Oh shoot, Took a deeper look it goes farther. I deleted some more geyekrXXXXX keys and found VMLIV and ZQTY services. here is partial log of a part of gmer.
GMER 1.0.15.15077 [gzwoy4u6.exe] -
http://www.gmer.netRootkit scan 2009-09-02 20:46:29
Windows 6.0.6002 Service Pack 2
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet004\Services\VMLIV@Type 272
Reg HKLM\SYSTEM\ControlSet004\Services\VMLIV@Start 4
Reg HKLM\SYSTEM\ControlSet004\Services\VMLIV@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet004\Services\VMLIV@ImagePath C:\Users\JUSTYN\AppData\Local\Temp\VMLIV.exe
Reg HKLM\SYSTEM\ControlSet004\Services\VMLIV@DisplayName VMLIV
Reg HKLM\SYSTEM\ControlSet004\Services\VMLIV@ObjectName LocalSystem
---- EOF - GMER 1.0.15 ----