Solved

RKill - Missing Services

Posted on 2014-01-06
19
2,711 Views
Last Modified: 2014-01-09
Client downloaded a PUP in error - Rkill log is showing some missing services.  What does this mean and is there anything to be concerned about?

Checking Windows Service Integrity:

 * AllUserInstallAgent [Missing Service]
 * SDRSVC [Missing Service]
 * adp94xx [Missing Service]
 * adpahci [Missing Service]
 * adpu320 [Missing Service]
 * arc [Missing Service]
 * AsyncMac [Missing Service]
 * discache [Missing Service]
 * HdAudAddService [Missing Service]
 * iirsp [Missing Service]
 * LSI_SCSI [Missing Service]
 * nfrd960 [Missing Service]
 * PptpMiniport [Missing Service]
 * RasAgileVpn [Missing Service]
 * Rasl2tp [Missing Service]
 * RasSstp [Missing Service]
 * Wanarp [Missing Service]
 * Wanarpv6 [Missing Service]
 * Wd [Missing Service]
 * AppMgmt [Missing Service]
 * CSC [Missing Service]
 * CscService [Missing Service]
 * PeerDistSvc [Missing Service]

 * SystemEventsBroker => %SystemRoot%\system32\svchost.exe -k DcomLaunch [Incorrect ImagePath]
 * WSService => %SystemRoot%\System32\svchost.exe -k wsappx [Incorrect ImagePath]

Thanks,
Mags
0
Comment
Question by:MagsMcKinley14
  • 9
  • 5
  • 4
  • +1
19 Comments
 
LVL 24

Expert Comment

by:aadih
Comment Utility
Is the PC being used in a domain environment

Nothing jumps out to be concerned about. But still I do not understand so many missing services (or what they are) . Is the PC functioning normally?
0
 

Author Comment

by:MagsMcKinley14
Comment Utility
That is interesting...it is a single home computer.  Should I run RogueKiller?

Computer is only a couple months old.  He upgraded to Windows 8.1 then mistakenly downloaded MapGalaxy and was getting some browser redirects.  Ran normal scans, just some PUPs...just a weird RKill log.  PC seems to be functioning normally.

Thanks again aadih!
Mags
0
 
LVL 53

Assisted Solution

by:McKnife
McKnife earned 100 total points
Comment Utility
Hi.

RKill seems to call any registry entry below HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
a service. There, windows keeps settings for services and also drivers which in internal terms are services, too. It seems some driver files are missing which used to be there on your computer. That might be due to hardware changes.
0
 
LVL 29

Expert Comment

by:Sudeep Sharma
Comment Utility
First make sure that you have the latest version of Rkill.
Secondly make sure that you are running it with "Run As Administrator".

Let us know the result.

Sudeep
0
 

Author Comment

by:MagsMcKinley14
Comment Utility
Thanks...I will try and let you know.
0
 

Author Comment

by:MagsMcKinley14
Comment Utility
Have latest version of Rkill...always download from Bleepingcomputer.

Ran with "Run As Administrator", same results.

He downloaded MapsGalaxy Toolbar again by mistake...why can't someone put Mindsparks out of business!!

Running AdwCleaner and JRT again
0
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
Did you read and verify my assumption?
0
 
LVL 29

Expert Comment

by:Sudeep Sharma
Comment Utility
@Mags,

Few questions which OS are you running this on?
Secondly could you try the iexplore.exe version and post the results,

Download it from here:
http://www.bleepingcomputer.com/download/rkill/

Sudeep
0
 

Author Comment

by:MagsMcKinley14
Comment Utility
Good Morning McKnife, I did read your assumption.  Thanks for the explanation and the only hardware change I know he made was adding his printer.

Hello Sudeep, he is running Windows 8.1...just updated it recently.  I will try and let you know.

Thanks guys!
Mags
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 
LVL 29

Accepted Solution

by:
Sudeep Sharma earned 400 total points
Comment Utility
rkill description
I think it is not yet compatible with Windows 8.1.

Sudeep
0
 

Author Comment

by:MagsMcKinley14
Comment Utility
Shall I run it on my 8.1 machine and see what results I get or would that not be a good idea?

His computer seems to be running well.
M.
0
 
LVL 29

Expert Comment

by:Sudeep Sharma
Comment Utility
You could give it a try.

Thanks,
Sudeep
0
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
You have read it, fine. And have you followed it? I was interested if you verified it. Are those files there, or not? At the mentioned regedit path you find the file names and paths.
0
 

Author Comment

by:MagsMcKinley14
Comment Utility
Thank you McKnife  I apparently did not read it correctly.  I will take a look.  Thanks for bringing it to my attention.
0
 

Author Comment

by:MagsMcKinley14
Comment Utility
Okay...so I ran Rkill on my 8.1 machine and came up with several missing services.  I looked for them in regedit, in the location that McKnife mentioned, and they were not there.

I think we can conclude that Rkill is not yet compatible with Windows 8.1 as Sudeep pointed out.  Do you agree?
0
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
Yes, that will be the simple solution.
0
 

Author Comment

by:MagsMcKinley14
Comment Utility
But a good one?  It seems to make sense since I don't think there are services missing from my computer.  Thanks.
0
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
There aren't. I checked on a clean 8.1 and for example "Wanarp" is missing there, while it's present on a Vista System.
0
 

Author Comment

by:MagsMcKinley14
Comment Utility
Looks like we are finished unless anyone thinks it is something other than Rkill not able to run correctly on Windows 8.1.
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

I'm a big fan of Windows' offline folder caching and have used it on my laptops for over a decade.  One thing I don't like about it, however, is how difficult Microsoft has made it for the cache to be moved out of the Windows folder.  Here's how to …
If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now