Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 12-22-2005, 11:25 AM   #1 (permalink)
TSF Enthusiast
 
Join Date: Sep 2004
Location: Milwaukee, WI -USA
Posts: 547
OS: WinXP Pro


Send a message via AIM to Peebs85 Send a message via MSN to Peebs85
cmdService

Fellow Analysts,

I am out of practice. A co-worker of mine seems to have got this nasty cmdService that will not go away. I dare say that the HJT log looks pretty clean to me but Spybot cannot remove this entry (whether at startup or in Safe Mode). Would someone give me a hand in fixing this up? I presume that you will need more logs/info, but I will wait to see what you want.

Thanks much,

Logfile of HijackThis v1.99.1
Scan saved at 12:18:43 PM, on 12/22/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\NavNT\defwatch.exe
C:\PROGRA~1\PANASO~1\PANASO~1\REMOTE~1\KcNTSRV.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\PANASO~1\TRAPMO~1\Trapmnnt.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\hkcmd.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Panasonic\Panasonic DP-CL21\Status Display\sdwakeup.exe
C:\WINNT\explorer.exe
C:\Hijack This\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [sdwakeup.exe] C:\Program Files\Panasonic\Panasonic DP-CL21\Status Display\sdwakeup.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/k...an_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = csm.corp.int
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = csm.corp.int
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = csm.corp.int
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DP-CL21 Remote Server - Panasonic Communications Co., Ltd. - C:\PROGRA~1\PANASO~1\PANASO~1\REMOTE~1\KcNTSRV.exe
O23 - Service: Iap - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Panasonic Trap Monitor Service - Panasonic - C:\PROGRA~1\PANASO~1\TRAPMO~1\Trapmnnt.exe
__________________
TSF deutsch-sprachiger Analyst -- für jene, die Deutsch sprechen, kann ich Ihnen helfen!
Senden Sie eine Nachricht und PM mich! Detah kann auch Deutsch.

Donations are Welcome! -- Spenden sind Wilkommen!
Peebs85 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 12-22-2005, 12:01 PM   #2 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,333
OS: N/A


Hi Peebs,

Unless mistaken, SpyBot is complaining about some reg entries that look like these..

Hkey_local_machine\System\controlset001\Services\cmdService >> 001 can be another number

Hkey_local_machine\System\CurrentControlSet\Services\cmdService


You'll need to go to start > run - regedit <Enter>
Naviagate to & delete those keys in red

If any of the above registry keys are giving you problems deleting, right click on them and click on Permissions. Then click on the Advanced button. Make sure the first box (Inherit from parent...) is checked. Click OK and OK. Then try deleting the entry again. Once you're done, close the Registry Editor.

If those keys aren't present, it may be false positives. For more info, please read here.

Either way... let me know how that went
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 12-22-2005, 12:46 PM   #3 (permalink)
TSF Enthusiast
 
Join Date: Sep 2004
Location: Milwaukee, WI -USA
Posts: 547
OS: WinXP Pro


Send a message via AIM to Peebs85 Send a message via MSN to Peebs85
sUBs,

You're not mistaken...the problem is that there are like 16 instances of that and none of them will let me delete them. They all give me this error message (substituting the different names):
Quote:
Cannot delete cmdService: Error while deleting key.
'Permissions' is not an option in the right-click menu.

What next sUBs??

Paul
__________________
TSF deutsch-sprachiger Analyst -- für jene, die Deutsch sprechen, kann ich Ihnen helfen!
Senden Sie eine Nachricht und PM mich! Detah kann auch Deutsch.

Donations are Welcome! -- Spenden sind Wilkommen!
Peebs85 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 12-22-2005, 12:51 PM   #4 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,333
OS: N/A


You have to download Reglite

Launch Reglite & navigate to those keys

Right click, select Properties & 'Take Ownership' of the key

Then try deleting them again
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 12-22-2005, 01:29 PM   #5 (permalink)
TSF Enthusiast
 
Join Date: Sep 2004
Location: Milwaukee, WI -USA
Posts: 547
OS: WinXP Pro


Send a message via AIM to Peebs85 Send a message via MSN to Peebs85
Mentor,

You're a genious. I am again very grateful for the help.

Go sUBs...go sUBs...

See you in the back forums...I'm on break now!
__________________
TSF deutsch-sprachiger Analyst -- für jene, die Deutsch sprechen, kann ich Ihnen helfen!
Senden Sie eine Nachricht und PM mich! Detah kann auch Deutsch.

Donations are Welcome! -- Spenden sind Wilkommen!
Peebs85 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 03:20 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85