This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

The specified service does not exist as an installed service [Solved]

71 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I need help with this. The specified service does not exist as an installed service….I see this error message frequently when trying to use my laptop. I am running a Dell laptop 4.0 GB memory Windows Vista Ultimate Service Pack 1 I think I picked up this virus by clicking on an email in my spam folder that looked like it was from LinkedIn. It wasn't! Safe Mode with Networking does allow the PC to start in safe mode but connecting to the internet fails with the "The specified service does not exist as an installed service" message. Any .exe when executed results in same "specified service" message. I cannot connect to the internet. When I try to change the connect status from unknown I get the message "The specified service does not exist as an installed service…. The only way to run anything on the laptop is to remove the file extension from the executable. dds.scr will run as dds Skype cannot connect since internet connectivity. I cannot run MBAM.exe, receive the same message
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!

The last time I picked up a topic with these issues we had a heck of a time! But with that one under my belt this sounds a lot more familiar now. So I'm going to do my best to help you out with this one :)

I suspect you either have a zero access infection on board, or have the remnants of one. Let's try to address two specific issues first that will *hopefully* get you back your internet and get programs running again so we can tackle things in a more "normal" manner.


This appears to be a standard 32-bit machine. So let's get a scan (in Safe Mode) that will help me identify the internet items we need to fix.

Download Farbar Recovery Scan Tool and save it to a flash drive.

Plug the flashdrive into the infected PC.

Restart your computer and tap F8 to bring up the Advanced Menu, then click Repair your computer

Follow the prompt to enter keyboard input method, and then the prompt to enter a password. If the machine does not have a password, simply click Enter.

In the next menu, use the arrow keys on the keyboard to highlight Command Prompt and press Enter.
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe and press Enter.
Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Place a check next to List Drivers MD5
  • Press Scan button.
    When finished, a log (FRST.txt) will be created on the flash drive. Please copy and paste it to your reply.


The reason you are unable to run any programs at the moment is because of User Account Control. In the last scenario I had, we were unable to disable it via any method other than a registry fix. I would like you to be extremely careful when doing this.


We are now going to try and disable UAC directly from the registry. A word of caution – incorrectly editing the registry may severely damage your system. These modifications are intended for Windows advanced users who are comfortable using the registry editor. If you are not comfortable doing so please stop now and let me know.

This can be completed in safe mode with no problems.

To start the registry editor, type regedit in the Start menu search text box and press enter.

In the left hand pane please navigate down to the subfolder for the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System

In the right hand pane look for where it says REG_DWORD (32-bit) Value name in the headings and find the item:
EnableLUA

If you double click on it a box will pop up with the current value that is in there. It will probably say 1 for enabled. Please change that to 0 for disabled.

Then click OK

Then you can close the registry editor window.

Then reboot the machine and see if the behavior has changed.

Let me know if you are not comfortable doing this or if you have any troubles whatsoever. If you run into any problems doing this please just cancel out. Do not make any changes to the registry if you are not completely comfortable in what you are doing.

We may not be able to re-enable this based on my previous experience with this type of issue, but that will be no problem as long as we can clean up the rest of the problems.

