Hi Neal,
Thank you very much for your prompt response. Following your instructions, here are the new hijackthis.log and ewido result log, respectively:
Logfile of HijackThis v1.99.1
Scan saved at 11:52:19, on 04/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\OrCAD\license_manager\lmgrd.exe
C:\SYMANT~1\SYMANT~1\DefWatch.exe
C:\OrCAD\license_manager\cdslmd.exe
C:\NetTime\NeTmSvNT.exe
C:\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\SYMANT~1\SYMANT~1\vptray.exe
C:\NetTime\NetTime.exe
C:\D-Tools\daemon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fpdisp4 .exe
C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\wscntfy.exe
C:\palmOne\Hotsync.exe
C:\WinZip\WZQKPICK.EXE
C:\palmOne\LifeDriveMgrTray.exe
C:\Patrick\PortBlocker\PortBlocker.exe
C:\palmOne\PalmOneLiveConnect.exe
C:\ewido anti-malware\ewidoctrl.exe
C:\HJT\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\system32\nvms.dll (file missing)
O2 - BHO: NavHelper Class - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHelper.dll
O3 - Toolbar: EμOAENEś - {15ADF205-4C54-4cfe-AC88-1EA0BA6D06A0} - C:\Program Files\ScanToolbar\ScanBar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [vptray] C:\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NetTime] C:\NetTime\NetTime.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [FinePrint Dispatcher v4] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fpdisp4 .exe
O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 - HKLM\..\Run: [NetCheck] netcheck.exe
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDAT\Update.exe
O4 - HKLM\..\Run: [res] C:\WINDOWS\system32\res.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: LifeDrive? Manager.lnk
O4 - Startup: PortBlocker.exe.lnk = C:\Patrick\PortBlocker\PortBlocker.exe
O4 - Global Startup: HotSync Manager.lnk = C:\palmOne\Hotsync.exe
O4 - Global Startup: HotSync 資料同步管理員.lnk = C:\palmOne\Hotsync.exe
O4 - Global Startup: WinBoard AutoUpdate.lnk = ?
O4 - Global Startup: WinDraft AutoUpdate.lnk = C:\IVEX\Common\AUTOUPD.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: iSiloX Clipper - {C86027A6-12A1-4298-B6EA-A42AC6EE6C7C} - C:\iSilo\iSiloX\iSiloXIE.dll
O9 - Extra 'Tools' menuitem: iSiloX Clipper... - {C86027A6-12A1-4298-B6EA-A42AC6EE6C7C} - C:\iSilo\iSiloX\iSiloXIE.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: iSiloX Clipper - {C86027A6-12A1-4298-B6EA-A42AC6EE6C7C} - C:\iSilo\iSiloX\iSiloXIE.dll (HKCU)
O9 - Extra 'Tools' menuitem: iSiloX Clipper... - {C86027A6-12A1-4298-B6EA-A42AC6EE6C7C} - C:\iSilo\iSiloX\iSiloXIE.dll (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.i-lookup.com
O15 - Trusted Zone: *.offshoreclicks.com
O15 - Trusted Zone: *.teensguru.com
O15 - Trusted Zone: *.xxxtoolbar.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsu...?1134461126545
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsof...?1145840723788
O17 - HKLM\System\CCS\Services\Tcpip\..\{0CF8617E-8AB5-478A-8BB1-882EB47B93DC}: NameServer = 203.82.252.66,203.82.252.130,128.128.2.25
O17 - HKLM\System\CS1\Services\Tcpip\..\{0CF8617E-8AB5-478A-8BB1-882EB47B93DC}: NameServer = 203.82.252.66,203.82.252.130,128.128.2.25
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: winptp32 - C:\WINDOWS\SYSTEM32\winptp32.dll
O23 - Service: Cadence License Manager - GLOBEtrotter Software Inc. - C:\OrCAD\license_manager\lmgrd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\ewido anti-malware\ewidoctrl.exe
O23 - Service: NetTime (NetTimeSvc) - Subjective Software - C:\NetTime\NeTmSvNT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\SYMANT~1\SYMANT~1\Rtvscan.exe
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 11:50:27, 04/25/2006
+ Report-Checksum: 45E2D28D
+ Scan result:
HKLM\SOFTWARE\Classes\GoRSDN.ContextItem -> Adware.ISTBar : Ignored
HKLM\SOFTWARE\Classes\GoRSDN.ContextItem\CLSID -> Adware.ISTBar : Ignored
HKLM\SOFTWARE\Classes\GoRSDN.ContextItem\CurVer -> Adware.ISTBar : Ignored
HKLM\SOFTWARE\Classes\GoRSDN.ContextItem.1 -> Adware.ISTBar : Ignored
HKLM\SOFTWARE\Classes\NavExcel.NavHelper -> Adware.NavExcel : Ignored
HKLM\SOFTWARE\Classes\NavExcel.NavHelper\CLSID -> Adware.NavExcel : Ignored
HKLM\SOFTWARE\Classes\NavExcel.NavHelper\CurVer -> Adware.NavExcel : Ignored
HKLM\SOFTWARE\Classes\NavExcel.NavHelper.1 -> Adware.NavExcel : Ignored
HKLM\SOFTWARE\Classes\NLS.UrlCatcher -> Adware.NaviSearch : Ignored
HKLM\SOFTWARE\Classes\NLS.UrlCatcher\CLSID -> Adware.NaviSearch : Ignored
HKLM\SOFTWARE\Classes\NLS.UrlCatcher.1 -> Adware.NaviSearch : Ignored
HKLM\SOFTWARE\Classes\Pugi.PugiObj -> Adware.ISTBar : Ignored
HKLM\SOFTWARE\Classes\Pugi.PugiObj\CLSID -> Adware.ISTBar : Ignored
HKLM\SOFTWARE\Classes\Pugi.PugiObj\CurVer -> Adware.ISTBar : Ignored
HKLM\SOFTWARE\Classes\Pugi.PugiObj.1 -> Adware.ISTBar : Ignored
HKLM\SOFTWARE\Classes\WinRes.WindowsResources -> Adware.CoolWebSearch : Ignored
HKLM\SOFTWARE\Classes\WinRes.WindowsResources\CLSI D -> Adware.CoolWebSearch : Ignored
HKLM\SOFTWARE\Classes\WinRes.WindowsResources\CurV er -> Adware.CoolWebSearch : Ignored
HKLM\SOFTWARE\Classes\WinRes.WindowsResources.1 -> Adware.CoolWebSearch : Ignored
HKLM\SOFTWARE\Classes\WUSE.1 -> Adware.SaveNow : Ignored
HKLM\SOFTWARE\Classes\WUSN.1 -> Adware.SaveNow : Ignored
HKLM\SOFTWARE\Microsoft\VisualStudio\Analyzer\Even ts\{6C736D71-BCBF-11D0-8A23-00AA00B58E10} -> Adware.CoolWebSearch : Ignored
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall\NavHelper -> Adware.NavExcel : Ignored
HKLM\SOFTWARE\NavExcel -> Adware.NavExcel : Ignored
HKLM\SOFTWARE\NavExcel\NavHelper -> Adware.NavExcel : Ignored
HKLM\SOFTWARE\NavExcel\NavHelper\v2.0.4d -> Adware.NavExcel : Ignored
[548] C:\WINDOWS\system32\winptp32.dll -> Trojan.Agent.qt : Ignored
[1492] C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHelper.dll -> Adware.NavExcel : Ignored
[608] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe -> Adware.NavExcel : Ignored
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt -> TrackingCookie.Atdmt : Ignored
C:\Documents and Settings\Administrator\Cookies\administrator@c.enh ance[1].txt -> TrackingCookie.Enhance : Ignored
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\7R678WMW\Windows_XP_CD-Key_Generator_by_Ruteam_www[1].crack.cd_.zip/crack.exe -> Dropper.Agent.tz : Ignored
C:\Download\Software\CRM\MS CRM\bind_8300.exe -> Adware.AdHelper : Ignored
C:\Download\Software\VC++\wis125.exe/enrtins_final.exe -> Downloader.Small.buq : Ignored
C:\MP3 to WAV Decoder\installer_M3_2.exe -> Downloader.Adload.a : Ignored
C:\MP3 to WAV Decoder\NH20040517.4a.EE.exe/NHInstall.exe -> Adware.NavExcel : Ignored
C:\MP3 to WAV Decoder\VVSNInst.exe -> Adware.SaveNow : Ignored
C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe -> Adware.NavExcel : Ignored
C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHelper.dll -> Adware.NavExcel : Ignored
C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHUninstaller.exe -> Adware.NavExcel : Ignored
C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHUpdater.exe -> Adware.NavExcel : Ignored
C:\Program Files\NavExcel\NavHelper\v2.0.4d\v2.0.4d.cab/NHelper.dll -> Adware.NavExcel : Ignored
C:\Program Files\NavExcel\NavHelper\v2.0.4d\v2.0.4d.cab/NHUninstaller.exe -> Adware.NavExcel : Ignored
C:\Program Files\NavExcel\NavHelper\v2.0.4d\v2.0.4d.cab/NHUpdater.exe -> Adware.NavExcel : Ignored
C:\Program Files\NavExcel\NavHelper\v2.0.4d\v2.0.4d.cab/navapp.exe -> Adware.NavExcel : Ignored
C:\Program Files\ScanToolbar\ScanBar.dll -> Adware.MyTool : Ignored
C:\Program Files\ScanToolbar\uninst.exe -> Adware.AdHelper : Ignored
C:\Temp\Stores\Good\plm.rar/123.exe -> Backdoor.Hupigon.gt : Ignored
C:\WINDOWS\system32\mqexdlm.srg -> Adware.BargainBuddy : Ignored
C:\WINDOWS\system32\winptp32.dll -> Trojan.Agent.qt : Ignored
D:\Projects\SMS Server\Borland5\Two Providers\Code\SMSServer.exe -> Heuristic.Win32.Dialer : Ignored
D:\Projects\SMS Server\Borland5\Two Providers\Code\SMSC.ZIP/SMSServer.exe -> Heuristic.Win32.Dialer : Ignored
D:\BCB Components\Instrumentation\2004070613322819745.rar/CRACK\eatdewlab.exe -> Trojan.Agent.jh : Ignored
D:\BCB Components\Instrumentation\2004070613322819745.rar/CRACK\eatabvc.exe -> Trojan.Agent.jh : Ignored
D:\Patrick\BCB Components\Instrumentation\2004070613322819745.rar/CRACK\eatdewlab.exe -> Trojan.Agent.jh : Ignored
D:\Patrick\BCB Components\Instrumentation\2004070613322819745.rar/CRACK\eatabvc.exe -> Trojan.Agent.jh : Ignored
::Report End
The progress of BitDefender scanning is extremely slow therefore I have to leave it to be continued after hours. Hope the two logs above can let you have insight to the infection of my PC.
Thanks again for your support.