the second log from roguekiller was the scan and delete with the registry option
RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback :
http://www.geekstogo.com/forum/files/file/413-roguekiller/Website :
http://tigzy.geekstogo.com/roguekiller.phpBlog :
http://tigzyrk.blogspot.com/Operating System : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User : Sherra [Admin rights]
Mode : Remove -- Date : 06/08/2013 19:49:39
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 7 ¤¤¤
[TASK][SUSP PATH] At1.job : C:\Users\Sherra\AppData\Roaming\wmplayer.exe /help
[TASK][SUSP PATH] At1 : C:\Users\Sherra\AppData\Roaming\wmplayer.exe /help
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (hxxp=127.0.0.1:63475) -> NOT REMOVED, USE PROXYFIX
[HJPOL] HKCU\[...]\System : disableregistrytools (0) -> DELETED
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> DELETED
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
[ZeroAccess][JUNCTION] C:\Windows\$NtUninstallKB46385$ >> \systemroot\system32\config --> REMOVED
[Del.Parent][FOLDER] ROOT : C:\Windows\$NtUninstallKB46385$\1053783041\L --> REMOVED
[Del.Parent][FOLDER] ROOT : C:\Windows\$NtUninstallKB46385$\1053783041\U --> REMOVED
[Del.Parent][FOLDER] ROOT : C:\Windows\$NtUninstallKB46385$\1053783041 --> REMOVED
[Del.Parent][FILE] 3721021429 : C:\Windows\$NtUninstallKB46385$\3721021429 [-] --> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\Windows\$NtUninstallKB46385$ --> REMOVED
¤¤¤ Driver : [LOADED] ¤¤¤
SSDT[18] : NtAllocateVirtualMemory @ 0x83E504AB -> HOOKED (Unknown @ 0x86AAB818)
SSDT[72] : NtCreateProcess @ 0x83E99D63 -> HOOKED (Unknown @ 0x86AB0620)
SSDT[73] : NtCreateProcessEx @ 0x83E99DAE -> HOOKED (Unknown @ 0x86AA92E8)
SSDT[78] : NtCreateThread @ 0x83E99B98 -> HOOKED (Unknown @ 0x86AABAE8)
SSDT[255] : NtQueueApcThread @ 0x83DB9837 -> HOOKED (Unknown @ 0x86AAB890)
SSDT[261] : NtReadVirtualMemory @ 0x83DDA986 -> HOOKED (Unknown @ 0x86AAB728)
SSDT[289] : NtSetContextThread @ 0x83E9A867 -> HOOKED (Unknown @ 0x86AAB980)
SSDT[305] : NtSetInformationProcess @ 0x83E1C858 -> HOOKED (Unknown @ 0x86AA91F8)
SSDT[306] : NtSetInformationThread @ 0x83E0123D -> HOOKED (Unknown @ 0x86AAB9F8)
SSDT[330] : NtSuspendProcess @ 0x83E9B457 -> HOOKED (Unknown @ 0x86AA9180)
SSDT[331] : NtSuspendThread @ 0x83DA292D -> HOOKED (Unknown @ 0x86AAB908)
SSDT[334] : NtTerminateProcess @ 0x83DF90D3 -> HOOKED (Unknown @ 0x86AA9270)
SSDT[335] : NtTerminateThread @ 0x83E244DF -> HOOKED (Unknown @ 0x86AABA70)
SSDT[358] : NtWriteVirtualMemory @ 0x83E158BD -> HOOKED (Unknown @ 0x86AAB7A0)
SSDT[382] : NtCreateThreadEx @ 0x83E23F94 -> HOOKED (Unknown @ 0x86AAB638)
SSDT[383] : NtCreateUserProcess @ 0x83DD1BA6 -> HOOKED (Unknown @ 0x86AAB6B0)
S_SSDT[317] : NtUserAttachThreadInput -> HOOKED (Unknown @ 0x894FE420)
S_SSDT[397] : NtUserGetAsyncKeyState -> HOOKED (Unknown @ 0x895525F8)
S_SSDT[428] : NtUserGetKeyboardState -> HOOKED (Unknown @ 0x894FE3A8)
S_SSDT[430] : NtUserGetKeyState -> HOOKED (Unknown @ 0x89552670)
S_SSDT[479] : NtUserMessageCall -> HOOKED (Unknown @ 0x8955E460)
S_SSDT[497] : NtUserPostMessage -> HOOKED (Unknown @ 0x89566BD8)
S_SSDT[498] : NtUserPostThreadMessage -> HOOKED (Unknown @ 0x89566B60)
S_SSDT[573] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0x89694CF0)
S_SSDT[576] : NtUserSetWinEventHook -> HOOKED (Unknown @ 0x894D66E8)
¤¤¤ Extern Hives: ¤¤¤
-> D:\windows\system32\config\SOFTWARE
-> D:\windows\system32\config\SYSTEM
-> D:\Users\Default\NTUSER.DAT
¤¤¤ Infection : ZeroAccess ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: WDC WD50 00AAKS-22YGA SCSI Disk Device +++++
--- User ---
[MBR] 8457d23c1b7eaf08c1b808635ac7db80
[BSP] 6dcd7dfb57a43d79b9bad5cc99f31bd2 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 11209 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 22956885 | Size: 465728 Mo
User = LL1 ... OK!
Error reading LL2 MBR!
Finished : << RKreport[2]_D_06082013_02d1949.txt >>
RKreport[1]_S_06082013_02d1945.txt ; RKreport[2]_D_06082013_02d1949.txt
[recovering disk space, attachment deleted by admin]