This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"the specified service is not an installed service" [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello to whoever reads this. I'll do my best to go through the details of my issue and hope someone out there knows how to help. I am running Windows Vista Service Pack 2. I'll go in chronological order. I had McAfee installed on my system (the subscription for which was through my internet service provider). About a week or two ago my computer started having troubles downloading files (specifically, pdfs, if that matters). When I would try to download any pdf, such as my phone bill from my phone company's website, thd download would be killed by windows (or McAfee, I'm not sure which), saying something like, "the downloaded file contained a virus and was deleted" (I don't remember exact wording of that one). I am reasonably certain those pdfs did not contain viruses, as it happened several times while trying to download files from several independent reputable sources. That was my first indication of a problem. Coincidentally, I was in the process of switching internet service providers. Since I was going to be losing my subscription to McAfee, I decided to uninstall it (using the windows Uninstall/change option in the programs listing). That seemed to go fine- it uninstalled and then had me restart. When I restarted, and came back in to windows, my computer was in big trouble and hasn't been able to function since. I unable to connect to the internet in any way that I know of. The little pair of computers in bottom right toolbar (the ones that are usually bluish-green, indicating an internet connection), are now covered with a red X. When I hover my mouse over them, I get the error message, "the specified service is not an installed service". Likewise, when I hover over the volume button, which is also covered in a red X, I get the message that the audio system is not installed. I tried doing a system restore. In normal windows mode, I got the error something like, "c:\windows\system32\rstrui.exe is not an installed service". So I restarted my computer in "Safe Mode with Networking". From that safe mode, nothing above was fixed, except that I COULD do a system restore. It could find that file for some reason within that safe mode. So I tried restoring to 5 days ago (before I uninstalled McAfee), and to the oldest date possible which was two or three weeks ago, and neither restore fixed anything. The other relevant thing to say is that the computer will not recognize a USB key I plug in to it. I tried downloading your suggested hijackthis.exe from another computer onto a USB key, and then I was going to install it, run it, and copy the logfile in with this posting. But I can find no way to get the file from my USB onto my affected computer. Any ideas for that? Ok well, I'll sign off for now, thanks in advance for any reply! Josh
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.




Scan with FRST (Recovery Environment)


To run FRST on Vista and Windows7:
  • For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
  • For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.


To enter System Recovery Options from the Advanced Boot Options:

  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.


To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:

  • Startup Repair
  • System Restore
  • Windows Complete PC Restore
  • Windows Memory Diagnostic Tool
  • Command Prompt
  • Select Command Prompt

  • In the command window:
  • type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
  • Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
Hi there Marius. Thank you for your reply, and I will follow all of those rules you laid out.

I have completed the scan with frst.exe. Here are the contents of the frst.txt log file. Looks like I have the ZeroAccess virus?? I look forward to your reply, thanks again.


Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-07-2013
Ran by [removed] on 24-07-2013 18:52:44
Running from J:\
Windows Vista ™ Home Basic (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and Addition.txt log.

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [RtHDVCpl] - RtHDVCpl.exe [x]
HKLM\…\Run: [RemoteControl] - K\POWERDVD\PDVDSERV.EXE" [x]
HKLM\…\Run: [LanguageShortcut] - GUAGE.EXE" [x]
HKLM\…\Run: [Apanel] - EL.CMD [x]
HKLM\…\Run: [Skytel] - Skytel.exe [x]
HKLM\…\Run: [eRecoveryService] - [x]
HKLM\…\Run: [NVRaidService] - VRAIDSERVICE.EXE [x]
HKLM\…\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM\…\Run: [SunJavaUpdateSched] - FILES\JAVA\JAVA UPDATE\JUSCHED.EXE" [x]
HKLM\…\Run: [ALUAlert] - OTIFY.EXE" "/LOWDISKSPACE C" [x]
HKLM\…\Run: [AppleSyncNotifier] - OTIFIER.EXE [x]
HKLM\…\Run: [Adobe ARM] - FILES\ADOBE\ARM\1.0\ADOBEARM.EXE" [x]
HKLM\…\Run: [APSDaemon] - .EXE" [x]
HKLM\…\Run: [AdobeAAMUpdater-1.0] - FILES\ADOBE\OOBE\PDAPP\UWA\UPDATERSTARTUPUTILITY.EXE" [x]
HKLM\…\Run: [mcui_exe] - KEY [x]
HKLM\…\Run: [syshost32] - STALLER\{3E7CCB85-B112-40C7-AB08-BC188AC4EC55}\SYSHOST.EXE [x]
HKLM\…\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\…\Run: [iTunesHelper] - ESHELPER.EXE" [x]
HKU\Default\…\RunOnce: [RUN] - C:\Windows\Acer_Normal\run_DT.exe [x]
HKU\Default User\…\RunOnce: [RUN] - C:\Windows\Acer_Normal\run_DT.exe [x]
HKU\UpdatusUser\…\RunOnce: [RUN] - C:\Windows\Acer_Normal\run_DT.exe [x]
HKU\User\…\Run: [Sidebar] - "C:\Program Files\Windows Sidebar\Sidebar.exe" /autorun [x]
HKU\User\…\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [ 2008-01-20] (Microsoft Corporation)
HKU\User\…\Run: [Regedit32] - C:\Windows\system32\regedit.exe [x]
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
ShortcutTarget: Picture Motion Browser Media Check Tool.lnk -> C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)

