ok, I ran RogueKiller again. Then I hit registry key and this is what it said:
RogueKiller V7.3.2 [03/20/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Dawn [Admin rights]
Mode: Scan -- Date: 03/23/2012 02:15:49
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 10 ¤¤¤
[BLACKLIST] HKLM\[...]\services : SSHNAS (%SystemRoot%\system32\svchost.exe -k netsvcs) -> FOUND
[BLACKLIST] HKLM\[...]\Root : LEGACY_SSHNAS () -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowUser (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowMyPics (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowMyMusic (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
::1 localhost
91.212.127.226 osguard-pro.microsoft.com
91.212.127.226 osguard-pro.com
91.212.127.226 www.osguard-pro.com
127.0.0.1 spe.atdmt.com
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: Maxtor 6Y080P0 +++++
--- User ---
[MBR] d9d7314065b6f4cbd1280aa02ca2fdbe
[BSP] 2de82c202d5e8a2d8b91600c8f20d280 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 642600 | Size: 77846 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] efd1d876a949b5802ad6462235b24fae
[BSP] 2de82c202d5e8a2d8b91600c8f20d280 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 642600 | Size: 77846 Mo
1 - [ACTIVE] NTFS (0x17) [HIDDEN!] Offset (sectors): 160071660 | Size: 7 Mo
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Then I checked all entries, hit delete and this report was given:
RogueKiller V7.3.2 [03/20/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Dawn [Admin rights]
Mode: Remove -- Date: 03/23/2012 02:19:50
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 10 ¤¤¤
[BLACKLIST] HKLM\[...]\services : SSHNAS (%SystemRoot%\system32\svchost.exe -k netsvcs) -> DELETED
[BLACKLIST] HKLM\[...]\Root : LEGACY_SSHNAS () -> DELETED
[HJ] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowUser (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyPics (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyMusic (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
::1 localhost
91.212.127.226 osguard-pro.microsoft.com
91.212.127.226 osguard-pro.com
91.212.127.226 www.osguard-pro.com
127.0.0.1 spe.atdmt.com
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: Maxtor 6Y080P0 +++++
--- User ---
[MBR] d9d7314065b6f4cbd1280aa02ca2fdbe
[BSP] 2de82c202d5e8a2d8b91600c8f20d280 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 642600 | Size: 77846 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] efd1d876a949b5802ad6462235b24fae
[BSP] 2de82c202d5e8a2d8b91600c8f20d280 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 642600 | Size: 77846 Mo
1 - [ACTIVE] NTFS (0x17) [HIDDEN!] Offset (sectors): 160071660 | Size: 7 Mo
Finished : << RKreport[3].txt >>
RKreport[2].txt ; RKreport[3].txt
Last, I hit Hosts tab and then host fix button and this report was given:
RogueKiller V7.3.2 [03/20/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Dawn [Admin rights]
Mode: HOSTSFix -- Date: 03/23/2012 02:20:19
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
::1 localhost
91.212.127.226 osguard-pro.microsoft.com
91.212.127.226 osguard-pro.com
91.212.127.226 www.osguard-pro.com
127.0.0.1 spe.atdmt.com
¤¤¤ Resetted HOSTS: ¤¤¤
127.0.0.1 localhost
Finished : << RKreport[4].txt >>
RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt
Thanks again for all the help! Will await further instructions.
-Dawn