Hi Derek,
Thanks for your fast answer!
Here it is the ComboFix report + the new HijackThis log. Any ideas?
Best regards,
Paco
ComboFix 08-01-15.3 - Lurdes 2008-01-15 1:37:22.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.600 [GMT 1:00]
Running from: C:\Documents and Settings\Lurdes\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SeaMonkey\SEAMON~1 .EXE
C:\Program Files\SeaMonkey\SeaMonkey.exe
C:\WINDOWS\recover.reg
C:\WINDOWS\system32\awtss.dll
C:\WINDOWS\system32\awtss.exe
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\quygyffo.exe
C:\WINDOWS\system32\sstwa.ini
C:\WINDOWS\system32\sstwa.ini2
C:\WINDOWS\system32\urqrpqn.dll
<pre>
C:\Program Files\Common Files\Real\Update_OB\realsched .exe ---> realsched.exe
C:\Program Files\SeaMonkey\SeaMonkey .exe ---> SeaMonkey.exe
C:\Program Files\SeaMonkey\SEAMON~1 .EXE ---> QooBox
C:\WINDOWS\system32\ctfmon .exe ---> QooBox
</pre>
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-12-15 to 2008-01-15 )))))))))))))))))))))))))))))))
.
2008-01-15 01:33 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-12 19:34 . 2008-01-12 19:34 <DIR> d-------- C:\Program Files\Real
2008-01-12 19:34 . 2008-01-12 19:34 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-01-12 19:34 . 2008-01-12 19:34 <DIR> d-------- C:\Program Files\Common Files\Real
2008-01-12 19:09 . 2008-01-12 19:09 <DIR> d-------- C:\Program Files\FLV Player
2008-01-10 09:43 . 2008-01-10 09:43 20 --a------ C:\WINDOWS\hppsapp.INI
2008-01-07 13:52 . 2008-01-07 13:52 <DIR> d-------- C:\Program Files\CCleaner
2007-12-23 21:05 . 2007-12-23 21:05 <DIR> d-------- C:\Program Files\DVDFabHDDecrypter4
2007-12-22 15:00 . 2007-12-22 15:00 <DIR> d-------- C:\Program Files\DVDStyler
2007-12-22 13:23 . 2007-12-22 13:23 <DIR> d-------- C:\Program Files\IfoEdit
2007-12-22 13:21 . 2007-12-22 14:53 432 --a------ C:\WINDOWS\IfoEdit.INI
2007-12-21 23:19 . 2007-12-21 23:19 <DIR> d-------- C:\Program Files\RipIt4Me
2007-12-21 23:18 . 2007-12-23 20:46 <DIR> d-------- C:\Documents and Settings\Lurdes\Application Data\RipIt4Me
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 00:47 --------- d-----w C:\Program Files\SeaMonkey
2008-01-14 20:22 --------- d-----w C:\Program Files\Sonic
2008-01-13 21:12 --------- d-----w C:\Program Files\SyncBack
2008-01-13 17:48 118,784 ----a-w C:\WINDOWS\SeaMonkeyUninstall.exe
2008-01-13 17:47 118,784 ----a-w C:\WINDOWS\GREUninstall.exe
2008-01-13 16:54 --------- d-----w C:\Program Files\QuickTime
2008-01-13 16:53 --------- d-----w C:\Program Files\Windows Defender
2007-12-30 19:52 --------- d-----w C:\Documents and Settings\Lurdes\Application Data\OpenOffice.org2
2007-12-23 20:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-12-16 12:32 --------- d-----w C:\Program Files\IrfanView
2007-12-12 00:26 --------- d-----w C:\Program Files\Avi2Dvd
2007-12-11 20:54 --------- d-----w C:\Program Files\AviSynth 2.5
2007-12-04 19:42 --------- d-----w C:\Program Files\Mathematics Worksheet Factory Deluxe 3.0
2007-12-04 12:50 --------- d-----w C:\Program Files\Supera
2007-12-02 23:44 --------- d-----w C:\Program Files\Ares
2007-12-01 08:13 --------- d-----w C:\Program Files\SnagIt32
2007-11-27 21:52 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-25 20:01 --------- d-----w C:\Program Files\Java
2007-09-30 07:35 48,504 ----a-w C:\Documents and Settings\Lurdes\Application Data\GDIPFONTCACHEV1.DAT
2007-03-15 14:31 18,297,362 ----a-w C:\Program Files\geogebra_setup_jre.exe
2006-12-20 19:05 1,565 ----a-w C:\Program Files\install.jnlp
2006-12-02 09:15 1,584 ----a-w C:\Program Files\author.jnlp
2007-06-01 21:30 56 --sh--r C:\WINDOWS\system32\81DC94357C.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00 15360]
"SeaMonkey Quick Launch"="C:\Program Files\SeaMonkey\SeaMonkey.exe" [2008-01-15 00:05 151552]
"Mozilla Quick Launch"="C:\PROGRA~1\SEAMON~1\SEAMON~1.exe" [2008-01-15 00:05 151552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 23:30 282624 C:\WINDOWS\stsystra.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-15 00:05 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 05:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2003-07-15 05:53 34880]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-11-27 22:52:34]
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 18:28:28]
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-09-30 09:10:20]
Inicio r pido de Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 08:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
R1 tidnet;TID NDIS Protocol Driver;C:\WINDOWS\system32\DRIVERS\tidnet.sys [2006-07-12 13:23]
R2 hnmwrlspkt;HomeNet Manager Wireless Protocol;C:\WINDOWS\system32\DRIVERS\hnm_wrls_pkt.sys [2006-01-12 22:27]
R2 wsppkt;Wireless Security Protocol;C:\WINDOWS\system32\DRIVERS\wsp_pkt.sys [2006-01-12 22:29]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3ff48c3a-88b7-11dc-923a-0016cffe2d4c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4938cf0a-4f4a-11dc-91a1-0016cffe2d4c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4938cf0c-4f4a-11dc-91a1-0016cffe2d4c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{777a9a22-4853-11dc-9192-0016cffe2d4c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{777a9a24-4853-11dc-9192-0016cffe2d4c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9613c76f-88aa-11dc-9239-0016cffe2d4c}]
\Shell\AutoRun\command - F:\AutoRun.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-15 00:50:21 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-15 01:48:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-15 1:50:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-15 00:50:39
.
2008-01-11 07:26:21 --- E O F ---
[attachment deleted by admin]