TechSpot

The specified service does not exist as an installed service

Solved
By xialoin
Jan 18, 2013
  1. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    When ComboFix is done, where will I find the log that I need to paste here?
     
  2. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    ComboFix 13-01-17.04 - Kate 19/01/2013 1:37.1.2 - x86 MINIMAL
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.2942.2451 [GMT 0:00]
    Running from: F:\ComboFix.exe
    * Created a new restore point
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    D:\install.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-12-19 to 2013-01-19 )))))))))))))))))))))))))))))))
    .
    .
    2013-01-19 06:27 . 2013-01-19 06:27--------d-----w-C:\FRST
    2013-01-19 00:46 . 2008-05-08 05:03303616----a-w-C:\SetACL.exe
    2013-01-19 00:29 . 2004-06-11 23:33290304----a-w-C:\subinacl.exe
    2013-01-19 00:03 . 2013-01-19 00:57--------d-----w-C:\Tweaking.com_Windows_Repair_Logs
    2013-01-19 00:03 . 2013-01-19 00:03--------d-----w-c:\program files\Tweaking.com
    2013-01-18 21:23 . 2013-01-18 21:23--------d-----w-c:\users\Kate\AppData\Roaming\Malwarebytes
    2013-01-18 21:23 . 2013-01-18 21:23--------d-----w-c:\programdata\Malwarebytes
    2013-01-18 21:23 . 2012-12-14 16:4921104----a-w-c:\windows\system32\drivers\mbam.sys
    2013-01-18 21:23 . 2013-01-18 21:23--------d-----w-c:\program files\Malwarebytes' Anti-Malware
    2013-01-18 21:23 . 2013-01-18 21:23--------d-----w-c:\users\Kate\AppData\Local\Programs
    2013-01-09 17:53 . 2013-01-09 17:59--------d-----w-c:\users\Kate\AppData\Local\Microsoft Games
    2012-12-21 16:39 . 2012-12-16 14:13295424----a-w-c:\windows\system32\atmfd.dll
    2012-12-21 16:39 . 2012-12-16 14:1334304----a-w-c:\windows\system32\atmlib.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-12-14 19:50 . 2012-05-04 07:04697272----a-w-c:\windows\system32\FlashPlayerApp.exe
    2012-12-14 19:50 . 2011-09-15 17:5773656----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-11-22 02:56 . 2012-12-12 19:382345984----a-w-c:\windows\system32\win32k.sys
    2012-11-12 11:52 . 2012-12-12 19:361638912----a-w-c:\windows\system32\mshtml.tlb
    2012-11-09 06:56 . 2011-06-09 17:3960480----a-w-c:\windows\system32\drivers\cfwids.sys
    2012-11-09 06:53 . 2011-06-09 17:39210136----a-w-c:\windows\system32\drivers\mfewfpk.sys
    2012-11-09 06:53 . 2011-06-09 17:29167344----a-w-c:\windows\system32\mfevtps.exe
    2012-11-09 06:52 . 2011-06-09 17:409648----a-w-c:\windows\system32\drivers\mfeclnk.sys
    2012-11-09 06:52 . 2011-06-09 17:3992192----a-w-c:\windows\system32\drivers\mferkdet.sys
    2012-11-09 06:51 . 2011-03-13 10:20565352----a-w-c:\windows\system32\drivers\mfehidk.sys
    2012-11-09 06:50 . 2011-06-09 17:39362640----a-w-c:\windows\system32\drivers\mfefirek.sys
    2012-11-09 06:50 . 2011-06-09 17:3965488----a-w-c:\windows\system32\drivers\mfebopk.sys
    2012-11-09 06:49 . 2011-06-09 17:39234824----a-w-c:\windows\system32\drivers\mfeavfk.sys
    2012-11-09 06:49 . 2011-03-13 10:20132912----a-w-c:\windows\system32\drivers\mfeapfk.sys
    2012-11-09 04:42 . 2012-12-12 19:362048----a-w-c:\windows\system32\tzres.dll
    2012-11-02 05:11 . 2012-12-12 19:37376832----a-w-c:\windows\system32\dpnet.dll
    2012-10-27 06:26 . 2012-12-12 19:36981504----a-w-c:\windows\system32\wininet.dll
    2012-10-22 16:30 . 2012-10-22 16:30163056----a-w-c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10142.bin
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{7473b6bd-4691-4744-a82b-7854eb3d70b6}"= "c:\program files\uTorrentControl_v2\prxtbuTor.dll" [2011-05-09 176936]
    .
    [HKEY_CLASSES_ROOT\clsid\{7473b6bd-4691-4744-a82b-7854eb3d70b6}]
    .
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4DB74D06-491C-440D-305E-012400990F3E}]
    2009-07-14 01:1573728----a-w-c:\windows\System32\coomcat.dll
    .
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}]
    2011-05-09 09:49176936----a-w-c:\program files\uTorrentControl_v2\prxtbuTor.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{7473b6bd-4691-4744-a82b-7854eb3d70b6}"= "c:\program files\uTorrentControl_v2\prxtbuTor.dll" [2011-05-09 176936]
    .
    [HKEY_CLASSES_ROOT\clsid\{7473b6bd-4691-4744-a82b-7854eb3d70b6}]
    .
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{7473B6BD-4691-4744-A82B-7854EB3D70B6}"= "c:\program files\uTorrentControl_v2\prxtbuTor.dll" [2011-05-09 176936]
    .
    [HKEY_CLASSES_ROOT\clsid\{7473b6bd-4691-4744-a82b-7854eb3d70b6}]
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MobileDocuments"="c:\program files\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"="OLOGIES\ATI.ACE\CORE-STATIC\CLISTART.EXE MSRUN" [X]
