Avatar of Mags
Mags
Flag for United States of America asked on

RKill - Missing Services

Client downloaded a PUP in error - Rkill log is showing some missing services.  What does this mean and is there anything to be concerned about?

Checking Windows Service Integrity:

 * AllUserInstallAgent [Missing Service]
 * SDRSVC [Missing Service]
 * adp94xx [Missing Service]
 * adpahci [Missing Service]
 * adpu320 [Missing Service]
 * arc [Missing Service]
 * AsyncMac [Missing Service]
 * discache [Missing Service]
 * HdAudAddService [Missing Service]
 * iirsp [Missing Service]
 * LSI_SCSI [Missing Service]
 * nfrd960 [Missing Service]
 * PptpMiniport [Missing Service]
 * RasAgileVpn [Missing Service]
 * Rasl2tp [Missing Service]
 * RasSstp [Missing Service]
 * Wanarp [Missing Service]
 * Wanarpv6 [Missing Service]
 * Wd [Missing Service]
 * AppMgmt [Missing Service]
 * CSC [Missing Service]
 * CscService [Missing Service]
 * PeerDistSvc [Missing Service]

 * SystemEventsBroker => %SystemRoot%\system32\svchost.exe -k DcomLaunch [Incorrect ImagePath]
 * WSService => %SystemRoot%\System32\svchost.exe -k wsappx [Incorrect ImagePath]

Thanks,
Mags
Anti-Virus AppsWindows 8

Avatar of undefined
Last Comment
Mags

8/22/2022 - Mon
aadih

Is the PC being used in a domain environment

Nothing jumps out to be concerned about. But still I do not understand so many missing services (or what they are) . Is the PC functioning normally?
Mags

ASKER
That is interesting...it is a single home computer.  Should I run RogueKiller?

Computer is only a couple months old.  He upgraded to Windows 8.1 then mistakenly downloaded MapGalaxy and was getting some browser redirects.  Ran normal scans, just some PUPs...just a weird RKill log.  PC seems to be functioning normally.

Thanks again aadih!
Mags
SOLUTION
McKnife

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Sudeep Sharma

First make sure that you have the latest version of Rkill.
Secondly make sure that you are running it with "Run As Administrator".

Let us know the result.

Sudeep
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
Mags

ASKER
Thanks...I will try and let you know.
Mags

ASKER
Have latest version of Rkill...always download from Bleepingcomputer.

Ran with "Run As Administrator", same results.

He downloaded MapsGalaxy Toolbar again by mistake...why can't someone put Mindsparks out of business!!

Running AdwCleaner and JRT again
McKnife

Did you read and verify my assumption?
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Sudeep Sharma

@Mags,

Few questions which OS are you running this on?
Secondly could you try the iexplore.exe version and post the results,

Download it from here:
http://www.bleepingcomputer.com/download/rkill/

Sudeep
Mags

ASKER
Good Morning McKnife, I did read your assumption.  Thanks for the explanation and the only hardware change I know he made was adding his printer.

Hello Sudeep, he is running Windows 8.1...just updated it recently.  I will try and let you know.

Thanks guys!
Mags
ASKER CERTIFIED SOLUTION
Sudeep Sharma

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Mags

ASKER
Shall I run it on my 8.1 machine and see what results I get or would that not be a good idea?

His computer seems to be running well.
M.
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
Sudeep Sharma

You could give it a try.

Thanks,
Sudeep
McKnife

You have read it, fine. And have you followed it? I was interested if you verified it. Are those files there, or not? At the mentioned regedit path you find the file names and paths.
Mags

ASKER
Thank you McKnife  I apparently did not read it correctly.  I will take a look.  Thanks for bringing it to my attention.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Mags

ASKER
Okay...so I ran Rkill on my 8.1 machine and came up with several missing services.  I looked for them in regedit, in the location that McKnife mentioned, and they were not there.

I think we can conclude that Rkill is not yet compatible with Windows 8.1 as Sudeep pointed out.  Do you agree?
McKnife

Yes, that will be the simple solution.
Mags

ASKER
But a good one?  It seems to make sense since I don't think there are services missing from my computer.  Thanks.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
McKnife

There aren't. I checked on a clean 8.1 and for example "Wanarp" is missing there, while it's present on a Vista System.
Mags

ASKER
Looks like we are finished unless anyone thinks it is something other than Rkill not able to run correctly on Windows 8.1.