Hello, I have noticed that HijackThis, being a 32 bit application, cannot read into c:\windows\system32 folder. So all entries from this folder are reported as missing by the software.
Is there a way to fix this?
Here's an example log of mine, all those missing files are actually not missing at all.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21.57.36, on 21/09/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\AASP\1.00.46\aa
Center.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Users\Fuzzeelord\AppDat
a\Local\Go
ogle\Updat
e\GoogleUp
date.exe
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe
C:\Program Files\ASUS\Ai Suite\AiGear3\CpuPowerMoni
tor.exe
C:\Windows\SysWOW64\Ctxfih
lp.exe
C:\Program Files (x86)\UpsPilot\Winpower.ex
e
C:\Utility\Manutenzione\Av
ira\AntiVi
r PersonalEdition Premium\avgnt.exe
C:\Program Files (x86)\Java\jre1.6.0_07\bin
\jusched.e
xe
C:\Program Files (x86)\UpsPilot\jre\bin\jav
aw.exe
C:\Windows\SysWOW64\CTXFIS
PI.EXE
C:\Program Files (x86)\Common Files\Grass Valley\ProCoder 3\Kernel\PNXSERVR.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Utility\Internet\eMule\
emule.exe
C:\Utility\totalcmd\TOTALC
MD.EXE
C:\Utility\Internet\TVUPla
yer\TVUPla
yer.exe
C:\Utility\Utilities\Hijac
kThis\Hija
ckThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-1
7B458C2A3A
8} - C:\Utility\Internet\Intern
et Download Manager\IDMIECC.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5
B79BFDFEA6
0} - C:\Utility\Internet\BitCom
et\tools\B
itCometBHO
_1.2.6.26.
dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~2\SPYBOT~1\SDHel
per.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - C:\Program Files (x86)\Java\jre1.6.0_07\bin
\ssv.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-D
FEE4931A4A
A} - C:\Program Files (x86)\AskSBar\bar\1.bin\AS
KSBAR.DLL (file missing)
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-D
FEE4931A4A
A} - C:\Program Files (x86)\AskSBar\bar\1.bin\AS
KSBAR.DLL (file missing)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundTray] "C:\Program Files (x86)\Analog Devices\SoundMAX\SoundTray
.exe"
O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe"
O4 - HKLM\..\Run: [CPU Power Monitor] "C:\Program Files\ASUS\Ai Suite\AiGear3\CpuPowerMoni
tor.exe"
O4 - HKLM\..\Run: [Cpu Level Up help] C:\Program Files\ASUS\Ai Suite\CpuLevelUpHelp.exe
O4 - HKLM\..\Run: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Winpower] "C:\Program Files (x86)\UpsPilot\Winpower.ex
e"
O4 - HKLM\..\Run: [avgnt] "C:\Utility\Manutenzione\A
vira\AntiV
ir PersonalEdition Premium\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_07\bin
\jusched.e
xe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-
Static\CLI
Start.exe"
MSRun
O4 - HKLM\..\Run: [NexusServer] "C:\Program Files (x86)\Common Files\Grass Valley\ProCoder 3\Kernel\PNXSERVR.exe" -SelfLaunch
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCe
nter
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Fuzzeelord\AppDa
ta\Local\G
oogle\Upda
te\GoogleU
pdate.exe"
/c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCe
nter (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O4 - Startup: AutorunsDisabled
O8 - Extra context menu item: Download All Links with IDM - C:\Utility\Internet\Intern
et Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Utility\Internet\Intern
et Download Manager\IEExt.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~2\MICROS~1
\OFFICE11\
EXCEL.EXE/
3000
O8 - Extra context menu item: Scarica tutti i video usando BitComet - res://C:\Utility\Internet\
BitComet\B
itComet.ex
e/AddVideo
.htm
O8 - Extra context menu item: Scarica tutto usando BitComet - res://C:\Utility\Internet\
BitComet\B
itComet.ex
e/AddAllLi
nk.htm
O8 - Extra context menu item: Scarica usando &BitComet - res://C:\Utility\Internet\
BitComet\B
itComet.ex
e/AddLink.
htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\PROGRA~2\Java\JRE16~1.0
_0\bin\ssv
.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\PROGRA~2\Java\JRE16~1.0
_0\bin\ssv
.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~2\MICROS~1\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C
1E3DC1AF43
A} - res://C:\Utility\Internet\
BitComet\t
ools\BitCo
metBHO_1.2
.6.26.dll/
206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~2\SPYBOT~1\SDHel
per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~2\SPYBOT~1\SDHel
per.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{4
CE83E63-A6
E2-4A46-99
B3-DDD3A61
719A2}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\T
cpip\..\{7
F1174E2-BE
DD-429D-94
4A-9B1ECD5
267A0}: NameServer = 192.168.0.1
O17 - HKLM\System\CS1\Services\T
cpip\..\{4
CE83E63-A6
E2-4A46-99
B3-DDD3A61
719A2}: NameServer = 192.168.0.1
O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard3
2.dll C:\Windows\SysWOW64\cssdll
32.dll
O23 - Service: ABBYY FineReader 9.0 - Servizio Gestione licenze (ABBYY.Licensing.FineReade
r.Professi
onal.9.0) - ABBYY (BIT Software) - C:\Program Files (x86)\ABBYY FineReader 9.0\NetworkLicenseServer.e
xe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Unknown owner - C:\Windows\system32\AEADIS
RV.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg
.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.ex
e (file missing)
O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Utility\Manutenzione\Av
ira\AntiVi
r PersonalEdition Premium\avmailc.exe
O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Utility\Manutenzione\Av
ira\AntiVi
r PersonalEdition Premium\sched.exe
O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Utility\Manutenzione\Av
ira\AntiVi
r PersonalEdition Premium\avguard.exe
O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Utility\Manutenzione\Av
ira\AntiVi
r PersonalEdition Premium\AVWEBGRD.EXE
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2ev
xx.exe (file missing)
O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Utility\Manutenzione\Av
ira\AntiVi
r PersonalEdition Premium\avesvc.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Utility\Internet\Comodo
\Firewall\
cmdagent.e
xe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensi
ng.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.e
xe (file missing)
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkSe
rvice.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3
SSRP\E_S40RPB.EXE
O23 - Service: @%systemroot%\system32\fxs
resm.dll,-
118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc
.exe (file missing)
O23 - Service: HDD Information Service (HDDSvc) - AltrixSoft (
http://www.altrixsoft.com/) - C:\Windows\SysWOW64\HDDSvc
.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.
exe (file missing)
O23 - Service: Marvell RAID Event Agent (Marvell RAID) - Unknown owner - C:\Program Files (x86)\Marvell\61xx\svc\mvr
aidsvc.exe
O23 - Service: MRU Web Service (MRUWebService) - Apache Software Foundation - C:\Program Files (x86)\Marvell\61xx\Apache2
\bin\Apach
e.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.
exe (file missing)
O23 - Service: @%SystemRoot%\System32\net
logon.dll,
-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.
exe (file missing)
O23 - Service: @%systemroot%\system32\psb
ase.dll,-3
00 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.
exe (file missing)
O23 - Service: @%systemroot%\system32\Loc
ator.exe,-
2 (RpcLocator) - Unknown owner - C:\Windows\system32\locato
r.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sam
srv.dll,-1
(SamSs) - Unknown owner - C:\Windows\system32\lsass.
exe (file missing)
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftwar
e Sandra Professional Business 2009\RpcAgentSrv.exe
O23 - Service: @%SystemRoot%\system32\SLs
vc.exe,-10
1 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.
exe (file missing)
O23 - Service: @%SystemRoot%\system32\snm
ptrap.exe,
-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptr
ap.exe (file missing)
O23 - Service: @%systemroot%\system32\spo
olsv.exe,-
1 (Spooler) - Unknown owner - C:\Windows\System32\spools
v.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0
detect.exe
,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Det
ect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds
.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.ex
e (file missing)
O23 - Service: @%systemroot%\system32\vss
vc.exe,-10
2 (VSS) - Unknown owner - C:\Windows\system32\vssvc.
exe (file missing)
O23 - Service: @%systemroot%\system32\wbe
ngine.exe,
-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengi
ne.exe (file missing)
O23 - Service: Winpowermonitor - Macrovision - C:\PROGRA~2\UpsPilot\monit
or.exe
O23 - Service: WinpowerRMI - Macrovision - C:\PROGRA~2\UpsPilot\wpRMI
.exe
O23 - Service: @%Systemroot%\system32\wbe
m\wmiapsrv
.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\W
miApSrv.ex
e (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11920 bytes