    "TWebCamera"="\TWEBCAMERA.EXE AUTORUN" [X]
    "mcui_exe"="KEY" [X]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
    "Toshiba TEMPRO"="c:\program files\Toshiba TEMPRO\TemproTray.exe" [2009-08-06 1050000]
    "SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-07-09 352256]
    "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 425984]
    "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-08-13 521528]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-28 7625248]
    "SmartFaceVWatcher"="c:\program files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [2009-07-29 163840]
    "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-03 611672]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-12-14 512360]
    "Z1"="c:\users\Kate\Desktop\mbar\mbar.exe" [2013-01-09 1356360]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "TOSHIBA Online Product Information"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2009-08-12 6203296]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    .
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
    R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [x]
    R2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [x]
    R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
    R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x]
    R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x]
    R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x]
    R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x]
    R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x]
    R2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [x]
    R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
    R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\Toshiba TEMPRO\TemproSvc.exe [x]
    R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [x]
    R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
    R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys [x]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
    R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
    R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
    R3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
    R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
    R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
    R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
    R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
    R3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
    R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
    S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
    .
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2013-01-18 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-04 19:50]
    .
    2013-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-09-29 11:31]
    .
    2013-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-09-29 11:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.wp.pl/
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    TCP: DhcpNameServer = 192.168.1.254
    DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - hxxp://assets.photobox.com/assets/v/ra3RgI_VSoCPalw7aL2ig_0fSS8.cab
    .
    - - - - ORPHANS REMOVED - - - -
    .
    HKLM-Run-TosNC - CCORE.EXE
    HKLM-Run-TosReelTimeMonitor - ITOR.EXE
    HKLM-Run-KeNotify - OTIFY.EXE
    HKLM-Run-TPwrMain - .EXE
    HKLM-Run-00TCrdMain - .EXE
    HKLM-Run-SynTPEnh - H.EXE
    HKLM-Run-ToshibaServiceStation - .EXE
    HKLM-Run-Toshiba Registration - DER.EXE
    HKLM-Run-AppleSyncNotifier - OTIFIER.EXE
    HKLM-Run-WinampAgent - AMPA.EXE
    HKLM-Run-APSDaemon - .EXE
    HKLM-Run-iTunesHelper - ESHELPER.EXE
    HKLM-RunOnce-Malwarebytes Anti-Malware (cleanup) - c:\users\Kate\AppData\Local\Temp\Rar$EX00.703\mbar\Data\cleanup.dll
    AddRemove-Bloxxit - d:\gry\Bloxit\uninstal.exe
    .
    .
    .
    Completion time: 2013-01-19 01:46:46
    ComboFix-quarantined-files.txt 2013-01-19 01:46
    .
    Pre-Run: 120,858,779,648 bytes free
    Post-Run: 121,645,056,000 bytes free
    .
    - - End Of File - - E1FC386E1E7AC62A97C389E2E8F93DDC
     
  3. Broni

    Broni Malware Annihilator Posts: 47,048   +256

  4. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    So how did it all start then? From nothing? Not a virus? I haven't deleted anything in the past month or two! Now, if we can't restore my windows to like, 3 weeks back, even 6 hours ago, then there is nothing left other than reinstalling windows and loosing all the files right? In that case, even if I wanted to do that, I haven't been given the Windows 7 CD. This leaves me with piracy.. So really? Nothing I can do about that now? And you said 'Surely we will fix that'..
     
