What exactly do you mean not a normal system file? Possibly some spyware or something? Anyway, here is the logfile.
Logfile of HijackThis v1.97.7
Scan saved at 4:57:07 PM, on 2/25/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\ZONELA~1\ZONEA
C:\WINDOWS\System32\ctfmon
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\inetsr
C:\PROGRA~1\Iomega\System3
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc3
C:\PROGRA~1\NORTON~1\SPEED
C:\WINDOWS\System32\svchos
C:\Program Files\Belkin Bulldog Plus\upsd.exe
C:\WINDOWS\system32\ZoneLa
C:\WINDOWS\System32\MsPMSP
C:\Program Files\Iomega\AutoDisk\ADSe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Patrick\Desktop\H
R0 - HKCU\Software\Microsoft\In
R3 - URLSearchHook: (no name) - {6CC1C918-AE8B-4373-A5B4-2
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEA
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.d
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.d
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
O16 - DPF: {3E68E405-C6DE-49FF-83AE-4
O16 - DPF: {41F17733-B041-4099-A042-B
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-3
O16 - DPF: {90A29DA5-D020-4B18-8660-6
O16 - DPF: {9F1C11AA-197B-4942-BA54-4
O16 - DPF: {A1337CC4-FF8E-11D1-9C48-0
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-0
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O17 - HKLM\System\CCS\Services\T
Main Topics
Browse All Topics





by: LucFPosted on 2004-02-25 at 13:38:14ID: 10454513
Hi pitbullhead,
ownload/dl hijackthis .shtml
What if I told you THE "System" process is not a normal system file??
Try this tool and post the logfile:
HijackThis : http://www.webattack.com/d
Greetings,
LucF