Da_maniaC Posted May 11, 2008 Report Share Posted May 11, 2008 Hey guys,I recently built a new machine and installed Vista Ultimate 64-bits onto it.Everything is running fine, however i do take the time to tweak my system in a way that i never want to bebothered by services suddenly starting up and wanting user input or just services which i do not need at all.I therefore have stuff like ReadyBoost and Vista Prefetch disabled.I figured i'd run Hijack This and see what the log would have to tell me.To my amazement there were quite a few .dll's that seemed to have their file missing.This would mean i could just delete their entries...however since its Vista i wonder if the files would actually still be thereserving some kind of purpose or that Hijack This might just be wrong in this case?Here's the Hijack This log:Logfile of HijackThis v1.99.0Scan saved at 17:00:13, on 11-5-2008Platform: Unknown Windows (WinNT 6.00.1905 SP1)MSIE: Internet Explorer v7.00 (7.00.6001.18000)Running processes:C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exeC:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exeC:\Program Files (x86)\WhatPulse\WhatPulse.exeC:\Program Files (x86)\MaxMonk\MaxMonk.exeC:\Program Files (x86)\Winamp\winampa.exeC:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exeC:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exeC:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exeC:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exeC:\Program Files\Logitech\SetPoint\x86\SetPoint32.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exeC:\Program Files (x86)\Hijack This\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://tweakers.net/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exeO1 - Hosts: ::1 localhostO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dllO2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO4 - HKLM\..\Run: [MaxMonkey] "C:\Program Files (x86)\MaxMonk\MaxMonk.exe"O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exeO4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exeO4 - HKLM\..\Run: [Hard Disk Sentinel] "C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe"O4 - HKCU\..\Run: [WhatPulse] C:\Program Files (x86)\WhatPulse\WhatPulse.exeO4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exeO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dllO9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dllO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dllO9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLLO10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dllO11 - Options group: [INTERNATIONAL] International*O13 - Gopher Prefix: O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLLO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLLO18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dllO23 - Service: Acronis Scheduler2 Service - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exeO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: @%SystemRoot%\system32\Alg.exe,-112 - Unknown - C:\Windows\System32\alg.exe (file missing)O23 - Service: @dfsrres.dll,-101 - Unknown - C:\Windows\system32\DFSR.exe (file missing)O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 - Unknown - %windir%\system32\svchost.exe (file missing)O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 - Unknown - C:\Windows\system32\fxssvc.exe (file missing)O23 - Service: @gpapi.dll,-112 - Unknown - %windir%\system32\svchost.exe (file missing)O23 - Service: Intel(R) Matrix Storage Event Monitor - Intel Corporation - C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exeO23 - Service: @keyiso.dll,-100 - Unknown - C:\Windows\system32\lsass.exe (file missing)O23 - Service: Logitech Bluetooth Service - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exeO23 - Service: @comres.dll,-2797 - Unknown - C:\Windows\System32\msdtc.exe (file missing)O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 - Unknown - C:\Windows\system32\lsass.exe (file missing)O23 - Service: PnkBstrA - Unknown - C:\Windows\system32\PnkBstrA.exeO23 - Service: @%systemroot%\system32\psbase.dll,-300 - Unknown - C:\Windows\system32\lsass.exe (file missing)O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 - Unknown - %windir%\system32\svchost.exe (file missing)O23 - Service: @%systemroot%\system32\Locator.exe,-2 - Unknown - C:\Windows\system32\locator.exe (file missing)O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 - Unknown - C:\Windows\system32\lsass.exe (file missing)O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 - Unknown - %windir%\system32\svchost.exe (file missing)O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 - Unknown - C:\Windows\system32\SLsvc.exe (file missing)O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 - Unknown - C:\Windows\System32\snmptrap.exe (file missing)O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 - Unknown - C:\Windows\System32\spoolsv.exe (file missing)O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exeO23 - Service: Acronis Try And Decide Service - Unknown - C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exeO23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 - Unknown - C:\Windows\system32\UI0Detect.exe (file missing)O23 - Service: @%SystemRoot%\system32\vds.exe,-100 - Unknown - C:\Windows\System32\vds.exe (file missing)O23 - Service: @%systemroot%\system32\vssvc.exe,-102 - Unknown - C:\Windows\system32\vssvc.exe (file missing)O23 - Service: @%systemroot%\system32\wbengine.exe,-104 - Unknown - C:\Windows\system32\wbengine.exe (file missing)O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 - Unknown - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 - Unknown - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)Could anyone tell me how safe it is to delete those entries?Thanks. :) Quote Link to comment Share on other sites More sharing options...
andsome Posted May 11, 2008 Report Share Posted May 11, 2008 No one on here now reads Hijack this logs.Please post it on here. Then let us know how you get on. :D Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted May 12, 2008 Report Share Posted May 12, 2008 Also, it is better to use the latest version 2.0.2 when posting a HJT log anywhere. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.