Rootkit.Win32.Agent.akga - AKGA rootkit
A friend of mine was infected with this Rootkit, I thank him for contributing the sample.
He saved the sys file from a backup, and uploaded it for us at Rapidshare.
A thread discussing behavioral details, and removal instructions for the rootkit
Courtesy of Spybot S&D - http://forums.spybot.info/showthread.php?&t=55711
I tried viewing the SYS file with Wordpad (not a disassembler) and found APIs like IoDeleteDevice and APIs which are hidden.
The file infects ntoskrnl.exe, so it is clearly a rootkit - exhibiting kernel infection behavior.