RKill - Missing Services

Client downloaded a PUP in error - Rkill log is showing some missing services.  What does this mean and is there anything to be concerned about?

Checking Windows Service Integrity:

 * AllUserInstallAgent [Missing Service]
 * SDRSVC [Missing Service]
 * adp94xx [Missing Service]
 * adpahci [Missing Service]
 * adpu320 [Missing Service]
 * arc [Missing Service]
 * AsyncMac [Missing Service]
 * discache [Missing Service]
 * HdAudAddService [Missing Service]
 * iirsp [Missing Service]
 * LSI_SCSI [Missing Service]
 * nfrd960 [Missing Service]
 * PptpMiniport [Missing Service]
 * RasAgileVpn [Missing Service]
 * Rasl2tp [Missing Service]
 * RasSstp [Missing Service]
 * Wanarp [Missing Service]
 * Wanarpv6 [Missing Service]
 * Wd [Missing Service]
 * AppMgmt [Missing Service]
 * CSC [Missing Service]
 * CscService [Missing Service]
 * PeerDistSvc [Missing Service]

 * SystemEventsBroker => %SystemRoot%\system32\svchost.exe -k DcomLaunch [Incorrect ImagePath]
 * WSService => %SystemRoot%\System32\svchost.exe -k wsappx [Incorrect ImagePath]

Thanks,
Mags
MagsOwnerAsked:
Who is Participating?
 
Sudeep SharmaConnect With a Mentor Technical DesignerCommented:
rkill description
I think it is not yet compatible with Windows 8.1.

Sudeep
0
 
aadihCommented:
Is the PC being used in a domain environment

Nothing jumps out to be concerned about. But still I do not understand so many missing services (or what they are) . Is the PC functioning normally?
0
 
MagsOwnerAuthor Commented:
That is interesting...it is a single home computer.  Should I run RogueKiller?

Computer is only a couple months old.  He upgraded to Windows 8.1 then mistakenly downloaded MapGalaxy and was getting some browser redirects.  Ran normal scans, just some PUPs...just a weird RKill log.  PC seems to be functioning normally.

Thanks again aadih!
Mags
0
Worried about phishing attacks?

90% of attacks start with a phish. It’s critical that IT admins and MSSPs have the right security in place to protect their end users from these phishing attacks. Check out our latest feature brief for tips and tricks to keep your employees off a hackers line!

 
McKnifeConnect With a Mentor Commented:
Hi.

RKill seems to call any registry entry below HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
a service. There, windows keeps settings for services and also drivers which in internal terms are services, too. It seems some driver files are missing which used to be there on your computer. That might be due to hardware changes.
0
 
Sudeep SharmaTechnical DesignerCommented:
First make sure that you have the latest version of Rkill.
Secondly make sure that you are running it with "Run As Administrator".

Let us know the result.

Sudeep
0
 
MagsOwnerAuthor Commented:
Thanks...I will try and let you know.
0
 
MagsOwnerAuthor Commented:
Have latest version of Rkill...always download from Bleepingcomputer.

Ran with "Run As Administrator", same results.

He downloaded MapsGalaxy Toolbar again by mistake...why can't someone put Mindsparks out of business!!

Running AdwCleaner and JRT again
0
 
McKnifeCommented:
Did you read and verify my assumption?
0
 
Sudeep SharmaTechnical DesignerCommented:
@Mags,

Few questions which OS are you running this on?
Secondly could you try the iexplore.exe version and post the results,

Download it from here:
http://www.bleepingcomputer.com/download/rkill/

Sudeep
0
 
MagsOwnerAuthor Commented:
Good Morning McKnife, I did read your assumption.  Thanks for the explanation and the only hardware change I know he made was adding his printer.

Hello Sudeep, he is running Windows 8.1...just updated it recently.  I will try and let you know.

Thanks guys!
Mags
0
 
MagsOwnerAuthor Commented:
Shall I run it on my 8.1 machine and see what results I get or would that not be a good idea?

His computer seems to be running well.
M.
0
 
Sudeep SharmaTechnical DesignerCommented:
You could give it a try.

Thanks,
Sudeep
0
 
McKnifeCommented:
You have read it, fine. And have you followed it? I was interested if you verified it. Are those files there, or not? At the mentioned regedit path you find the file names and paths.
0
 
MagsOwnerAuthor Commented:
Thank you McKnife  I apparently did not read it correctly.  I will take a look.  Thanks for bringing it to my attention.
0
 
MagsOwnerAuthor Commented:
Okay...so I ran Rkill on my 8.1 machine and came up with several missing services.  I looked for them in regedit, in the location that McKnife mentioned, and they were not there.

I think we can conclude that Rkill is not yet compatible with Windows 8.1 as Sudeep pointed out.  Do you agree?
0
 
McKnifeCommented:
Yes, that will be the simple solution.
0
 
MagsOwnerAuthor Commented:
But a good one?  It seems to make sense since I don't think there are services missing from my computer.  Thanks.
0
 
McKnifeCommented:
There aren't. I checked on a clean 8.1 and for example "Wanarp" is missing there, while it's present on a Vista System.
0
 
MagsOwnerAuthor Commented:
Looks like we are finished unless anyone thinks it is something other than Rkill not able to run correctly on Windows 8.1.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.