Please let me know if you have any questions or concerns about these instructions or carrying them out.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-01-2013 Ran by [removed] at 16-01-2013 22:22:36 Running from E:\ Windows Vista ™ Ultimate Service Pack 1 (X86) OS Language: English(US) The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\…\Run: [Windows Defender] DER\MSASCUI.EXE -HIDE [x] HKLM\…\Run: [ECenter] CHER.EXE [x] HKLM\…\Run: [Apoint] T.EXE [x] HKLM\…\Run: [OEM02Mon.exe] .EXE [x] HKLM\…\Run: [NvCplDaemon] VSTARTUP [x] HKLM\…\Run: [NvMediaCenter] IT [x] HKLM\…\Run: [NVHotkey] VHOTKEY.DLL,START [x] HKLM\…\Run: [UpdReg] DOWS\UPDREG.EXE [x] HKLM\…\Run: [PSQLLauncher] CHER.EXE" /STARTUP [x] HKLM\…\Run: [IAAnotif] OTIF.EXE" [x] HKLM\…\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup [30192 2010-08-20] (Google) HKLM\…\Run: [dscactivate] T\CUSTOM\DSCA.EXE" [x] HKLM\…\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" [184320 2007-12-21] (CyberLink Corp.) HKLM\…\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [34672 2008-06-11] (Adobe Systems Incorporated) HKLM\…\Run: [DellSupportCenter] TER [x] HKLM\…\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe [405504 2007-09-13] (IDT, Inc.) HKLM\…\Run: [SCCSwitcher] C:\Program Files\TamTam CVS SCC\SCCSwitcher.exe [69632 2008-12-10] (David Levinson) HKLM\…\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [417792 2009-09-04] (Apple Inc.) HKLM\…\Run: [iTunesHelper] ESHELPER.EXE" [x] HKLM\…\Run: [ConnectionCenter] TR.EXE" /STARTUP [x] HKLM\…\Run: [AdobeAAMUpdater-1.0] FILES\ADOBE\OOBE\PDAPP\UWA\UPDATERSTARTUPUTILITY.EXE" [x] HKLM\…\Run: [mcui_exe] KEY [x] HKLM\…\Run: [XeroxRegistation] OR\APPDATA\LOCAL\TEMP\XEROX\EREG\EREG.EXE" /STARTUP [x] HKLM\…\Run: [SignIn] .EXE" /AUTORUN [x] HKLM\…\Run: [Communicator] KEY [x] HKLM\…\Run: [EEventManager] AGER.EXE" [x] HKLM\…\Run: [FUFAXRCV] SOFTWARE\FAX UTILITY\FUFAXRCV.EXE" [x] HKLM\…\Run: [FUFAXSTM] SOFTWARE\FAX UTILITY\FUFAXSTM.EXE" [x] HKLM\…\Run: [SunJavaUpdateSched] FILES\JAVA\JAVA UPDATE\JUSCHED.EXE" [x] HKU\bconnor\…\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [206064 2008-08-13] (SupportSoft, Inc.) HKU\bconnor\…\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [68856 2008-10-24] (Google Inc.) HKU\bconnor\…\Run: [googletalk] C:\Users\bconnor\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart [3739648 2007-01-01] (Google) HKU\bconnor\…\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation) HKU\bconnor\…\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation) HKLM\…\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [512360 2012-12-14] (Malwarebytes Corporation) Winlogon\Notify\psfus: C:\Windows\system32\psqlpwd.dll (UPEK Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL Lsa: [Authentication Packages] msv1_0 setuid Lsa: [Notification Packages] scecli psqlpwd Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickSet.lnk ShortcutTarget: QuickSet.lnk -> C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.) Startup: C:\Users\All Users\Start Menu\Programs\Startup\Snagit 11.lnk ShortcutTarget: Snagit 11.lnk -> C:\Program Files\TechSmith\Snagit 11\Snagit32.exe (TechSmith Corporation) Startup: C:\Users\All Users\Start Menu\Programs\Startup\VPN Client.lnk ShortcutTarget: VPN Client.lnk -> C:\Windows\Installer\{1CE60928-8325-49A8-8B06-633E48DD2B67}\Icon3E5562ED7.ico () Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) ==================== Services (Whitelisted) =================== 2 ABBYY.Licensing.FineReader.Sprint.9.0; "C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service [759048 2009-05-14] (ABBYY) 2 Apple Mobile Device; "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe" [144712 2009-06-05] (Apple Inc.) 2 Creative Labs Licensing Service; "C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe" [72704 2008-10-24] (Creative Labs) 2 Creative Service for CDROM Access; C:\Windows\system32\CTsvcCDA.exe [44032 2007-04-08] (Creative Technology Ltd) 2 CVPND; "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe" [1528616 2010-09-27] (Cisco Systems, Inc.) 2 CVS; C:\Program Files\cvsnt\cvsservice.exe [35328 2004-08-19] (GNU) 2 CVSLock; C:\Program Files\cvsnt\cvslock.exe [48640 2004-08-19] () 3 dkab_device; C:\Windows\system32\DKabcoms.exe -service [508824 2006-10-21] ( ) 2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [161048 2008-05-02] (Stardock Corporation) 2 dsNcService; C:\Program Files\Juniper Networks\Common Files\dsNcService.exe [431472 2009-01-22] (Juniper Networks) 2 EpsonCustomerParticipation; "C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe" [521600 2011-06-09] (SEIKO EPSON CORPORATION) 3 GoogleDesktopManager-051210-111108; "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [30192 2010-08-20] (Google) 2 gupdate1c9f1f9b2071890; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [133104 2009-06-20] (Google Inc.) 2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [13824 2008-01-20] (Microsoft Corporation) 2 MBAMScheduler; "C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe" [398184 2012-12-14] (Malwarebytes Corporation) 2 McMPFSvc; "C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [167784 2012-08-31] (McAfee, Inc.) 2 