========================== Services (Whitelisted) =================

S2 AdobeActiveFileMonitor10.0; C:\Program Files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-09-01] (Adobe Systems Incorporated)
S2 AdobeActiveFileMonitor7.0; C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [169312 2008-09-16] (Adobe Systems Incorporated)
S2 eRecoveryService; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [57344 2007-09-10] (Acer Inc.)
S2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
S2 McMPFSvc; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
S2 mcmscsvc; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
S2 McNaiAnn; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
S2 McNASvc; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [279048 2012-11-16] (McAfee, Inc.)
S2 McProxy; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
S2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [203840 2013-02-19] (McAfee, Inc.)
S2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [169320 2013-02-19] (McAfee, Inc.)
S2 mfevtp; C:\Windows\system32\mfevtps.exe [172416 2013-02-19] (McAfee, Inc.)
S2 MSK80Service; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [167784 2012-08-31] (McAfee, Inc.)
S2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-08] ()
S2 WebClient; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)
S2 WPDBusEnum; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [60920 2013-02-19] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [146872 2012-04-20] (McAfee, Inc.)
S2 int15; C:\Acer\Empowering Technology\eRecovery\int15.sys [15392 2007-07-02] (Acer, Inc.)
S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [133416 2013-02-19] (McAfee, Inc.)
S3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [235264 2013-02-19] (McAfee, Inc.)
S3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [65928 2013-02-19] (McAfee, Inc.)
S3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [363080 2013-02-19] (McAfee, Inc.)
S0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [565888 2013-02-19] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [92632 2013-02-19] (McAfee, Inc.)
S1 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [210608 2013-02-19] (McAfee, Inc.)
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 mfeavfk01; No ImagePath
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-24 18:52 - 2013-07-24 18:52 - 00000000 ____D C:\FRST
2013-07-12 02:07 - 2013-05-28 17:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-07-12 02:07 - 2013-05-28 17:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-07-12 02:07 - 2013-05-28 17:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-07-12 02:07 - 2013-05-28 17:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-07-12 02:07 - 2013-05-28 17:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-07-12 02:07 - 2013-05-28 17:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-07-12 02:07 - 2013-05-28 17:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\System32\url.dll
2013-07-12 02:07 - 2013-05-28 17:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-07-12 02:07 - 2013-05-28 17:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-07-12 02:07 - 2013-05-28 17:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-07-12 02:07 - 2013-05-28 17:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-07-12 02:07 - 2013-05-28 17:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-07-12 02:07 - 2013-05-28 17:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-07-12 02:07 - 2013-05-28 17:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-07-12 02:07 - 2013-05-28 17:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-07-12 02:07 - 2013-05-28 17:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-07-11 04:45 - 2013-06-03 17:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-07-11 04:45 - 2013-05-31 20:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\System32\qedit.dll
2013-07-11 04:45 - 2013-05-07 20:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL
2013-07-11 04:45 - 2013-04-17 03:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\System32\d3d10.dll
2013-07-11 04:45 - 2013-04-17 03:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll
2013-07-11 04:45 - 2013-04-17 03:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\System32\d3d10core.dll
2013-07-11 04:45 - 2013-04-17 03:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll
2013-07-11 04:45 - 2013-04-17 02:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll
2013-07-11 04:45 - 2013-04-17 02:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2013-07-11 04:45 - 2013-04-17 02:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\System32\d2d1.dll
2013-07-11 04:45 - 2013-04-17 02:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2013-07-11 04:45 - 2013-04-17 02:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\System32\FntCache.dll