  5. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    Dude! There has to be something! You can't just say no and give up on this. Please.. Can't we possibly use one of those programs to see what file we accidentaly deleted and then like restore it?
     
  6. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    There is no reason to get upset with me.
    I didn't do anything to your computer.
    I'm only trying to help to the best of my knowledge.

    Then, apparently you even didn't check my link.
    If you did you'd know that repair installation will not disturb your data (backing up your data is always recommended though, even when your computer is fine).
    If you don't have Windows DVD you can easily create it without pirating anything.
    See my manual here: http://www.smartestcomputing.us.com...ble-dvd-or-usb-for-your-version-of-windows-7/
    In order to run repair installation you'll have to uninstall Service Pack 1.
     
  7. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    Please be polite.
    You're not the only person I'm helping so I can't reply to your reply in a split second.
     
  8. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    I'am polite, it's 02:30 in UK, I'm really tired, I'm starting work at 6am! I have probably less than 3 hours of sleep left now because of this stupid laptop, everyone would be annoyed at least a little that after all this you just get a message that you can't really solve this.. Sorry but I appreciate your help!
     
  9. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

  10. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    I strongly suggest you get some sleep.
    Rushing things up is never a good idea.

     
  11. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    You think so? I'll take the laptop to work tomorrow, well now it's today actually, and at about 12 I will try to uninstall my Service Pack 1 but hang on a minute.. I thought you can't uninstall it if it was already there when you bought the laptop. What then?
     
     
  12. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    Service Pack can always be uninstalled.
     
  13. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    Ok, I think I'll get some sleep now. Or might aswell just stay up :p When I will be installing my new Windows 7, will it ask for the key that I have on the sticker on the bottom of my laptop? Or will it just recognise that I have a legal version and just kind of reboot my system?
     
  14. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    You'll NOT be installing new Windows. You'll repair existing installation.'
    Go to bed! Now!...LOL
     
  15. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    Sorry :p But I just want to get rid of the Service Pack at least for now :D
     
  16. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    You have all instructions in my reply #31 so whatever you want to do....
     
  17. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    I'm confused, do I have to uninstall the Service Pack 1 or can I just overwrite it?
     
  18. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    First you need to create Windows 7 DVD as described in my link.
    Then in order to run repair installation you'll have to uninstall SP1 because you have to have same Windows version on DVD and on your computer.
    Once again you won't be able to do it in 30 minutes or so....go to bed and start fresh tomorrow.
    Start with reading my replies and my links.
     
  19. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    Bye! I will have nightmares now because of you :p
     
  20. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    Same here because of you....LOL
     
  21. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    Hey I'm back, overslept 4 hours but everything has quietend down at my work :p I have time, but actually I'm facing an issue with uninstalling the Service Pack 1. First of all, I guess I have to be in Safe mode, as always. When I go to 'Installed Updates' in 'Programs and Features', when I find the file 'Service Pack for Microsoft Windows (KB976932)' and double-click on it or select it and press uninstall, a pop up comes up, 'Are you sure you want to uninstall this update?' I press yes and nothing happens.. I repeat the process, nothing happens.. So I tried doing that through 'Command Prompt', and this time, this comes up: [​IMG]But nothing happens too when I click 'OK'
     
  22. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    1. Click the Start button [​IMG], and then, in the search box, type Command Prompt.
    2. In the list of results, right-click Command Prompt, and then click Run as administrator. If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
    3. Type the following: wusa.exe /uninstall /kb:976932
    4. Press the Enter key.
     
  23. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    Same picture comes up like in #46 post.
     
  24. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    Are you sure you put "space" after "wusa.exe" and after "/uninstall"?
     
  25. xialoin

    xialoin TS Rookie Topic Starter Posts: 34

    Oh :p I guess I should try that :p I wasted the whole day and all you need to do is put 'space' between words :D Thanks I'll try that!
     


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.