Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 06-30-2009, 09:26 AM   #1 (permalink)
Registered User
 
Join Date: Jun 2009
Posts: 1
OS: xp media


Missing Services

Windows Update Service is missing
Intelligent Tranfer is missing
services.msc reports Access is denied



DDS (Ver_09-06-26.01) - NTFSx86

Run by Tanya Lantz at 8:07:41.93 on Tue 06/30/2009

Internet Explorer: 6.0.2900.5512

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.130 [GMT -4:00]



AV: Norton 360 *On-access scanning enabled* (Updated) {A5F1BC7C-EA33-4247-961C-0217208396C4}

FW: Norton 360 *enabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}



============== Running Processes ===============



C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\system32\dlcicoms.exe

C:\WINDOWS\system32\nvsvc32.exe

svchost.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\stsystra.exe

C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\WINDOWS\ehome\ehtray.exe

C:\Program Files\Dell\Media Experience\DMXLauncher.exe

C:\WINDOWS\System32\DLA\DLACTRLW.EXE

C:\Program Files\AWS\WeatherBug\Weather.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files\Digital Line Detect\DLG.exe

C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Documents and Settings\Tanya Lantz\Desktop\dds.scr



============== Pseudo HJT Report ===============



uStart Page = hxxp://www.msn.com

uSearch Bar = hxxp://search.imesh.com/sidebar.html?src=ssb

mDefault_Search_URL = hxxp://www.google.com/ie

mStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/

uInternet Connection Wizard,ShellNext = hxxp://rdr.wildtangent.com/wire/moregames.aspx?dp=dell&itemName=polarbowler

mSearchAssistant = hxxp://www.google.com/ie

uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll

BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll

TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll

TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File

TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File

TB: {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - No File

EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll

uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1

uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe

uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1

uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe

mRun: [DLCICATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCItime.dll,_RunDLLEntry@16

mRun: [osCheck] "c:\program files\norton 360\osCheck.exe"

mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"

mRun: [SigmatelSysTrayApp] stsystra.exe

mRun: [nwiz] nwiz.exe /install

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [Malwarebytes Anti-Malware Reboot] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript

mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start

mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup

mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup

mRun: [ehTray] c:\windows\ehome\ehtray.exe

mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe

mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE

mExplorerRun: [<NO NAME>] 1 (0x1)

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodaks~1.lnk - c:\program files\kodak\kodak software updater\7288971\program\Kodak Software Updater.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE

IE: &Search

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll

IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL

IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll

DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.clarkcolor.com/ClarkActivia.cab

DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab

DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} - hxxp://weis.coupons.smartsource.com/download/cscmv5X.cab

DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.mpix.com/customer/uploading/activex/ImageUploader5.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab

DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll

Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL

Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll

Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

LSA: Notification Packages =



============= SERVICES / DRIVERS ===============



R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-2-17 9968]

R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-2-17 55024]

R2 dlci_device;dlci_device;c:\windows\system32\dlcicoms.exe -service --> c:\windows\system32\dlcicoms.exe -service [?]

R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]

R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-2-17 7408]

S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-1-3 1245064]



============== File Associations ===============



inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"

piffile="%1" %*"

scrfile="%1" %*



=============== Created Last 30 ================



2009-06-30 07:19 6,136,176 a------- C:\WindowsUpdateAgent30-x86.exe

2009-06-30 06:47 389,120 a------- c:\windows\system32\CF2929.exe

2009-06-30 06:47 <DIR> --ds---- C:\ComboFix

2009-06-30 06:35 <DIR> --d----- c:\docume~1\tanyal~1\applic~1\GlarySoft

2009-06-30 06:34 <DIR> --d----- c:\program files\Glary Utilities

2009-06-29 22:02 389,120 a------- c:\windows\system32\CF27699.exe

2009-06-29 21:43 1,343,190 a------- C:\MGtools.exe

2009-06-29 20:33 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com

2009-06-29 20:32 <DIR> --d----- c:\program files\common files\Wise Installation Wizard

