Sorry for the delays, I'm able to spend only abt an hour a day on the PC.
From tmrw(Friday) I should be able to spend more time at a stretch.
Thanks for all the help.
Here are the logs :
*****************Highjack This Starts**********************
Logfile of HijackThis v1.99.1
Scan saved at 5:14:54 PM, on 1/4/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
C:\Program Files\Common Files\Nokia\Services\ServiceLayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\ramleela\LOCALS~1\Temp\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://mail.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI
O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [system spool] C:\WINDOWS\System32\syspools.exe
O4 - HKLM\..\Run: [Microsoft Windows Update] C:\WINDOWS\system32\srshost.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0C718019-23C1-407E-AECA-C68F26A2E3C9}: NameServer = 61.1.96.69,61.1.96.71
O17 - HKLM\System\CS1\Services\Tcpip\..\{0C718019-23C1-407E-AECA-C68F26A2E3C9}: NameServer = 61.1.96.69,61.1.96.71
O17 - HKLM\System\CS2\Services\Tcpip\..\{0C718019-23C1-407E-AECA-C68F26A2E3C9}: NameServer = 61.1.96.69,61.1.96.71
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O21 - SSODL: fNSXYZETUiRVqZXRt - {8C5CFB61-26F6-51CB-D212-F7928FC48082} - C:\WINDOWS\System32\kdcy.dll (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe
*****************Highjack This END**********************
*****************Combifix Starts **********************
ComboFix 06-12-29W-BetaE2 - Running from: "C:\Documents and Settings\ramleela\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2006-12-04 to 2007-01-04 ))))))))))))))))))))))))))))))))))
2007-01-03 17:46 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-01-03 17:46 <DIR> d-------- C:\WINDOWS\LastGood
2007-01-02 18:09 <DIR> d-------- C:\DOCUME~1\ramleela\DoctorWeb
2007-01-02 17:28 <DIR> d-------- C:\WINDOWS\erdnt
2007-01-01 15:00 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2006-12-28 22:24 <DIR> d--hs---- C:\FOUND.000
2006-12-25 06:10 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2006-12-23 15:53 <DIR> d-------- C:\WINDOWS\BBSTORE
2006-12-17 11:48 5,935,148 --a------ C:\WINDOWS\macromix.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-27 08:51 -------- d-------- C:\Program Files\virtools
2006-11-26 13:12 -------- d-------- C:\Program Files\newsaver
2006-11-26 13:09 -------- d-------- C:\Program Files\idtrmaruti
2006-11-17 21:00 -------- d-------- C:\Program Files\directx
2006-11-17 20:59 -------- d-------- C:\Program Files\gamespy arcade
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"DVDBitSet"="\"C:\\Program Files\\HP CD-DVD\\Umbrella\\DVDBitSet.exe\" /NOUI"
"DVDTray"="\"C:\\Program Files\\HP CD-DVD\\Umbrella\\DVDTray.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_07\\bin\\jusched.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"DataLayer"="C:\\Program Files\\Nokia\\Nokia PC Suite 5\\DataLayer.exe"
"Nokia Tray Application"="C:\\Program Files\\Common Files\\Nokia\\NCLTools\\NclTray.exe"
"system spool"="C:\\WINDOWS\\System32\\syspools.exe"
"Microsoft Windows Update"="C:\\WINDOWS\\system32\\srshost.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"fNSXYZETUiRVqZXRt"="{8C5CFB61-26F6-51CB-D212-F7928FC48082}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Microsoft AUT Update"="MSlti32.exe"
"Microsoft Update"="msconfg.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Microsoft AUT Update"="MSlti32.exe"
"Microsoft Update"="msconfg.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWindowsUpdate"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWindowsUpdate"=dword:00000001
"NoSaveSettings"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Completion time: 07-01-04 1:06:06.95
C:\ComboFix2.txt ... 07-01-02 17:31
*****************Combifix END**********************
*****************Active Scan Starts**********************
Incident Status Location
Virus:bck/dumador.o Disinfected Operating system
Virus:trj/dumaru.q Disinfected Operating system
Virus:bck/dumador.da Disinfected Operating system
Virus:trj/qhost.gen Disinfected Operating system
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\ramleela\Cookies\
[email protected][2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\ramleela\Cookies\
[email protected][2].txt
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20070101-153751.backup
Virus:W32/Sdbot.ftp.worm Disinfected C:\WINDOWS\system32\a
Spyware:Cookie/Bridgetrack Not disinfected C:\FOUND.016\FILE0001.CHK
Spyware:Cookie/Serving-sys Not disinfected D:\WINDOWS\Cookies\
[email protected][1].txt
Spyware:Cookie/Com.com Not disinfected D:\WINDOWS\Cookies\
[email protected][2].txt
Spyware:Cookie/Serving-sys Not disinfected D:\WINDOWS\Cookies\
[email protected][2].txt
Hacktool:Exploit/iFrame Not disinfected Local Folders\Sent Items\Old Sent items\strange message from mail server - URGENT
*****************Active Scan END**********************
A0236957.DLL;C:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Probably BACKDOOR.Trojan;Incurable.Moved.;
A0237083.exe;C:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.HLLW.MyBot.based;Deleted.;
A0237084.exe;C:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Trojan.MulDrop.899;Deleted.;
A0237085.exe;C:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Trojan.MulDrop.899;Deleted.;
A0237086.exe;C:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;BackDoor.Dumaru;Deleted.;
A0237087.exe;C:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.HLLW.Agobot;Deleted.;
A0237088.dll;C:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Trojan.Proxy.133;Deleted.;
A0237089.exe;C:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.HLLW.Mixer.1;Deleted.;
A0237090.exe;C:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.HLLW.Agobot;Deleted.;
A0237091.exe;C:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;BackDoor.Dumaru;Deleted.;
A0237274.exe;D:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237275.Exe;D:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237276.exe;D:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237277.exe;D:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237278.exe;D:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237279.EXE;E:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237280.EXE;E:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237281.EXE;E:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237282.exe;E:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237283.exe;E:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237284.exe;E:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237285.exe;E:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237286.exe;E:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237287.exe;E:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237288.Exe;E:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237289.exe;E:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237290.exe;F:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237291.EXE;F:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237292.EXE;F:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237293.exe;F:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
A0237294.exe;F:\System Volume Information\_restore{56645FE7-6EF3-43CE-8B9F-EB34CA7BCDF5}\RP474;Win32.Dref;Cured.;
*****************Cure It Starts**********************
*****************Cure It END**********************