mcmscsvc; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [167784 2012-08-31] (McAfee, Inc.) 2 McNaiAnn; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [167784 2012-08-31] (McAfee, Inc.) 2 McNASvc; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [167784 2012-08-31] (McAfee, Inc.) 3 McODS; "C:\Program Files\McAfee\VirusScan\mcods.exe" [279048 2012-09-10] (McAfee, Inc.) 2 McProxy; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [167784 2012-08-31] (McAfee, Inc.) 2 McShield; "C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe" [200816 2012-07-17] (McAfee, Inc.) 2 mfefire; "C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe" [168368 2012-07-17] (McAfee, Inc.) 2 mfevtp; "C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe" [166320 2012-07-17] (McAfee, Inc.) 2 MSK80Service; "C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [167784 2012-08-31] (McAfee, Inc.) 2 msoidsvc; "C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE" [1542560 2010-08-17] (Microsoft Corp.) 2 MSSQLSERVER; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER [28768528 2005-10-13] (Microsoft Corporation) 4 msvsmon80; "C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 [2808664 2007-02-22] (Microsoft Corporation) 4 msvsmon90; "C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon90 [3201024 2008-07-29] (Microsoft Corporation) 3 sm920service; C:\Program Files\HP\Service Manager 9.20\Server\RUN\smservice.exe [335928 2010-05-25] (Hewlett-Packard Development Company) 2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter [201968 2008-08-13] (SupportSoft, Inc.) 3 SQLSERVERAGENT; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE" -i MSSQLSERVER [318680 2005-10-13] (Microsoft Corporation) 2 WebClient; C:\Windows\System32\svchost.exe -k LocalService [21504 2008-01-20] (Microsoft Corporation) 2 msftesql; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe" -s:MSSQL.1 -f:MSSQLSERVER [x] 4 MSSQL$MSSQLSERVER2008; "c:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQL3\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER2008 [x] 2 MSSQL$SQLEXPRESS; "c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS [x] 4 MSSQLServerADHelper100; "c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE" [x] 4 NetMsmqActivator; "c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator [x] 4 NetPipeActivator; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [x] 4 NetTcpActivator; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [x] 4 NetTcpPortSharing; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [x] 4 SQLAgent$MSSQLSERVER2008; "c:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQL3\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER2008 [x] 4 SQLAgent$SQLEXPRESS; "c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE" -i SQLEXPRESS [x] ==================== Drivers (Whitelisted) ==================== 3 cfwids; C:\Windows\System32\drivers\cfwids.sys [60480 2012-07-17] (McAfee, Inc.) 3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.) 2 CVPNDRVA; \??\C:\Windows\system32\Drivers\CVPNDRVA.sys [308859 2010-09-27] (Cisco Systems, Inc.) 3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.) 3 dsNcAdpt; C:\Windows\System32\DRIVERS\dsNcAdpt.sys [23552 2009-01-22] (Juniper Networks) 3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [146872 2012-04-20] (McAfee, Inc.) 3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [127992 2012-07-17] (McAfee, Inc.) 3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [230224 2012-07-17] (McAfee, Inc.) 3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [61912 2012-07-17] (McAfee, Inc.) 3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [360792 2012-07-17] (McAfee, Inc.) 0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [554048 2012-07-17] (McAfee, Inc.) 3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [92192 2012-07-17] (McAfee, Inc.) 1 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [206784 2012-07-17] (McAfee, Inc.) 3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-08] (Microsoft Corporation) 4 nvstor; C:\Windows\system32\drivers\nvstor.sys [45112 2008-01-20] () 4 RsFx0103; C:\Windows\System32\DRIVERS\RsFx0103.sys [239336 2009-03-29] (Microsoft Corporation) 4 RsFx0150; C:\Windows\System32\DRIVERS\RsFx0150.sys [240608 2010-04-03] (Microsoft Corporation) 3 VSPerfDrv100; \??\c:\Program Files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys [48128 2009-12-08] (Microsoft Corporation) 3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x] 3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x] 3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-12-01 14:06 - 2014-12-01 14:06 - 00000000 ____D C:\Users\bconnor\Documents\My Axure RP Libraries 2014-12-01 14:06 - 2014-12-01 14:06 - 00000000 ____D C:\Users\bconnor\AppData\Local\Axure 2014-12-01 14:05 - 2014-12-01 14:05 - 00000032 RASHOT C:\Users\bconnor\AppData\Local\t56.dat 2014-12-01 14:05 - 2014-12-01 14:05 - 00000000 ____D C:\Users\bconnor\AppData\Roaming\Axure 2014-12-01 14:05 - 2014-12-01 14:05 - 00000000 ____D C:\Users\bconnor\AppData\Local\IsolatedStorage 2014-12-01 14:05 - 2014-12-01 14:05 - 00000000 ____D C:\Users\All Users\Axure 2013-01-16 22:20 - 2013-01-16 22:20 - 