2009-06-29 19:20 26,368 a------- c:\windows\system32\dllcache\usbstor.sys

2009-06-26 20:57 21,504 a------- c:\windows\system32\hidserv.dll

2009-06-22 11:19 61,224 a------- c:\documents and settings\tanya lantz\GoToAssistDownloadHelper.exe

2009-06-22 10:37 105,676 a------- c:\windows\system32\drivers\OLD1D.tmp

2009-06-22 10:37 105,676 a------- c:\windows\system32\drivers\OLD1A.tmp

2009-06-22 10:35 <DIR> --d----- c:\program files\driver

2009-06-22 10:34 2 a------- C:\1342267410

2009-06-22 10:34 <DIR> --dsh--- c:\windows\System Volume Information

2009-06-22 10:34 <DIR> --d----- c:\docume~1\alluse~1\applic~1\17057184

2009-06-18 14:04 <DIR> --d----- c:\docume~1\alluse~1\applic~1\202E

2009-06-14 13:39 99,328 a------- c:\windows\system32\srusd.dll

2009-06-14 13:39 99,328 a------- c:\windows\system32\dllcache\srusd.dll

2009-06-14 13:39 6,784 a------- c:\windows\system32\drivers\serscan.sys

2009-06-14 13:39 6,784 a------- c:\windows\system32\dllcache\serscan.sys

2009-06-14 13:39 71,680 a------- c:\windows\system32\fnfilter.dll

2009-06-14 13:39 71,680 a------- c:\windows\system32\dllcache\fnfilter.dll

2009-06-07 03:53 <DIR> --d----- c:\docume~1\alluse~1\applic~1\13F

2009-06-06 16:42 483,328 a------- c:\windows\system32\actskn45.ocx

2009-06-06 16:42 <DIR> --d----- c:\program files\iMesh Applications



==================== Find3M ====================



2009-06-17 11:27 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys

2009-06-17 11:27 19,096 a------- c:\windows\system32\drivers\mbam.sys

2009-05-30 15:48 2,516 a--sh--- c:\windows\system32\KGyGaAvL.sys

2009-05-07 11:32 345,600 a------- c:\windows\system32\localspl.dll

2009-05-07 11:32 345,600 -------- c:\windows\system32\dllcache\localspl.dll

2009-04-29 00:46 3,068,928 -------- c:\windows\system32\dllcache\mshtml.dll

2009-04-29 00:46 666,624 a------- c:\windows\system32\wininet.dll

2009-04-29 00:46 666,624 -------- c:\windows\system32\dllcache\wininet.dll

2009-04-29 00:46 620,032 -------- c:\windows\system32\dllcache\urlmon.dll

2009-04-29 00:46 1,499,136 -------- c:\windows\system32\dllcache\shdocvw.dll

2009-04-29 00:46 81,920 a------- c:\windows\system32\ieencode.dll

2009-04-29 00:46 81,920 -------- c:\windows\system32\dllcache\ieencode.dll

2009-04-17 08:26 1,847,168 a------- c:\windows\system32\win32k.sys

2009-04-17 08:26 1,847,168 -------- c:\windows\system32\dllcache\win32k.sys

2009-04-15 10:51 585,216 a------- c:\windows\system32\rpcrt4.dll

2009-04-15 10:51 585,216 -------- c:\windows\system32\dllcache\rpcrt4.dll

2007-12-31 08:30 85,360 a------- c:\docume~1\tanyal~1\applic~1\GDIPFONTCACHEV1.DAT

2007-05-31 16:38 4,224 a------- c:\docume~1\tanyal~1\applic~1\wklnhst.dat



============= FINISH: 8:07:55.37 ===============
Attached Files
File Type: txt ark.txt (7.3 KB, 3 views)
File Type: zip Attach.zip (6.0 KB, 1 views)
BHosterman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 07-27-2009, 06:41 AM   #2 (permalink)
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,450
OS: XP SP3


Re: Missing Services

Hello and welcome to TSF.

Apologies for the long delay in response. Since it has been a while you posted, if you still require assistance, please provide us with a new set of logs in a new topic as this one shall be closed.

New Instructions - Read This Before Posting for Malware Removal Help
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006
amateur is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 09:22 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85