xA1A583F4]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwOpenKey [0xA12EB64E]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwOpenProcess [0xA12EB08C]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwOpenThread [0xA12EB0F0]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwQueryValueKey [0xA12EB76E]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwRestoreKey [0xA12EB72E]
SSDT            \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys                                                                 ZwSetInformationFile [0xA1A58526]
SSDT            \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys                                                                 ZwSetValueKey [0xA1A57BFC]
SSDT            \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys                                                                 ZwTerminateProcess [0xA1A58B04]
SSDT            \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys                                                                 ZwWriteFile [0xA1A5870C]
---- User code sections - GMER 1.0.15 ----
.text           C:\WINDOWS\system32\SearchIndexer.exe[1632] kernel32.dll!WriteFile                                            7C810E27 7 Bytes  JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT             C:\WINDOWS\system32\services.exe[788] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW]  003D0002
IAT             C:\WINDOWS\system32\services.exe[788] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW]        003D0000
---- Devices - GMER 1.0.15 ----
AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                        aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                      aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                     aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                     aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                   aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Registry - GMER 1.0.15 ----
Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout                            15
Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota                               10000
Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler                                             yes
Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk                                            
Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout                            90
Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota                              10000
Reg             HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.§\OpenWithProgids@\xad\xa7\20_auto_file   
---- EOF - GMER 1.0.15 ----