00000000 ____D C:\FRST 2013-01-09 19:25 - 2013-01-09 19:25 - 00000055 ____A C:\Users\bconnor\AppData\Roaming\mbam.context.scan ==================== One Month Modified Files and Folders ======== 2014-12-01 14:06 - 2014-12-01 14:06 - 00000000 ____D C:\Users\bconnor\Documents\My Axure RP Libraries 2014-12-01 14:06 - 2014-12-01 14:06 - 00000000 ____D C:\Users\bconnor\AppData\Local\Axure 2014-12-01 14:05 - 2014-12-01 14:05 - 00000032 RASHOT C:\Users\bconnor\AppData\Local\t56.dat 2014-12-01 14:05 - 2014-12-01 14:05 - 00000000 ____D C:\Users\bconnor\AppData\Roaming\Axure 2014-12-01 14:05 - 2014-12-01 14:05 - 00000000 ____D C:\Users\bconnor\AppData\Local\IsolatedStorage 2014-12-01 14:05 - 2014-12-01 14:05 - 00000000 ____D C:\Users\All Users\Axure 2013-01-16 22:20 - 2013-01-16 22:20 - 00000000 ____D C:\FRST 2013-01-13 20:15 - 2008-11-13 17:40 - 00000000 ____D C:\Users\bconnor\AppData\Local\TSVNCache 2013-01-13 20:15 - 2008-10-24 08:35 - 00000012 ____A C:\Windows\bthservsdp.dat 2013-01-13 20:15 - 2006-11-02 05:00 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-01-13 20:15 - 2006-11-02 05:00 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-01-13 20:15 - 2006-11-02 04:46 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-01-13 20:15 - 2006-11-02 04:46 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-01-13 20:15 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\System32\inetsrv 2013-01-13 20:14 - 2009-12-06 17:40 - 00000000 ____D C:\Users\bconnor\AppData\Roaming\Skype 2013-01-13 20:02 - 2012-10-23 12:02 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-01-13 20:02 - 2009-06-29 18:53 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-01-13 15:43 - 2009-06-29 18:53 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-01-13 15:42 - 2006-11-02 02:33 - 01115522 ____A C:\Windows\System32\PerfStringBackup.INI 2013-01-10 19:36 - 2012-11-15 17:54 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2013-01-10 19:36 - 2012-11-15 17:54 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-01-10 19:33 - 2011-09-26 08:53 - 00000000 ____D C:\Program Files\eclipse 2013-01-10 15:25 - 2009-06-20 14:50 - 00000868 ____A C:\Windows\Tasks\Google Software Updater.job 2013-01-09 19:25 - 2013-01-09 19:25 - 00000055 ____A C:\Users\bconnor\AppData\Roaming\mbam.context.scan ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2012-09-19 21:38:50 Restore point made on: 2012-09-26 21:39:02 Restore point made on: 2012-10-09 23:00:59 Restore point made on: 2012-10-11 23:00:55 Restore point made on: 2012-10-16 16:03:43 Restore point made on: 2012-10-20 11:13:32 Restore point made on: 2012-10-22 21:27:42 Restore point made on: 2012-10-26 16:33:36 Restore point made on: 2012-10-27 08:52:37 Restore point made on: 2012-10-29 10:21:26 Restore point made on: 2012-10-29 10:22:54 Restore point made on: 2012-10-29 10:24:01 Restore point made on: 2012-10-29 10:25:02 Restore point made on: 2012-10-29 12:31:28 Restore point made on: 2012-10-29 12:42:56 Restore point made on: 2012-10-31 12:25:24 Restore point made on: 2012-11-11 10:01:49 Restore point made on: 2012-11-13 11:53:00 Restore point made on: 2012-11-14 00:01:18 ==================== Memory info =========================== Percentage of memory in use: 9% Total physical RAM: 4093.14 MB Available physical RAM: 3705.92 MB Total Pagefile: 3958.5 MB Available Pagefile: 3813.27 MB Total Virtual: 2047.88 MB Available Virtual: 1966.31 MB ==================== Partitions ============================= 1 Drive c: (OS) (Fixed) (Total:285.5 GB) (Free:154.06 GB) NTFS ==>[Drive with boot components (obtained from BCD)] 3 Drive e: (LA-PUBLIC) (Removable) (Total:3.76 GB) (Free:3.08 GB) FAT32 4 Drive x: (RECOVERY) (Fixed) (Total:10 GB) (Free:4.26 GB) NTFS Disk ### Status Size Free Dyn Gpt ——– ———- ——- ——- — — Disk 0 Online 298 GB 0 B Disk 1 Online 3854 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 OEM 94 MB 32 KB Partition 2 Primary 10 GB 95 MB Partition 3 Primary 285 GB 10 GB Partition 0 Extended 2560 MB 296 GB Partition 4 Logical 2559 MB 296 GB ========================================================= Disk: 0 Partition 1 Type : DE Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 4 FAT Partition 94 MB Healthy Hidden ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 X RECOVERY NTFS Partition 10 GB Healthy Boot ========================================================= Disk: 0 Partition 3 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C OS NTFS Partition 285 GB Healthy ========================================================= Disk: 0 Partition 4 Type : DD Hidden: Yes Active: No There is no volume associated with this partition. ========================================================= Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 3854 MB 32 KB ========================================================= Disk: 1 Partition 1 Type : 0B Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 E LA-PUBLIC FAT32 Removable 3854 MB Healthy ========================================================= Last Boot: 2013-01-13 15:57 ==================== End Of Log ============================
Were you able to complete the registry edit, and if so, are you able to run programs in normal mode now?

