Funny read this post an hour ago, and half an hour ago had a machine that came in that comes up clean on every scan except AVG, which shows a virus attached to explorer, svchost, and one other windows system process. I found the rootkit in sys32/drivers and had already deleted it. But AVG was still tripping along with not being able to do windows updates. Saw on another forum talking about the exact same rootkit as this article, and to run tdsskiller from kaspersky, and it popped it out of the mbr. The infected machine was xp pro though, not anything x64