Solved

RKill - Missing Services

Posted on 2014-01-06
19
2,980 Views
Last Modified: 2014-01-09
Client downloaded a PUP in error - Rkill log is showing some missing services.  What does this mean and is there anything to be concerned about?

Checking Windows Service Integrity:

 * AllUserInstallAgent [Missing Service]
 * SDRSVC [Missing Service]
 * adp94xx [Missing Service]
 * adpahci [Missing Service]
 * adpu320 [Missing Service]
 * arc [Missing Service]
 * AsyncMac [Missing Service]
 * discache [Missing Service]
 * HdAudAddService [Missing Service]
 * iirsp [Missing Service]
 * LSI_SCSI [Missing Service]
 * nfrd960 [Missing Service]
 * PptpMiniport [Missing Service]
 * RasAgileVpn [Missing Service]
 * Rasl2tp [Missing Service]
 * RasSstp [Missing Service]
 * Wanarp [Missing Service]
 * Wanarpv6 [Missing Service]
 * Wd [Missing Service]
 * AppMgmt [Missing Service]
 * CSC [Missing Service]
 * CscService [Missing Service]
 * PeerDistSvc [Missing Service]

 * SystemEventsBroker => %SystemRoot%\system32\svchost.exe -k DcomLaunch [Incorrect ImagePath]
 * WSService => %SystemRoot%\System32\svchost.exe -k wsappx [Incorrect ImagePath]

Thanks,
Mags
0
Comment
Question by:MagsMcKinley14
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 9
  • 5
  • 4
  • +1
19 Comments
 
LVL 24

Expert Comment

by:aadih
ID: 39760989
Is the PC being used in a domain environment

Nothing jumps out to be concerned about. But still I do not understand so many missing services (or what they are) . Is the PC functioning normally?
0
 

Author Comment

by:MagsMcKinley14
ID: 39761082
That is interesting...it is a single home computer.  Should I run RogueKiller?

Computer is only a couple months old.  He upgraded to Windows 8.1 then mistakenly downloaded MapGalaxy and was getting some browser redirects.  Ran normal scans, just some PUPs...just a weird RKill log.  PC seems to be functioning normally.

Thanks again aadih!
Mags
0
 
LVL 54

Assisted Solution

by:McKnife
McKnife earned 100 total points
ID: 39761363
Hi.

RKill seems to call any registry entry below HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
a service. There, windows keeps settings for services and also drivers which in internal terms are services, too. It seems some driver files are missing which used to be there on your computer. That might be due to hardware changes.
0
Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

 
LVL 30

Expert Comment

by:Sudeep Sharma
ID: 39761963
First make sure that you have the latest version of Rkill.
Secondly make sure that you are running it with "Run As Administrator".

Let us know the result.

Sudeep
0
 

Author Comment

by:MagsMcKinley14
ID: 39762556
Thanks...I will try and let you know.
0
 

Author Comment

by:MagsMcKinley14
ID: 39763804
Have latest version of Rkill...always download from Bleepingcomputer.

Ran with "Run As Administrator", same results.

He downloaded MapsGalaxy Toolbar again by mistake...why can't someone put Mindsparks out of business!!

Running AdwCleaner and JRT again
0
 
LVL 54

Expert Comment

by:McKnife
ID: 39764488
Did you read and verify my assumption?
0
 
LVL 30

Expert Comment

by:Sudeep Sharma
ID: 39765099
@Mags,

Few questions which OS are you running this on?
Secondly could you try the iexplore.exe version and post the results,

Download it from here:
http://www.bleepingcomputer.com/download/rkill/

Sudeep
0
 

Author Comment

by:MagsMcKinley14
ID: 39765139
Good Morning McKnife, I did read your assumption.  Thanks for the explanation and the only hardware change I know he made was adding his printer.

Hello Sudeep, he is running Windows 8.1...just updated it recently.  I will try and let you know.

Thanks guys!
Mags
0
 
LVL 30

Accepted Solution

by:
Sudeep Sharma earned 400 total points
ID: 39765168
rkill description
I think it is not yet compatible with Windows 8.1.

Sudeep
0
 

Author Comment

by:MagsMcKinley14
ID: 39765211
Shall I run it on my 8.1 machine and see what results I get or would that not be a good idea?

His computer seems to be running well.
M.
0
 
LVL 30

Expert Comment

by:Sudeep Sharma
ID: 39765269
You could give it a try.

Thanks,
Sudeep
0
 
LVL 54

Expert Comment

by:McKnife
ID: 39765276
You have read it, fine. And have you followed it? I was interested if you verified it. Are those files there, or not? At the mentioned regedit path you find the file names and paths.
0
 

Author Comment

by:MagsMcKinley14
ID: 39765341
Thank you McKnife  I apparently did not read it correctly.  I will take a look.  Thanks for bringing it to my attention.
0
 

Author Comment

by:MagsMcKinley14
ID: 39765407
Okay...so I ran Rkill on my 8.1 machine and came up with several missing services.  I looked for them in regedit, in the location that McKnife mentioned, and they were not there.

I think we can conclude that Rkill is not yet compatible with Windows 8.1 as Sudeep pointed out.  Do you agree?
0
 
LVL 54

Expert Comment

by:McKnife
ID: 39765503
Yes, that will be the simple solution.
0
 

Author Comment

by:MagsMcKinley14
ID: 39765550
But a good one?  It seems to make sense since I don't think there are services missing from my computer.  Thanks.
0
 
LVL 54

Expert Comment

by:McKnife
ID: 39766506
There aren't. I checked on a clean 8.1 and for example "Wanarp" is missing there, while it's present on a Vista System.
0
 

Author Comment

by:MagsMcKinley14
ID: 39766622
Looks like we are finished unless anyone thinks it is something other than Rkill not able to run correctly on Windows 8.1.
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Sometimes a user will call me frantically, explaining that something has gone wrong and they have tried everything (read - they have messed it up more and now need someone to clean up) and it still does no good, can I help them?!  Usually the standa…
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This Micro Tutorial will teach you how to reformat your flash drive. Sometimes your flash drive may have issues carrying files so this will completely restore it to manufacturing settings. Make sure to backup all files before reformatting. This w…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question