This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

The specified service does not exist as an installed service [Solved]

71 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

patndoris

http://download.bleepingcomputer.com/win-s…s/vista/nsi.reg
http://download.bleepingcomputer.com/win-s…ta/PlugPlay.reg
http://download.bleepingcomputer.com/win-s…ista/Netman.reg

I ran the 3 acripts above



I Booted the computer in Safe Mode WITH NETWORKING -

I did this and there was no apparent improvement.

Connect to a Network shows wifi networks but cannot connect. Get same error message:

"The specified service does not exist as an installed service".


However, there seems to be improvement with the USB.

After booting in Safe Mode WITH NETWORKING I was able to access the USB drive.

Before the fix the USB was only available if I booted with the USB already plugged in. Baby steps!
Fantastic! We'll take one baby step at at time :)

Let's try for a few more. I've researched some additional networking and audio services and let's give those a try.

http://download.bleepingcomputer.com/win-s…ointBuilder.reg
http://download.bleepingcomputer.com/win-s…ta/Audiosrv.reg
http://download.bleepingcomputer.com/win-s…a/WebClient.reg
http://download.bleepingcomputer.com/win-s…sta/lmhosts.reg
http://download.bleepingcomputer.com/win-s…sta/SSDPSRV.reg

The goal here is for internet and audio. This is going to be a bit of trial and error since we don't know precisely what has been damaged by the virus. These are all services that should be set to automatic by default on Vista so we aren't enabling anything here that would be out of the ordinary just so you don't worry.

After doing these, reboot the machine, and then let me know if we have any further improvement.
Wait! after running the 3 scripts I discovered that the internet in safe mode works and fully booted mode is working also! Many baby steps! The Network and Sharing Center still shows the message "The specified service does not exist as an installed service" and I cannot open The Network and Sharing Center, but the internet now works. Sorry my prior message was wrong. vistabug,
patndoris I ran the 5 registry scripts you provided in Post 17. I did a full reboot. I tried various applications, MS Word, Excel, Firefox, Eclipse, PKZIP. I listened to WXPN over my speakers. I see no obvious issues. The only weird thing I can see The Network and Sharing Center still shows a red "X" in the system tray. But I can still connect to the internet. There is also a message: "Connection status: unknown. Followed by :The specified service does not exist as an installed service" I guess that is still a problem. Let me know your thoughts vistabu
Fantastic! So we have USB, audio and internet back. That's great! Regardless of whether it's in normal or safe mode, that makes working on the machine much easier.

Once again, I do not anticipate this will correct the error you were receiving - but we want to start looking for and removing any malware that may stil be lingering on the machine before we continue fixing any remaining issues. Now that we have internet back and availalbe it becomes much easier to do so :)

The glitch with Combofix has been worked out so let's move ahead with those directions now:

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop but do not run it yet.

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

NoOrphans::


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe which will cause it to run.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

If you have a problem launching programs (where you receive a notification that they have been marked for deletion) after running Combofix, please do not panic! Simply reboot the computer and all should be fine.
PATNDORIS I need another night to run combofix properly - I tried to shutoff Mcfee Security and it took me too long to figure it out.. I finally did figure it out. Will run it Monday. Go Ravens!!
Being from Baltimore (and with a Go Ravens in there!)I how can I possibly deny you another night to run Combofix after such a great game last night? :D Seriously, I'm in this for the long haul with you. Take the time you need to run the steps. I'm not going anywhere as long as you are still with me. I'll be right here when you've run it.
Patndoris - I graduated from Western Maryland college, now McDaniel. My son lives in Baltimore. We have many ties to that city.

See the log file pasted below from ComboFix. Let me know your thoughts…..

