I found similar files in those two locations, but the names don't match exactly. Here's what I found:
ConfigOCXDos32.exe-up.txt
_wrar370.exe
Thanks for the info on System Restore. I'm guessing I need to go back and do that with another clean?
I tried attaching the host files you asked for, but it says I'm not allowed to attach that type of file. Any ideas?
I ran the two programs requested. Here's the combofix log:
ComboFix 07-11-02.3 - Sadler 2007-11-02 11:35:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.201 [GMT -6:00]
Running from: C:\Documents and Settings\Power User\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kdick.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-02 to 2007-11-02 )))))))))))))))))))))))))))))))
.
2007-11-02 11:33 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-01 13:35 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-11-01 13:35 <DIR> d-------- C:\Documents and Settings\Power User\Application Data\SUPERAntiSpyware.com
2007-11-01 13:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-01 13:33 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-31 10:35 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-10-31 10:35 298,104 --a------ C:\WINDOWS\system32\imon.dll
2007-10-31 10:35 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2007-10-26 16:17 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-17 16:37 <DIR> d-------- C:\Downloads
2007-10-17 10:37 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-10-17 10:32 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-10-17 10:32 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-26 21:01 --------- d-----w C:\Documents and Settings\Power User\Application Data\U3
2007-10-25 15:32 --------- d-----w C:\Documents and Settings\Power User\Application Data\AdobeUM
2007-10-17 22:47 359,808 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2007-10-16 19:47 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-17 23:20 --------- d-----w C:\Documents and Settings\Power User\Application Data\.ABC
2007-09-17 22:29 --------- d-----w C:\Program Files\LogMeIn
2007-09-17 21:05 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-09-13 22:01 --------- d-----w C:\Program Files\ABC
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 08:59]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 08:59]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-10 09:18]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 14:25]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 14:45]
"ControlCenter2.0"="C:\Program Files\SP\ControlCenter2\brctrcen.exe" [2006-09-07 17:45]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-10-31 10:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-05-25 15:22 63040 C:\WINDOWS\system32\LMIinit.dll
R0 hotcore3;hotcore3;C:\WINDOWS\system32\drivers\hotcore3.sys
R1 Uim_IM;UIM Drive Backup Image Plugin;C:\WINDOWS\system32\Drivers\Uim_IM.sys
R1 UimBus;Universal Image Mounter Controller;C:\WINDOWS\system32\DRIVERS\UimBus.sys
R2 LMIInfo;LogMeIn Kernel Information Provider;\??\C:\Program Files\LogMeIn\x86\RaInfo.sys
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
R2 Nhksrv;Netropa NHK Server;C:\WINDOWS\Nhksrv.exe
R3 BrScnUsb;SP USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys
R3 BrSerIf;SP MFC Serial Port Interface WDM Driver;C:\WINDOWS\system32\Drivers\BrSerIf.sys
R3 BrUsbSer;SP MFC USB Serial WDM Driver;C:\WINDOWS\system32\Drivers\BrUsbSer.sys
R3 lmimirr;lmimirr;C:\WINDOWS\system32\DRIVERS\lmimirr.sys
R3 Msikbd2k;DellTouch;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys
S3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys
S3 BioNT_BS;BioNT_BS;\??\C:\Program Files\Paragon Software\Drive Backup\BlueScrn\BioNT_bs.sys
S3 brfilt;Brother MFC Filter Driver;C:\WINDOWS\system32\Drivers\Brfilt.sys
S3 brparimg;Brother Multi Function Parallel Image driver;C:\WINDOWS\system32\DRIVERS\BrParImg.sys
S3 BrParWdm;Brother WDM Parallel Driver;C:\WINDOWS\system32\Drivers\BrParwdm.sys
S3 BrSerWdm;SP WDM Serial driver;C:\WINDOWS\system32\Drivers\BrSerWdm.sys
S3 NAL;Nal Service ;\??\C:\WINDOWS\system32\Drivers\iqvw32.sys
S3 USB-100;Realtek RTL8150 USB 10/100 Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\RTL8150.SYS
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9bb588fe-c0fc-11db-a8eb-000874382a49}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-11-02 11:41:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-02 11:43:53 - machine was rebooted
.
--- E O F ---