There are some very odd entries in that log that appear as if the file names of a few of your programs and normal start items may have been changed by malware, but I don't want to go by the results of just one scan. When you try launching something please use a program that you have on your machine like Quicktime, Skype, or the internet. Don't try iTunes as that one appears to be one of the ones that may have a naming issue at the moment. (Please note that this does not mean the file iteslf is corrupted only that the name of the file appears a little odd in this particular diagnostic log. It will require further research to see what's going on so please don't panic.)

Please let me know if you were able to complete the registry edit and can now run files in normal mode with internet access or not, so we can procede with cleaning in a little easier way for you. If not , or if you are not comfortable doing so that is fine, we have other ways we can approach this - just let me know and we can tackle it from another angle :)
patndoris I tried the registry edit this evening. I have experience updating it in the past. I used the Registry search facility to find HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System With no success so I stopped trying. I am willing to try again if I approached the edit incorrectly. vistabug
Let's give this registry fix a try and see if this works a little better for you. You won't have to do any manual navigation to use this. You should be able to do this in safe mode.

Launch Notepad (Start>All Programs>Accessories)
Copy/paste all all of the code in the box below to it. Don't forget to include Windows Registry Editor Version 5.00.
Save in: Desktop
File Name: UACDisable.reg
Save as Type: All files
Click Save

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=dword:00000000


On the desktop, doubleclick UACDisable.reg and allow it to run. When prompted, let it merge.

After running the fix, please reboot the computer into normal mode and see if you can then run programs normally (without getting the specified service error). Let me know the results please.
patndoris Creating and running the registry change script seemed to run successfully but there is no change to the symptoms. I still get the message : "The specified service does not exist as an installed service". The message pops when trying to connect to the internet, stopping me from connecting. As before, I am grateful for your assistance and I hope you don't give up on my case. However I am flying out on business within the hour. I can only carry my work laptop, so for the coming week I will not be able to implement any of your suggestions. When I get home late Friday I hope we can get back on the case and work through to resolution. Please don't close down my topic… vistabug
patndoris I am back online and ready to work through this problem with you. I will be looking for you next strategy to help me get my laptop healthy again. vistabug
Welcome back from your trip! I hope it was a good one (even if it was for work.)

I've given a lot of thought to how to address the issues you have. You have some very corrupted registry entries (although they are mostly related to things like the mouse pad, java adobe and graphics, etc. Not the most critical workings of the machine from what shows in the logs) that we will need to address along the way, but not right off the bat. Just know that they exist and may be causing some issues and we will address later. They may be causing problems with booting normally, and that may be why you are having to boot into safe mode with networking. Unfortunately, since no one tool or tools can show us the full extent of what's going on with the machine, there may be other corruptions we can't see just yet, and that's a little more concerning but we are going to continue forward with this and see if we can't get things to a better place.

Before running any tools to look for malware infections (or the remnants of it), I'd like to try and make sure your default services are intact as it is difficult to tell what havoc this infection has caused on your machine. The last infection like this I had took quite awhile to work out, but we were able to get that machine to a working state.



Launch Notepad (Start>All Programs>Accessories)
Copy/paste all all of the code in the box below to it. Don't forget to include Windows Registry Editor Version 5.00.
Save in: Desktop
File Name: VistaDefault.reg
Save as Type: All files
Click Save

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost]
"netsvcs"=hex(7):41,00,65,00,4c,00,6f,00,6f,00,6b,00,75,00,70,00,53,00,76,00,\
  63,00,00,00,77,00,65,00,72,00,63,00,70,00,6c,00,73,00,75,00,70,00,70,00,6f,\
  00,72,00,74,00,00,00,54,00,68,00,65,00,6d,00,65,00,73,00,00,00,43,00,65,00,\
  72,00,74,00,50,00,72,00,6f,00,70,00,53,00,76,00,63,00,00,00,53,00,43,00,50,\
  00,6f,00,6c,00,69,00,63,00,79,00,53,00,76,00,63,00,00,00,6c,00,61,00,6e,00,\
  6d,00,61,00,6e,00,73,00,65,00,72,00,76,00,65,00,72,00,00,00,67,00,70,00,73,\
  00,76,00,63,00,00,00,49,00,4b,00,45,00,45,00,58,00,54,00,00,00,41,00,75,00,\
  64,00,69,00,6f,00,53,00,72,00,76,00,00,00,46,00,61,00,73,00,74,00,55,00,73,\
  00,65,00,72,00,53,00,77,00,69,00,74,00,63,00,68,00,69,00,6e,00,67,00,43,00,\
  6f,00,6d,00,70,00,61,00,74,00,69,00,62,00,69,00,6c,00,69,00,74,00,79,00,00,\
  00,49,00,61,00,73,00,00,00,49,00,72,00,6d,00,6f,00,6e,00,00,00,4e,00,6c,00,\
  61,00,00,00,4e,00,74,00,6d,00,73,00,73,00,76,00,63,00,00,00,4e,00,57,00,43,\
  00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,\
  4e,00,77,00,73,00,61,00,70,00,61,00,67,00,65,00,6e,00,74,00,00,00,52,00,61,\
  00,73,00,61,00,75,00,74,00,6f,00,00,00,52,00,61,00,73,00,6d,00,61,00,6e,00,\
  00,00,52,00,65,00,6d,00,6f,00,74,00,65,00,61,00,63,00,63,00,65,00,73,00,73,\
  00,00,00,53,00,45,00,4e,00,53,00,00,00,53,00,68,00,61,00,72,00,65,00,64,00,\
  61,00,63,00,63,00,65,00,73,00,73,00,00,00,53,00,52,00,53,00,65,00,72,00,76,\
  00,69,00,63,00,65,00,00,00,54,00,61,00,70,00,69,00,73,00,72,00,76,00,00,00,\
  57,00,6d,00,69,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,70,00,00,\
  00,54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,\
  77,00,75,00,61,00,75,00,73,00,65,00,72,00,76,00,00,00,42,00,49,00,54,00,53,\
  00,00,00,53,00,68,00,65,00,6c,00,6c,00,48,00,57,00,44,00,65,00,74,00,65,00,\
  63,00,74,00,69,00,6f,00,6e,00,00,00,4c,00,6f,00,67,00,6f,00,6e,00,48,00,6f,\
  00,75,00,72,00,73,00,00,00,50,00,43,00,41,00,75,00,64,00,69,00,74,00,00,00,\
  68,00,65,00,6c,00,70,00,73,00,76,00,63,00,00,00,75,00,70,00,6c,00,6f,00,61,\
  00,64,00,6d,00,67,00,72,00,00,00,69,00,70,00,68,00,6c,00,70,00,73,00,76,00,\
  63,00,00,00,73,00,65,00,63,00,6c,00,6f,00,67,00,6f,00,6e,00,00,00,41,00,70,\
  00,70,00,49,00,6e,00,66,00,6f,00,00,00,6d,00,73,00,69,00,73,00,63,00,73,00,\
  69,00,00,00,4d,00,4d,00,43,00,53,00,53,00,00,00,50,00,72,00,6f,00,66,00,53,\
  00,76,00,63,00,00,00,45,00,61,00,70,00,48,00,6f,00,73,00,74,00,00,00,77,00,\
  69,00,6e,00,6d,00,67,00,6d,00,74,00,00,00,73,00,63,00,68,00,65,00,64,00,75,\
  00,6c,00,65,00,00,00,53,00,65,00,73,00,73,00,69,00,6f,00,6e,00,45,00,6e,00,\
  76,00,00,00,62,00,72,00,6f,00,77,00,73,00,65,00,72,00,00,00,68,00,6b,00,6d,\
  00,73,00,76,00,63,00,00,00,41,00,70,00,70,00,4d,00,67,00,6d,00,74,00,00,00,\
  00,00

On the desktop, doubleclick VistaDefault.reg and allow it to run. When prompted, let it merge.

After running the fix, please try rebooting the computer into normal mode and see if you can then run programs normally. Let me know the results please.


If the programs do not launch normally, and you do not have internet access please do the following:


Boot your computer in Safe Mode WITH NETWORKING
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode WITH NETWORKING menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode WITH NETWORKING
  • Log into your usual account

    See if you are able to access the internet now.


If so, please do the following (or you can try downloading it to a flash drive and transferring it over and seeing if it will run ok if you can't access the internet)


Please download the ESET services repair tool, extract the file to your desktop.
  • Double-click ServicesRepair.exe,
  • If security notifications appear, click Continue or Run and then click Yes when asked if you want to proceed.
  • Once the tool has finished, you will be prompted to restart your computer. Click Yes to restart.
  • a log will be saved in the CCSupport folder the tool created on your desktop, please post the content in your next reply


Then reboot the computer again (try for normal mode) but if not go for safe mode with networking, and see if you can launch programs normally and access the internet. Let me know the results.

If you are not able to complete any of these steps, or you have trouble with them, please let me know.
patndoris I ran VistaDefault.reg on my vista laptop. There was no apparent improvement. There are no audio devices available No access to usb drive unless it is installed prior to reboot. Connect to a Network shows wifi networks but cannot connect. Get same error message: "The specified service does not exist as an installed service". Boot your computer in Safe Mode WITH NETWORKING - I did this and there was no apparent improvement. Connect to a Network shows wifi networks but cannot connect. Get same error message: "The specified service does not exist as an installed service".
Please note that I do not anticipate this will fix your problem completely, but I do want to see if it will remove anything that may be hindering us from being able to fix the issues being able to resolve the UAC and internet. So let's go ahead and run this tool and see what we find in terms of malware and we'll go from there.

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

NoOrphans::


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe which will cause it to run.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

If you have a problem launching programs (where you receive a notification that they have been marked for deletion) after running Combofix, please do not panic! Simply reboot the computer and all should be fine.
Vistabug,

Please hold off doing the Combofx routine. There has been a slight hitch in the latest download of Combofix and we need to get that resolved before you run that.

I will let you know as soon as this has been fixed and we can continue with this fix. In the mean time, let's forge ahead with trying to fix the USB, and the internet:

Please download the following files to your flash drive and transfer them to the desktop of the infected computer and then run the registry fixes as you have done before by double clicking then and letting them merge into the registry.

http://download.bleepingcomputer.com/win-s…s/vista/nsi.reg
http://download.bleepingcomputer.com/win-s…ta/PlugPlay.reg
http://download.bleepingcomputer.com/win-s…ista/Netman.reg

After doing these merges, please reboot the machine and see if you have internet and USB at least in Safe Mode with Networking. You could attempt normal mode, but I suspect that you will still get the error (since UAC is probably still enabled) and because of the registry corruptions. At this point, my goal is to get your internet back in safe mode and to get your USB working. We are going to have to try for small steps here.

Let me know if this provides any progress at all.
patndoris Is there an alternative source to download ComboFix.exe. They want to install 7zip installer and Yahoo toolbar and other extraneous, unrelated software which I would like to avoid. Their menu system is designed in a sneaky fashion and it seems impossible to avoid some of the Yahoo "stuff". Hopefully there is another source. Sorry to be a bother. vistabug
Please see my post above. Normally you would not have any of those problems with Combofix. It does not promote or install adware during it's normal installation. Just skip the Combofix step right now and move on to the the registry fixes I've listed. Please do not look for any alternate sources from which to download Combofix, as they are not authorized to host them and the contents are not verified and may harm your computer.

We are just going to keep working on the registry issues right now until Combofix is back online which will be very shortly and we can pick up with that step then. Let me know how the registry fixes go. I'm somewhat hopeful that you will have USB and internet back in safe mode with networking after this and then we will work on disabling UAC again and then audio. Let's cross our fingers!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI