Hello Gentlemen,
I came across the same “getpadd.sys” file on my 2 month old ASUS notebook. I discovered that the file didn’t reside in the path the antivirus told me, and was actually in a folder named ABLKSR, with an .exe by the same name. I started researching both files and the folder, and found very little about “getpadd.sys” file, basically the same as you all have. However, the folder and the .exe file was part of my power management software for my ASUS notebook. After running a boot-time scan, nothing was found. I then thought maybe the file may have been deleted, as I told it to. When my system came back up, I found the file was still there. Thinking on this for a little bit, I remembered that at the time that I got this alert, I had reconnected my AC power to my notebook in order to recharge my battery, and since I was coming up from a reboot, this would explain why it was running at that current time. After running a scan with SUPERAntiSpyware, I found no spyware on my system except for tracking cookies, which isn’t uncommon. Once that was done, I ran another anti-virus scan to determine if this file was still running, getting negative results. I concluded that the reason it was running at that time of the alert was due to a change in my power management settings being activated during the reboot.
This file may be a rootkit, as Avast has suggested, I’m not posting to dispute that. I would suggest trying to recall if it is possible that the file is part of power management software or other system software that may have been running when you got the alert. Whether or not you should delete this file, I would suggest consider what was happening that may have cause this file to be activated in the first place. In my case, I found enough evidence to tell me I didn’t need to delete this file, so ignoring the alert would be acceptable. Being a freelance computer consultant with high security standards, I would recommend taking any antivirus' advice, but continue to investigate your situation until you feel safe in your conclusions.