1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Two HijackThis Items Worry Me

Discussion in 'Malware and Virus Removal Archive' started by Ann, 2007/07/24.

  1. 2007/07/24
    Ann

    Ann Well-Known Member Thread Starter

    Joined:
    2002/01/10
    Messages:
    597
    Likes Received:
    1
    Hi -

    I run a HijackThis log every few months or so even though I do not have problems. I noticed a couple of suspicious items and wonder if anyone can help me decipher these two items in my HijackThis log.

    Item one is worrisome as it has no file and no owner.. Does anyone know if it should be removed?

    O23 - Service: svcWRSSSDK - Unknown owner - (no file)

    The following may be left behind after removing NAV and running the Norton Removal Tool, but I am not sure:

    O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (file missing)

    Any help will be appreciated.

    Ann
     
    Ann,
    #1
  2. 2007/07/24
    Whiskeyman Lifetime Subscription

    Whiskeyman Inactive Alumni

    Joined:
    2005/09/10
    Messages:
    1,772
    Likes Received:
    37
    O23 - Service: svcWRSSSDK - Unknown owner - (no file)

    Webroot Spy Sweeper Engine

    O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (file missing)

    Check Services to see if SymWMI Service is still listed and set to Start. It probably wasn't disabled before removal.
     

  3. to hide this advert.

  4. 2007/07/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    To remove the Symantec service, click Start>Run, enter the following two commands one at a time, hitting enter after each.

    sc stop SymWSC
    sc delete SymWSC
     
  5. 2007/07/24
    Ann

    Ann Well-Known Member Thread Starter

    Joined:
    2002/01/10
    Messages:
    597
    Likes Received:
    1
    Whiskeyman - Thank you so much. I no longer have SpySweeper, so I can let HijackThis delete or remove. I do not find SymWMI Service in Services.

    noahdfear - I did as you suggest, but I did not see anything happen. Am going to run another HijackThis log and see if it is gone. Will let you know if I got rid of it or not. Thanks a bunch.

    Ann
     
    Ann,
    #4
  6. 2007/07/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Since you no longer have Spy Sweeper, do these two as well.

    sc stop svcWRSSSDK
    sc delete svcWRSSSDK


    ;)
     
  7. 2007/07/24
    Ann

    Ann Well-Known Member Thread Starter

    Joined:
    2002/01/10
    Messages:
    597
    Likes Received:
    1
    noahdfear - it worked. SymWMI Service is no longer listed in HijackThis log.
    Too late for Spysweeper, but I did remove it via Hijackthis by checking Fix.
    I am printing out this thread for my information. Thanks! :)
     
    Ann,
    #6
  8. 2007/07/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Fixing a service with HijackThis will usually only stop it if running. Is it gone now? :confused:
     
  9. 2007/07/24
    Ann

    Ann Well-Known Member Thread Starter

    Joined:
    2002/01/10
    Messages:
    597
    Likes Received:
    1
    noahdfear,

    No, it was still listed in HijackThis log. I quickly ran your fix and, once again, it worked. The SpySweeper entry is gone. I have learned several things today and that is always a good thing. Thanks for your help. :cool:

    Ann
     
    Ann,
    #8
  10. 2007/07/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Happy to help. ;)
     
  11. 2007/07/26
    Ann

    Ann Well-Known Member Thread Starter

    Joined:
    2002/01/10
    Messages:
    597
    Likes Received:
    1
    Hi noahdfear,

    I was reading my notes and thought I'd ask you if this procedure to stop and delete works with any service you have running. A little knowledge is a dangerous thing! :rolleyes:
     
    Ann,
    #10
  12. 2007/07/26
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi Ann,

    Yes it does, but you have to get the name of the service right. Using your's above as examples;

    O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (file missing)

    When you look in the services applet (Start>Run>services.msc), that service is listed as SymWMI Service. That's it's display name. In the registry, it's key name is SymWSC, as shown in parenthesis above. To delete the service using the sc delete command, you must use the key name.

    O23 - Service: svcWRSSSDK - Unknown owner - (no file)

    Display name (if displayed) and key name are the same ....... svcWRSSSDK

    The sc stop command must be used prior to the sc delete, always. Can't delete a service if it's running (I'm sure you knew that already, just threw it in for good measure ;) ).
     
  13. 2007/07/27
    Ann

    Ann Well-Known Member Thread Starter

    Joined:
    2002/01/10
    Messages:
    597
    Likes Received:
    1
    Thank you, noahdfear. Saving my notes on this thread, one more time. :)
     
    Ann,
    #12
  14. 2007/07/27
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    You're welcome Ann :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.