ran combofix but got stuck on stage 4 for 3 hours so stopped it
then kept getting errors on windows say sed.exe and grex.exe (which google says is a worm) not responding all the time
ran comboxfix again and got log but all the time sed.exe not respsonding kept coming up
ComboFix 13-05-01.03 - Chris 02/05/2013 12:34:39.6.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3060.1670 [GMT 1:00]
Running from: c:\users\Chris\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1365455016.bdinstall.bin
c:\programdata\1367165827.bdinstall.bin
c:\programdata\1367166156.bdinstall.bin
c:\programdata\1367494000.bdinstall.bin
c:\windows\system32\spsys.log
.
.
((((((((((((((((((((((((( Files Created from 2013-04-02 to 2013-05-02 )))))))))))))))))))))))))))))))
.
.
2013-05-02 11:43 . 2013-05-02 11:43 -------- d-----w- c:\users\Chris\AppData\Local\temp
2013-05-02 11:43 . 2013-05-02 11:43 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-05-02 11:43 . 2013-05-02 11:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-04-28 16:22 . 2013-05-02 11:29 -------- d-----w- c:\program files\Bitdefender
2013-04-28 13:45 . 2013-04-30 19:23 -------- d-----w- c:\windows\system32\catroot2
2013-04-28 10:49 . 2013-04-28 12:14 181064 ----a-w- c:\windows\PSEXESVC.EXE
2013-04-28 10:49 . 2013-04-28 10:49 -------- d-----w- c:\program files\Tweaking.com
2013-04-28 04:15 . 2013-04-28 04:15 -------- d-----w- C:\_OTL
2013-04-26 20:44 . 2013-04-29 19:44 -------- d-----w- C:\Casino
2013-04-16 19:50 . 2013-04-16 19:50 -------- d-----w- c:\users\Chris\AppData\Local\cache
2013-04-16 19:47 . 2013-04-16 21:42 -------- d-----w- c:\users\Chris\AppData\Local\FullTiltPoker
2013-04-16 19:46 . 2013-04-30 22:45 -------- d-----w- c:\program files\Full Tilt Poker
2013-04-15 15:40 . 2013-04-15 15:40 -------- d-----w- c:\programdata\Licenses
2013-04-15 15:40 . 2011-11-04 04:13 1070352 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2013-04-15 15:40 . 2009-03-24 11:52 129872 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2013-04-10 05:00 . 2013-03-03 19:07 1082232 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-10 05:00 . 2013-03-11 13:25 3603816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-04-10 05:00 . 2013-03-11 13:25 3551080 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-04-10 05:00 . 2013-03-09 03:45 49152 ----a-w- c:\windows\system32\csrsrv.dll
2013-04-10 05:00 . 2013-03-09 01:28 64000 ----a-w- c:\windows\system32\smss.exe
2013-04-10 05:00 . 2013-03-08 03:52 2067968 ----a-w- c:\windows\system32\mstscax.dll
2013-04-10 05:00 . 2013-03-08 03:53 376320 ----a-w- c:\windows\system32\winsrv.dll
2013-04-10 05:00 . 2013-03-05 01:40 2049024 ----a-w- c:\windows\system32\win32k.sys
2013-04-09 21:58 . 2013-04-09 21:58 -------- d-----w- c:\program files\ERUNT
2013-04-09 03:39 . 2013-04-09 03:50 -------- d-----w- c:\programdata\Dumps
2013-04-08 21:10 . 2013-04-08 21:18 -------- d-----w- c:\programdata\BDLogging
2013-04-08 21:10 . 2007-04-11 10:11 511328 ----a-w- c:\windows\capicom.dll
2013-04-08 21:10 . 2009-07-14 22:27 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2013-04-08 21:04 . 2013-04-08 21:04 -------- d-----w- c:\users\Chris\AppData\Roaming\QuickScan
2013-04-08 21:03 . 2013-05-02 11:27 -------- d-----w- c:\program files\Common Files\Bitdefender
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-15 16:47 . 2012-12-13 19:48 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-04-15 16:47 . 2012-12-13 19:48 691592 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-04-04 13:50 . 2013-03-22 23:05 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-03-22 22:23 . 2011-12-26 22:04 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-03-22 22:23 . 2011-12-26 22:00 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-03-06 23:32 . 2012-09-23 23:33 228600 ----a-w- c:\windows\system32\aswBoot.exe
2013-03-03 19:50 . 2008-10-23 12:05 499712 ----a-w- c:\windows\system32\msvcp71.dll
2013-02-12 01:57 . 2013-03-17 23:23 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-07 12:15 . 2013-02-07 12:15 16024 ----a-w- c:\windows\system32\drivers\psi_mf_x86.sys
2013-02-05 17:53 . 2012-01-22 18:59 4659712 ----a-w- c:\windows\system32\Redemption.dll
2013-02-05 17:52 . 2013-02-05 17:52 90112 ----a-w- c:\windows\MAMCityDownload.ocx
2013-02-05 17:52 . 2013-02-05 17:52 330240 ----a-w- c:\windows\MASetupCaller.dll
2013-02-05 17:52 . 2013-02-05 17:52 30568 ----a-w- c:\windows\MusiccityDownload.exe
2013-02-05 17:52 . 2013-03-18 21:02 821824 ----a-w- c:\windows\system32\dgderapi.dll
2013-02-05 17:52 . 2013-03-18 21:02 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
2013-02-05 17:52 . 2013-03-18 21:02 20032 ----a-w- c:\windows\system32\drivers\dgderdrv.sys
2013-04-11 22:12 . 2013-04-11 22:12 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-25 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-25 170520]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2013-02-13 310128]
.
c:\users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2013-2-7 575000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-16 12:17 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-13 16:47]
.
2013-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-04-16 12:16]
.
2013-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-04-16 12:16]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = about:blank
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\zk7l92vm.default-1365749469265\
FF - ExtSQL: 2013-03-18 13:42; {DAC3F861-B30D-40dd-9166-F4E75327FAC7}; c:\programdata\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF - ExtSQL: 2013-04-15 16:46; {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}; c:\users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\zk7l92vm.default-1365749469265\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-05-02 12:43
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
Completion time: 2013-05-02 12:44:52
ComboFix-quarantined-files.txt 2013-05-02 11:44
.
Pre-Run: 188,021,313,536 bytes free
Post-Run: 188,280,819,712 bytes free
.
- - End Of File - - 495D11EE45675F9D646A5F0B67FAB68E