==================== One Month Modified Files and Folders =======

2013-07-24 18:52 - 2013-07-24 18:52 - 00000000 ____D C:\FRST
2013-07-24 17:38 - 2006-11-02 04:45 - 00003216 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-24 17:38 - 2006-11-02 04:45 - 00003216 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-24 17:36 - 2006-11-02 02:33 - 00703516 _____ C:\Windows\System32\PerfStringBackup.INI
2013-07-24 17:22 - 2008-12-27 17:56 - 00000000 ____D C:\Users\User\Desktop\Josh
2013-07-24 17:21 - 2013-01-11 23:12 - 00001356 _____ C:\Users\User\AppData\Local\d3d9caps.dat
2013-07-23 18:11 - 2008-12-22 10:36 - 00000000 ___RD C:\Users\User\Desktop
2013-07-23 17:41 - 2008-12-22 08:28 - 01278137 _____ C:\Windows\WindowsUpdate.log
2013-07-22 20:36 - 2006-11-02 03:18 - 00000000 __RHD C:\Users\Public\Desktop
2013-07-22 20:20 - 2008-04-08 15:01 - 00000000 ____D C:\ProgramData\McAfee
2013-07-22 20:15 - 2012-12-25 19:56 - 00000000 ____D C:\Program Files\McAfee.com
2013-07-22 20:15 - 2012-12-25 19:56 - 00000000 ____D C:\Program Files\Common Files\Mcafee
2013-07-22 20:15 - 2012-12-25 19:55 - 00000000 ____D C:\Program Files\McAfee
2013-07-22 20:15 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\System32\spool
2013-07-22 20:15 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\System32\Msdtc
2013-07-22 20:15 - 2006-11-02 02:22 - 46661632 _____ C:\Windows\System32\config\software_previous
2013-07-22 20:15 - 2006-11-02 02:22 - 40370176 _____ C:\Windows\System32\config\components_previous
2013-07-22 20:15 - 2006-11-02 02:22 - 30146560 _____ C:\Windows\System32\config\system_previous
2013-07-22 20:15 - 2006-11-02 02:22 - 00786432 _____ C:\Windows\System32\config\default_previous
2013-07-22 20:15 - 2006-11-02 02:22 - 00262144 _____ C:\Windows\System32\config\security_previous
2013-07-22 20:15 - 2006-11-02 02:22 - 00262144 _____ C:\Windows\System32\config\sam_previous
2013-07-22 20:14 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\registration
2013-07-21 16:12 - 2008-01-20 19:02 - 03248580 _____ C:\Windows\PFRO.log
2013-07-12 02:45 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-12 02:36 - 2006-11-02 04:44 - 00311160 _____ C:\Windows\System32\FNTCACHE.DAT
2013-07-12 02:34 - 2010-02-12 16:57 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-12 02:33 - 2006-11-02 04:35 - 00000000 ____D C:\Windows\System32\XPSViewer
2013-07-12 02:10 - 2006-11-02 02:24 - 75699896 _____ (Microsoft Corporation) C:\Windows\System32\mrt.exe
2013-07-12 02:09 - 2008-04-08 14:25 - 00000000 ____D C:\ProgramData\Microsoft Help

Files to move or delete:
====================
C:\Users\User\1866876.exe

==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
C:\Program Files\Windows Defender\mpsvc.dll => ATTENTION: ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender

==================== EXE ASSOCIATION =====================

HKLM\…\.exe: exefile => OK
HKLM\…\exefile\DefaultIcon: %1 => OK
HKLM\…\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2013-06-30 23:58:00
Restore point made on: 2013-07-01 23:00:48
Restore point made on: 2013-07-02 23:14:52
Restore point made on: 2013-07-04 17:02:36
Restore point made on: 2013-07-05 19:13:34
Restore point made on: 2013-07-07 02:00:36
Restore point made on: 2013-07-07 02:02:09
Restore point made on: 2013-07-07 23:00:41
Restore point made on: 2013-07-08 23:00:37
Restore point made on: 2013-07-09 23:39:48
Restore point made on: 2013-07-10 23:24:40
Restore point made on: 2013-07-11 23:00:49
Restore point made on: 2013-07-12 02:00:32
Restore point made on: 2013-07-12 23:15:32
Restore point made on: 2013-07-13 23:00:48
Restore point made on: 2013-07-14 23:57:55
Restore point made on: 2013-07-15 23:00:50
Restore point made on: 2013-07-16 23:00:47
Restore point made on: 2013-07-17 23:28:03
Restore point made on: 2013-07-18 23:00:50
Restore point made on: 2013-07-20 12:11:37