ComboFix 13-02-03.03 - bconnor 02/04/2013 21:51:08.1.2 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.3581.2398 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\bconnor\Desktop\CFScript.txt.txt
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\users\bconnor\AppData\Local\assembly\tmp
c:\users\bconnor\g2mdlhlpx.exe
C:\data . . . . Failed to delete
c:\data\MSSQL\MaineHealth_2.LDF . . . . Failed to delete
c:\data\MSSQL\MaineHealth2.mdf . . . . Failed to delete
.
.
((((((((((((((((((((((((( Files Created from 2013-01-05 to 2013-02-05 )))))))))))))))))))))))))))))))
.
.
2014-12-01 22:06 . 2014-12-01 22:06 ——– d—–w- c:\users\bconnor\AppData\Local\Axure
2014-12-01 22:05 . 2014-12-01 22:05 ——– d—–w- c:\users\bconnor\AppData\Local\IsolatedStorage
2014-12-01 22:05 . 2014-12-01 22:05 ——– d—–w- c:\programdata\Axure
2014-12-01 22:05 . 2014-12-01 22:05 ——– d—–w- c:\users\bconnor\AppData\Roaming\Axure
2013-02-05 03:16 . 2013-02-05 03:16 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-02-02 01:45 . 2012-10-31 04:39 261600 —-a-w- c:\program files\Mozilla Firefox\updated\components\browsercomps.dll
2013-02-02 01:45 . 2010-08-20 14:04 119808 —-a-w- c:\program files\Mozilla Firefox\updated\components\GoogleDesktopMozilla.dll
2013-02-02 01:45 . 2012-10-31 04:39 73696 —-a-w- c:\program files\Mozilla Firefox\updated\breakpadinjector.dll
2013-02-02 01:45 . 2012-10-31 04:39 18912 —-a-w- c:\program files\Mozilla Firefox\updated\AccessibleMarshal.dll
2013-01-17 06:20 . 2013-01-17 06:20 ——– d—–w- C:\FRST
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-31 03:57 . 2012-10-23 20:02 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-31 03:57 . 2012-10-23 20:02 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-14 21:49 . 2012-11-16 01:54 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-09-13 03:05 . 2009-09-13 03:05 124240 —-a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll
2009-09-13 03:06 . 2009-09-13 03:06 13136 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2009-09-13 03:06 . 2009-09-13 03:06 70488 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2009-09-13 03:06 . 2009-09-13 03:06 91480 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2009-09-13 03:06 . 2009-09-13 03:06 22360 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2009-09-13 03:07 . 2009-09-13 03:07 255312 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2009-09-13 03:06 . 2009-09-13 03:06 31064 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2009-09-13 03:06 . 2009-09-13 03:06 40280 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2009-08-14 17:33 . 2009-08-14 17:33 652640 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2009-09-13 03:06 . 2009-09-13 03:06 23896 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2013-02-04 03:56 . 2011-11-15 22:56 262552 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-08-20 14:04 . 2009-11-06 03:54 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2011-04-14 18:01 . 2010-09-23 18:25 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 —-a-w- c:\users\bconnor\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 —-a-w- c:\users\bconnor\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 —-a-w- c:\users\bconnor\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-04-17 04:13 721408 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-04-17 04:13 721408 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-24 68856]
"googletalk"="c:\users\bconnor\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="VSTARTUP" [X]
"NvMediaCenter"="IT" [X]
"DellSupportCenter"="TER" [X]
"mcui_exe"="KEY" [X]
"Communicator"="KEY" [X]
"ECenter"="CHER.EXE" [N/A]
"Apoint"="T.EXE" [N/A]
"OEM02Mon.exe"=".EXE" [N/A]
"NVHotkey"="VHOTKEY.DLL" [N/A]
"UpdReg"="DOWS\UPDREG.EXE" [N/A]
"PSQLLauncher"="CHER.EXE" [N/A]
"IAAnotif"="OTIF.EXE" [N/A]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-20 30192]
"dscactivate"="T\CUSTOM\DSCA.EXE" [N/A]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-13 405504]
"SCCSwitcher"="c:\program files\TamTam CVS SCC\SCCSwitcher.exe" [2008-12-11 69632]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="ESHELPER.EXE" [N/A]
"ConnectionCenter"="TR.EXE" [N/A]
"AdobeAAMUpdater-1.0"="FILES\ADOBE\OOBE\PDAPP\UWA\UPDATERSTARTUPUTILITY.EXE" [N/A]
"XeroxRegistation"="OR\APPDATA\LOCAL\TEMP\XEROX\EREG\EREG.EXE" [N/A]
"SignIn"=".EXE" [N/A]
"EEventManager"="AGER.EXE" [N/A]
"FUFAXRCV"="SOFTWARE\FAX UTILITY\FUFAXRCV.EXE" [N/A]
"FUFAXSTM"="SOFTWARE\FAX UTILITY\FUFAXSTM.EXE" [N/A]
"SunJavaUpdateSched"="FILES\JAVA\JAVA UPDATE\JUSCHED.EXE" [N/A]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
Snagit 11.lnk - c:\program files\TechSmith\Snagit 11\Snagit32.exe [2012-5-16 9063352]
VPN Client.lnk - c:\windows\Installer\{1CE60928-8325-49A8-8B06-633E48DD2B67}\Icon3E5562ED7.ico [2011-12-14 6144]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-04-17 04:04 86528 —-a-w- c:\windows\System32\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
Authentication Packages REG_MULTI_SZ msv1_0 setuid
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
.
2013-02-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-23 03:57]
.
2013-02-04 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-24 19:30]
.
2013-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-20 22:51]
.
2013-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-20 22:51]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Open with XmlPad - c:\program files\WMHelp Software\WMHelp XmlPad\WmhASPP.dll/101
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: google.com\www
Trusted Zone: mainehealthlink.com
Trusted Zone: mmc.com
TCP: DhcpNameServer = 192.168.1.1
Handler: wmh - {A1428E78-2D00-4590-A071-0CC9700A7768} - c:\program files\WMHelp Software\WMHelp XmlPad\WmhASPP.dll
FF - ProfilePath - c:\users\bconnor\AppData\Roaming\Mozilla\Firefox\Profiles\beg4gcam.default\
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-{52CF142B-7B0E-41E7-98F5-B834122523E7}_is1 - c:\program files\Programmer's Notepad\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-04 22:27
Windows 6.0.6001 Service Pack 1 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msftesql]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:MSSQLSERVER"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(884)
c:\windows\system32\setuid.dll
c:\windows\system32\psqlpwd.dll
c:\program files\Fingerprint Reader Suite\homefus2.dll
c:\program files\Fingerprint Reader Suite\infra.dll
.
- - - - - - - > 'Explorer.exe'(5908)
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\users\bconnor\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
c:\program files\Fingerprint Reader Suite\farchns.dll
c:\program files\Fingerprint Reader Suite\infra.dll
c:\windows\system32\btncopy.dll
c:\program files\WinSCP\DragExt.dll
c:\windows\System32\ntlanman.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvvsvc.exe
c:\program files\Dell\DellDock\DockLogin.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\rundll32.exe
c:\program files\Fingerprint Reader Suite\upeksvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\atashost.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\cvsnt\cvsservice.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\EPSON\EpsonCustomerParticipation\EPCP.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe
c:\program files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSvcm.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\STacSV.exe
c:\program files\Common Files\McAfee\SystemCore\mfefire.exe
c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe
c:\program files\TechSmith\Snagit 11\TSCHelp.exe
c:\program files\TechSmith\Snagit 11\SnagPriv.exe
c:\program files\TechSmith\Snagit 11\snagiteditor.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
.
**************************************************************************
.
Completion time: 2013-02-04 22:49:52 - machine was rebooted
ComboFix-quarantined-files.txt 2013-02-05 03:49
.
Pre-Run: 158,939,107,328 bytes free
Post-Run: 160,389,328,896 bytes free
.
- - End Of File - - AF39D17347815DF1A95766E662CE81AF
Well it's good to work with someone who has ties to where I live :) Not often I get to do that. Lived here all my life within 20 minutes of there :D (But amazingly I don't eat crabs :blush: )

OK back to work here!

Let's take a step back and review now so I make sure I'm not missing anything and have not overlooked anything. If you don't mind, please re-verify the following:

  • We are working in normal mode now not safe mode.
  • USB is working properly.
  • We have internet. (except for the Red X on the connection status followed by the error only on this item)
  • We have audio.
  • We are no longer getting the error about the specified service when running programs (except as noted above)
How is the machine running overall at this point? Any other specific issues still going on?


There are a number of ways to address the registry corruptions and how we do may depend a bit upon how the machine is behaving overall at this point.
patndoris The only issue that might require attention is: The Network and Sharing Center still shows the red" X" and still shows message "The specified service does not exist as an installed service". Also and I cannot open The Network and Sharing Center, but the internet now works. Everything else still seems to work fine. Is there anything you think I should check for potential problems? vistabug
Let's try another three registry merges and see if this helps any. This Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change. These three entries are all kind of interdependent upon one another so we have to do them all. You know how they are done :)

Be sure to reboot the machine after you do them and then see if we have any changes after you are done.

http://download.bleepingcomputer.com/win-s…ta/netprofm.reg
http://download.bleepingcomputer.com/win-s…ista/NlaSvc.reg
http://download.bleepingcomputer.com/win-s…/SLUINotify.reg

This will hopefully help with the Red X over the connection in the task bar. I definitely do NOT want to leave you unable to access Network and Sharing center. But let's address the problem one step at a time here.

I'd also like you after you have done this to run the following scan and post the results. This is a double check for any further malware:


This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

If it doesn't find anything there will be no log to post.
patndoris Set back! When I tried to run the latest 3 Registry scripts the dreaded message appears: "The specified service does not exist as an installed service". and the script fails to run. Not sure what to do next. vistabug
It's ok, it's not a setback, it's just not a step forward as we'd hoped.


Let's also try the ESET services repair again now that you have internet access available and it's easier to run:

Please download ESET's ServiceRepair.exe to your desktop.

Double-click on the file and click Yes on the first Message box.
When done, the tool will ask for a reboot to complete the fix. Please allow it.
If it doesn't ask you to reboot your PC, please perform a manual reboot.


And I'd also like to do the following tool which repairs many items that malware can damage. Since we've been able to run Combofix now, I think it's ok to go ahead and run this tool and see if it can fix anything else for you now. We are sort of in "damage control" mode to fix things that the malware has changed to get you back up to where you should be and this automates some of the process and may look in many places we wouldn't think to check.

Windows Repair (All In One) from Tweaking.com.

Windows Repair is an all-in-one repair tool to help fix a large majority of known Windows problems including registry errors and file permissions as well as issues with Internet Explorer, Windows Update, Windows Firewall and more. Malware and installed programs can modify your default settings. With Tweaking.com - Windows Repair you can restore Windows original settings.


Please follow the instructions found here for running this tool and then post back and let me know how the machine seems to be behaving now.


If at this point you are still having the Red X issue then let's talk about if any of the last set of merges worked? Or did you get the error on the first one and then stop? If so, please go ahead and try the other two and see if they work. They don't have to be done in order - we just want to get all three done. In fact, if you can get one to work, it might be best to reboot, then do the next one, reboot, and so on. Even if we narrow it down to which one or ones don't work that's something we can work with. We can manually edit the registry if we need to (it's just not preferable).


I'll be waiting to hear where we stand after this! We will beat this. Persistence pays off (plus I can always pick the brains of my colleagues if I run out of ideas). But we still have a few more tools up our sleeves. We have the majority of the issues solved, if it were just the red X I might be ok, but I'm not OK with you not being able to open network and sharing center. We most certainly need to have that fixed. So I hope you can hang in there with me a bit longer. :)
I ran ServicRepair.exe but it had to be in Safe mode or else it would not run. I also ran Windows Repair (All In One) from Tweaking.com also in safe mode.It is still running. I will send update tomorrow. vistabug
The screen is black! Big trouble…In my prior post I ran ServicRepair.exe but it had to be in Safe mode or else it would not run. MY laptop seemed OK after that except that the red X was still a problem. I also ran Windows Repair (All In One) from Tweaking.com. I did create a registry backup and a "Restore point" as the software advised. It ran into the night. I restarted the next evening. It then required a long check disk procedure again over night. Now this evening I try to restart the laptop normally and in safe mode. It seems to boot but the screen is black! Hopefully I can employ one of the backups I created to bring it back to life. Not sure how to do it with a dark screen. Thanks for your help with this vistabug

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI