- an istsvc file thaht always here whene i deleted.
- many popus like ( sherch result for...., find a...at....)
- always hang up demand.
- my connection is slow and i believe that is related to an infection.
- the item 04 of my hijacjthis log always here when i fixed it, and i don't have mcaffe, navprotect, rant ...etc in my pc !!!)
- when i run a software a message related to an autoexec.NT. is apear and i can not run.
please help me.
this is my hijackthis log :
Logfile of HijackThis v1.99.0
Scan saved at 13:27:28, on 25/02/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\netdde.exe
D:\WINDOWS\system32\cisvc.exe
D:\WINDOWS\System32\imapi.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\vssvc.exe
D:\WINDOWS\System32\wbem\wmiapsrv.exe
D:\WINDOWS\System32\dmadmin.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\rant.exe
D:\WINDOWS\qniqtso.exe
D:\Program Files\ISTsvc\istsvc.exe
D:\WINDOWS\nvsvca32.exe
D:\WINDOWS\msexploren.exe
D:\WINDOWS\System32\navprotect.exe
D:\WINDOWS\System32\lah.exe
D:\WINDOWS\System32\mcafee32.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\system32\cidaemon.exe
D:\WINDOWS\System32\navprot32.exe
D:\Documents and Settings\Benteboula Toufik\Bureau\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:1030
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;cgi*.ebay.com;disney.go.com;msa_e1.ebay.com;rhapsody_app*.listen.com;<local>
O4 - HKLM\..\Run: [Norton AutoProtect] navprot32.exe
O4 - HKLM\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\Run: [Norton Personal Firewall] lah.exe
O4 - HKLM\..\Run: [rant] rant.exe
O4 - HKLM\..\Run: [antiware] D:\windows\system32\elitedez32.exe
O4 - HKLM\..\Run: [×jœS˜‰ØUÑñT»óonÄ;D:\Program Files\ISTsvc\istsvc.exe] D:\WINDOWS\qniqtso.exe
O4 - HKLM\..\Run: [McAfee Windows Protection] mcafee32.exe
O4 - HKLM\..\Run: [IST Service] D:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [nvsvca32] D:\WINDOWS\nvsvca32.exe
O4 - HKLM\..\Run: [SvcH0st] D:\WINDOWS\msexploren.exe /i
O4 - HKLM\..\RunServices: [Norton Personal Firewall] lah.exe
O4 - HKLM\..\RunServices: [Norton AutoProtect] navprot32.exe
O4 - HKLM\..\RunServices: [rant] rant.exe
O4 - HKLM\..\RunServices: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\RunServices: [McAfee Windows Protection] mcafee32.exe
O4 - HKCU\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKCU\..\Run: [Norton Personal Firewall] lah.exe
O4 - HKCU\..\Run: [Norton AutoProtect] navprot32.exe
O4 - HKCU\..\Run: [rant] rant.exe
O4 - HKCU\..\Run: [McAfee Windows Protection] mcafee32.exe
O8 - Extra context menu item: Download All by FlashGet - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\Program Files\FlashGet\jc_link.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{A760F5A3-BB80-4D42-862C-AB65B3D2B149}: NameServer = 81.22.91.164 81.22.90.29
O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - D:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements - Unknown - D:\WINDOWS\system32\services.exe
O23 - Service: Service COM de gravage de CD IMAPI - Unknown - D:\WINDOWS\System32\imapi.exe
O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - D:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: DDE réseau - Unknown - D:\WINDOWS\system32\netdde.exe
O23 - Service: DSDM DDE réseau - Unknown - D:\WINDOWS\system32\netdde.exe
O23 - Service: Plug-and-Play - Unknown - D:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance - Unknown - D:\WINDOWS\system32\sessmgr.exe
O23 - Service: Prise en charge des cartes à puces - Unknown - D:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Carte à puce - Unknown - D:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Journaux et alertes de performance - Unknown - D:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Cliché instantané de volume - Unknown - D:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI - Unknown - D:\WINDOWS\System32\wbem\wmiapsrv.exe
O23 - Service: Network Security Service (NSS) - Unknown - D:\WINDOWS\javaqr.exe (file missing)