==================== Memory info ===========================

Percentage of memory in use: 16%
Total physical RAM: 1790.63 MB
Available physical RAM: 1496.3 MB
Total Pagefile: 1732.79 MB
Available Pagefile: 1564.65 MB
Total Virtual: 2047.88 MB
Available Virtual: 1972.51 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:144.29 GB) (Free:8.84 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:144.04 GB) (Free:138.4 GB) NTFS
Drive j: () (Removable) (Total:14.9 GB) (Free:14.88 GB) FAT32
Drive x: (PQSERVICE) (Fixed) (Total:9.76 GB) (Free:3.27 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 298 GB) (Disk ID: 235BFA9F)
Partition 1: (Not Active) - (Size=10 GB) - (Type=27)
Partition 2: (Active) - (Size=144 GB) - (Type=06)
Partition 3: (Not Active) - (Size=144 GB) - (Type=07 NTFS)

========================================================
Disk: 5 (Size: 15 GB) (Disk ID: 2F964ECD)
Partition 1: (Active) - (Size=15 GB) - (Type=07 NTFS)


LastRegBack: 2013-07-24 07:21

==================== End Of Log ============================
Fix with FRST (normal mode)

  • Open notepad (Start =>All Programs => Accessories => Notepad).
  • Please copy the entire contents of the code box below.
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
  • Save it to the same direction as frst.exe (or frst64.exe) as fixlist.txt.

    HKLM\…\Run: [syshost32] - STALLER\{3E7CCB85-B112-40C7-AB08-BC188AC4EC55}\SYSHOST.EXE [x]
    HKU\User\…\Run: [Regedit32] - C:\Windows\system32\regedit.exe [x]
    
    C:\windows\Installer\{3E7CCB85-B112-40C7-AB08-BC188AC4EC55}
    C:\Users\User\1866876.exe
    
    DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
  • Run frst.exe (on 64bit, run frst64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.



Combofix

Combofix should only be run when adviced by a team member!

Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe

When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.

Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this.
Oops, I am sorry, I think I made a mistake. I ran the frst.exe Fix from still within "repair your computer" mode. After I did that, I noticed you had said normal mode. My log clearly shows that the "DeleteJunctionsIndirectory" command did not work, because I was not in the right mode. I stopped right there, and I did NOT run combofix, because I made this mistake. My apologies, here is the fixlog.txt that was created, please let me know how to proceed. Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 23-07-2013 Ran by [removed] at 2013-07-25 08:22:38 Run:1 Running from J:\ Boot Mode: Recovery ============================================== HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\syshost32 => Value deleted successfully. HKU\User\Software\Microsoft\Windows\CurrentVersion\Run\\Regedit32 => Value deleted successfully. C:\windows\Installer\{3E7CCB85-B112-40C7-AB08-BC188AC4EC55} => Moved successfully. C:\Users\User\1866876.exe => Moved successfully. Error: DeleteJunctionsIndirectory: C:\Program Files\Windows Defender => entry should be fixed outside recovery mode. ==== End of Fixlog ====
Ok I tried to run Combofix and I was unable to. I downloaded it onto my USB key from the link you provided (using a different computer, that does have access to the internet). I then put it in my infected computer and I copied it to my desktop. I did this by opening a command prompt and typing "copy j:\combofix.exe c:\users\user\desktop\". This seemed to work, because the icon then appeared on my desktop. However, any way I try to run it, such as: 1) by double clicking on the icon 2) by right clicking on the icon and then clicking on "Open", "Run as administrator", or "start" 3) by opening a command prompt and typing c:\users\user\desktop\combofix.exe gives me a pop up box with the error message, "c:\users\user\desktop\combofix.exe does not exist as an installed service." I will wait until I next hear from you on how to proceed.
Ok, I have a few things to report here. The first time I tried to run combofix, it gave me a warning that my McAfee antivirus software was active and that that could interfere with combofix. However (if you read my first post), I had uninstalled McAfee, which is what started all these problems. I had then tried a couple of system restores, and after those restores, the McAfee icon appeared again. But when I tried to uninstall it, (through the Windows uninstall program option), Windows informed me it had already been uninstalled.

Furthermore, when I opened the McAfee Security Center, both the Real-Time Scanning and the Firewall were off. So, I assumed this meant McAfee was actually NOT active. So, I went ahead and ran combofix.

It seemed to run fine, except that maybe it has stalled near the end of its run? It has left me with a window titled, "Administrator: ComboFix - Find 3M", the contents of which says: "Almost done … This window will close in a short while. Please wait a few seconds for the report log to pop up. Combofix's log shall be located at C:\COMBOFIX.TXT".

I have now waited several hours for this window to disappear, since it says it would. It is still up on my screen. So, I went ahead and grabbed the combofix.txt log file anyway, because it seems to have been created and completed.

So:
1) Should I close the Combofix window that remains open? Or is it still working and I should leave it open?
2) What is the next step?

Here is the combofix.txt log file. It seems to think that the McAfee antivirus and firewall were enabled, but again, I made sure they were both disabled. I don't even think McAfee is properly installed anymore anyway, so I don't know how it could be enabled and functioning. I look forward to your response.


ComboFix 13-07-25.02 - User 26/07/2013 17:57:38.1.2 - x86 MINIMAL
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.2.1033.18.1791.1356 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2013-06-27 to 2013-07-27 )))))))))))))))))))))))))))))))
.
.
2013-07-27 01:03 . 2013-07-27 01:04 ——– d—–w- c:\users\User\AppData\Local\temp
2013-07-27 01:03 . 2013-07-27 01:03 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp
2013-07-27 01:03 . 2013-07-27 01:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-07-25 02:52 . 2013-07-25 02:52 ——– d—–w- C:\FRST
2013-07-11 12:45 . 2013-06-04 01:50 2049024 —-a-w- c:\windows\system32\win32k.sys
2013-07-11 12:45 . 2013-04-17 10:10 1069056 —-a-w- c:\windows\system32\DWrite.dll
2013-07-11 12:45 . 2013-04-17 10:10 798208 —-a-w- c:\windows\system32\FntCache.dll
2013-07-11 12:45 . 2013-04-17 11:28 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2013-07-11 12:45 . 2013-04-17 11:28 189952 —-a-w- c:\windows\system32\d3d10core.dll
2013-07-11 12:45 . 2013-04-17 10:33 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2013-07-11 12:45 . 2013-04-17 11:28 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2013-07-11 12:45 . 2013-04-17 11:28 1029120 —-a-w- c:\windows\system32\d3d10.dll
2013-07-11 12:45 . 2013-04-17 10:34 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2013-07-11 12:45 . 2013-04-17 10:14 683008 —-a-w- c:\windows\system32\d2d1.dll
2013-07-11 12:45 . 2013-06-01 04:06 505344 —-a-w- c:\windows\system32\qedit.dll
2013-07-11 12:45 . 2013-05-08 04:04 1548288 —-a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-11 12:45 . 2013-04-09 03:51 936960 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 04:10 . 2012-10-06 00:29 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-12 04:10 . 2011-12-15 15:51 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-08 04:37 . 2013-06-13 02:32 905576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-05-02 22:03 . 2013-06-13 02:31 3603832 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-02 22:03 . 2013-06-13 02:31 3551096 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-05-02 04:04 . 2013-06-13 02:32 443904 —-a-w- c:\windows\system32\win32spl.dll
2013-05-02 04:03 . 2013-06-13 02:32 37376 —-a-w- c:\windows\system32\printcom.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\Sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcui_exe"="KEY" [X]
"RtHDVCpl"="RtHDVCpl.exe" [2008-03-26 5369856]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe /noballoononstart [2008-12-28 385024]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
ASETRES.EXE [2008-4-14 20480]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe 9999 [2008-4-8 535336]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
R2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;c:\program files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [2011-09-01 169624]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2013-07-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-06 04:10]
.
2013-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-06 00:01]
.
2013-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-06 00:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&s=1&o=vb32&d=1208&m=aspire_m1640
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
Trusted Zone: intuit.com\globalcommunities
TCP: DhcpNameServer = [removed] [removed]
Handler: intu-tt2011 - {B3B5DAD9-E96D-45b4-B636-B6CF2F773DE1} - c:\program files\TurboTax 2011\ic2011pp.dll
Handler: intu-tt2012 - {02F985EF-502B-4597-993F-6BF9E004C138} - c:\program files\TurboTax 2012\ic2012pp.dll
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-RemoteControl - K\POWERDVD\PDVDSERV.EXE
HKLM-Run-LanguageShortcut - GUAGE.EXE
HKLM-Run-Apanel - EL.CMD
HKLM-Run-eRecoveryService - (no file)
HKLM-Run-NVRaidService - VRAIDSERVICE.EXE
HKLM-Run-SunJavaUpdateSched - FILES\JAVA\JAVA UPDATE\JUSCHED.EXE
HKLM-Run-ALUAlert - OTIFY.EXE
HKLM-Run-AppleSyncNotifier - OTIFIER.EXE
HKLM-Run-Adobe ARM - FILES\ADOBE\ARM\1.0\ADOBEARM.EXE
HKLM-Run-APSDaemon - .EXE
HKLM-Run-AdobeAAMUpdater-1.0 - FILES\ADOBE\OOBE\PDAPP\UWA\UPDATERSTARTUPUTILITY.EXE
HKLM-Run-iTunesHelper - ESHELPER.EXE
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-07-26 18:04
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-07-26 18:06:55
ComboFix-quarantined-files.txt 2013-07-27 01:06
.
Pre-Run: 21,969,915,904 bytes free
Post-Run: 22,136,631,296 bytes free
.
- - End Of File - - FD61D8C147BF5B847DE192307B307327
A863475757CC50891AA8458C415E4B25
ESET Services Repair

Download ESET services repair from here and save the file to your desktop.

Run it by right click –> "run as administrator".

After the tool is finished, reboot.
Ok I ran the ESET Services Repair. When I rebooted into normal mode, Windows gave me a message that said the Recycle Bin on C:\ has been corrupted, would you like to empty it? I clicked yes. Now my computer is sitting here (in normal mode). It still says all the same things though: the internet is not an installed service, the audio service is not running, and the system restore (which I just tried to find experimentally) is also not an installed service. I will wait to hear from you before doing anything else. Thanks.
Ok well thank you. I am aware I could (theoretically) re-install windows, instead of going through all of this. However, when they sold me the computer they did NOT provide me with a copy of a Vista re-install disk (they almost never do anymore). So this most recent suggestion of yours is not an option for me. Any other ideas, or is my computer just dead? Is it a possibility that the ability to re-install exists somewhere in a partition of my hard drive, instead of on a separate disk? Also, I will remind you that when I originally ran the "Fix with FRST" step, I did not do it in normal mode (I was in repair/recovery mode) and so the DeleteJunctionsIndirectory command appeared to have an error, as displayed in the log. Is it possible that by re-running this step properly, and proceeding forward from there, that I might have better results?
The problem isn´t the FRST fix but the damaged windows system.
We can give this a shot:

Windows Repair (all-in-one)

Please download Windows Repair (all in one) from here.

Install the program then run it.

Go to step 2 and allow it to run Disk check.

[external image: Posted Image]

Once that is done then go to step 3 and allow it to run SFC by clicking Do it

[external image: Posted Image]


On the Start Repairs tab, click Start.
Within the opening window, hit unselect all.
Check only the following:



  • Reset Registry Permissions
  • Reset File Permissions
  • Register System Files
  • Repair Windows Firewall
  • Repair Windows Updates

then click on Start

DON'T use the computer while each scan is in progress.

Restart may be needed to finish the repair procedure.

Let me know how that worked out for you.
Ok well I ran "Windows Repair (all in one)". It looked promising, but then ended up with the exact same result. Everything is "not an installed service". I should comment that I had to run it in safe mode, just like everything else I've run, because in normal mode any attempt to run it makes the computer produce the "not an installed service" error. When I began running Windows Repair, it warned me that running in safe mode might prevent some of its fixes from working. So maybe that's why it didn't work, but I don't know how I can run it in normal mode anyway. Would you like me to post the log files? There appeared to be several of them, so maybe let me know which ones, or if you want all of them.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI