Spybot unable to remove cmdService entry in Win2000 registry

Discussion in 'Malware Help (A Specialist Will Reply)' started by roadcaptain, Apr 29, 2006.

  1. roadcaptain

    roadcaptain Private E-2

    I have viewed a previous post (http://forum.majorgeeks.com/archive/index.php/t-84849.html)
    I have followed BJGarrick's instuctions to remove the service

    Click Start > Run > type in regedit

    Manually navigate to the following key:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService

    Right click on cmdService and select "Permissions". In the list click on "Everyone" and at the bottom, check the box next to "Full Control. Click OK to exit.

    Now right click on "cmdService" and delete it. If you get any errors let me know!

    Now do the same for the key below:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService

    Right click on cmdService and select "Permissions". In the list click on "Everyone" and at the bottom, check the box next to "Full Control. Click OK to exit.

    Now right click on "cmdService" and delete it.


    After you complete this, reboot and see if Spybot still detects these entries.



    When I right click on cmdService to select "Permissions" there is no option for "Permissions"....this is particular to Win2000 I believe, I suspect permission are a default setting in XP.
    The point being that I can proceed no further until I discover how to select permissons for everyone with full control.

    Any suggestions would be greatly appreciated, I have quite a few hours involved in trying to solve this and Major Geeks is the only resource I have found + I am new here.
     
  2. roadcaptain

    roadcaptain Private E-2

    Re: Spybot unable to cmdService entry in Win2000

    Header should read: Spybot unable to remove cmdService entry in Win2000 registry
     
  3. roadcaptain

    roadcaptain Private E-2

    Edit by chaslang: Inline log removed. Cleaning steps not run.
     
    Last edited by a moderator: Apr 30, 2006
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please do not post any logs inline and also you must run cleaning procedures before HijackThis logs will be accepted.

    Start with downloading HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  5. roadcaptain

    roadcaptain Private E-2

    Thank you for steering me in the correct direction.
    I have completed the steps in read and run me 1st. CC Cleaner went well, Microsoft Windows Malicious Software Removal Tool went well also,Ad-Aware SE went well, Spybot went well but once again was unable to kill cmdService.
    Microsoft Windows Defender would not load (I do have the latest Java 5.0 Update6).
    Tried to run Counter Spy but with the same results as with Windows Defender.
    CW Shredder ran well.
    Kill2Me ran well.
    Bit Defender and Panda ActiveScan would not run in safe mode with networking due to no dial-up connection but ran well in normal mode.
    It appears that I still have a problem with unwanted pages popping up just as before.
    Please be so kind as to provide me with some enlightenment about the situation I find myself in.

    Thank you
    Roadcaptain​
     

    Attached Files:

  6. roadcaptain

    roadcaptain Private E-2

    I seem to have forgotten to include the HiJackThis log.
     

    Attached Files:

  7. roadcaptain

    roadcaptain Private E-2

    Upon further investigation....the problem only occurs when I log in as a User and not an Administrator. I assume this can be fixed by creating another user and removing the current one.
    Also the CD burner in E drive no longer recongnizes CD-R disk ( I haven't tried any others as yet).

    Thank you so much for the valuable information
    Roadcaptain​
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could try that and see what happens, but I would recommend doing the below since you have a bunch of problems that will affect all user accounts.

    CD burner issues are not topics for this forum. For that, you should post in the Hardware Forum.

    It does not look to me like you ran the Hoster program. If you had, all of those O1 - Hosts lines should be gone. Did you run it?

    Run the Hoster procedure again!

    You Windows 2000 version is way out of date. You are running the original version and they are up to an SP4 revision level. This is a major security risk. You must get updated after we remove all malware.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Dcom Helper ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    DcmHlp

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O1 - Hosts: 203.186.128.56 www.abbey.co.uk
    O1 - Hosts: 203.186.128.56 abbey.co.uk
    O1 - Hosts: 203.186.128.56 www.cahoot.co.uk
    O1 - Hosts: 203.186.128.56 cahoot.co.uk
    O1 - Hosts: 203.186.128.56 www.co-operativebank.com
    O1 - Hosts: 203.186.128.56 co-operativebank.com
    O1 - Hosts: 203.186.128.56 www.cajamar.com
    O1 - Hosts: 203.186.128.56 cajamar.com
    O1 - Hosts: 203.186.128.56 www.unicaja.com
    O1 - Hosts: 203.186.128.56 unicaja.com
    O1 - Hosts: 203.186.128.56 www.caixagalicia.com
    O1 - Hosts: 203.186.128.56 caixagalicia.com
    O1 - Hosts: 203.186.128.56 www.caixasabadell.es
    O1 - Hosts: 203.186.128.56 caixasabadell.es
    O1 - Hosts: 203.186.128.56 www.cajamadrid.com
    O1 - Hosts: 203.186.128.56 cajamadrid.com
    O1 - Hosts: 203.186.128.56 www.sparda-b.de
    O1 - Hosts: 203.186.128.56 sparda-b.de
    O1 - Hosts: 203.186.128.56 www.bankingonline.de
    O1 - Hosts: 203.186.128.56 www.raiffeisenbank-erding.de
    O1 - Hosts: 203.186.128.56 raiffeisenbank-erding.de
    O1 - Hosts: 203.186.128.56 www.bnhof.de
    O1 - Hosts: 203.186.128.56 bnhof.de
    O1 - Hosts: 203.186.128.56 www.dkb.de
    O1 - Hosts: 203.186.128.56 dkb.de
    O1 - Hosts: 203.186.128.56 www.sparkasse-regensburg.de
    O1 - Hosts: 203.186.128.56 sparkasse-regensburg.de
    O1 - Hosts: 203.186.128.56 www.berliner-bank.de
    O1 - Hosts: 203.186.128.56 berliner-bank.de
    O1 - Hosts: 203.186.128.56 www.berliner-sparkasse.de
    O1 - Hosts: 203.186.128.56 berliner-sparkasse.de
    O1 - Hosts: 203.186.128.56 www.capitalone.co.uk
    O1 - Hosts: 203.186.128.56 capitalone.co.uk
    O1 - Hosts: 203.186.128.56 www.unicredit.it
    O1 - Hosts: 203.186.128.56 unicredit.it
    O1 - Hosts: 203.186.128.56 www.sanpaolo.com
    O1 - Hosts: 203.186.128.56 sanpaolo.com
    O1 - Hosts: 203.186.128.56 bankofscotlandhalifax.co.uk
    O1 - Hosts: 203.186.128.56 interactif.creditlyonnais.fr
    O1 - Hosts: 203.186.128.56 creditlyonnais.fr
    O1 - Hosts: 203.186.128.56 www.creditlyonnais.fr
    O1 - Hosts: 203.186.128.56 www.secure.bnpparibas.net
    O1 - Hosts: 203.186.128.56 secure.bnpparibas.net
    O1 - Hosts: 203.186.128.56 bnpparibas.net
    O1 - Hosts: 203.186.128.56 www.bnpparibas.net
    O1 - Hosts: 203.186.128.56 www.anbusiness.com
    O1 - Hosts: 203.186.128.56 anbusiness.com
    O1 - Hosts: 203.186.128.56 www.caixatarragona.es
    O1 - Hosts: 203.186.128.56 caixatarragona.es
    O1 - Hosts: 203.186.128.56 www.caixaontinyent.es
    O1 - Hosts: 203.186.128.56 caixaontinyent.es
    O1 - Hosts: 203.186.128.56 www.arquia.es
    O1 - Hosts: 203.186.128.56 arquia.es
    O1 - Hosts: 203.186.128.56 fibank.es
    O1 - Hosts: 203.186.128.56 www.fibank.es
    O2 - BHO: (no name) - {0F8C97E3-ADD5-47F8-BE18-A54DCDB76693} - C:\Program Files\DirectX\megoqa.dll
    O2 - BHO: (no name) - {37D36E70-4652-43B0-A34B-9F5163DB8E1F} - \
    O4 - HKLM\..\Run: [Windows Services] spoolsvc.exe
    O4 - HKLM\..\RunServices: [Windows Services] spoolsvc.exe
    O4 - HKCU\..\Run: [Windows Services] spoolsvc.exe
    O4 - HKCU\..\RunServices: [Windows Services] spoolsvc.exe
    O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\WINDOWS\dcmhelp.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\dcmhelp.exe
    c:\windows\system32\ld3687.tmp
    c:\eied_s7.cab
    c:\windows\system32\1024
    C:\cxx.exe
    C:\ddg.exe
    C:\kx.exe
    C:\WINDOWS\msdirectx.sys
    C:\WINDOWS\msgctrl.exe
    C:\WINDOWS\msinit.exe
    C:\WINDOWS\SmltbXkgYW5kIENhdA\mA5Qvr40sqc4KHh1xE.vbs
    C:\WINDOWS\SYSTEM32\edfimg_22205.exe
    C:\WINDOWS\SYSTEM32\eraseme_23877.exe
    C:\WINDOWS\SYSTEM32\Process.exe
    C:\WINDOWS\SYSTEM32\setup_12430.exe
    C:\WINDOWS\SYSTEM32\setup_17412.exe
    C:\WINDOWS\SYSTEM32\TFTP1016
    C:\WINDOWS\SYSTEM32\TFTP1020
    C:\WINDOWS\SYSTEM32\TFTP1076
    C:\WINDOWS\SYSTEM32\TFTP1124
    C:\WINDOWS\SYSTEM32\TFTP1580
    C:\WINDOWS\SYSTEM32\TFTP1632
    C:\WINDOWS\SYSTEM32\TFTP4132
    C:\WINDOWS\SYSTEM32\TFTP544
    C:\WINDOWS\SYSTEM32\TFTP572
    C:\WINDOWS\SYSTEM32\TFTP692
    C:\WINDOWS\SYSTEM32\TFTP748
    C:\WINDOWS\SYSTEM32\TFTP824
    C:\WINDOWS\SYSTEM32\TFTP848
    C:\WINDOWS\SYSTEM32\TFTP924
    C:\WINDOWS\System32\spoolsvc.exe <--- only delete spoolsvc.exe if found. DO NOT delete spoolsv.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    You may need to run the SpywareQuake Removal Procedure since you appear to have this infection.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: May 1, 2006
  9. roadcaptain

    roadcaptain Private E-2

    Ok...I ran Hoster before starting the steps.
    When I got to where I was to boot into Safe Mode and use Windows Explorer to delete files......it would not boot in safe mode...(got stop error blue screen) tried 3 times.
    Booted in normal mode then shut down and booted into safe mode and it worked this time.
    Only found six of the files listed (hidden files are showing).
    Reset web settings, deleted cookies, files, offline content.

    Browsed for fifteen minutes and unwanted windows popped in again.

    Ran SpywareQuake removal procedure and when I got into safe mode Spyware Quake did not show in add/remove programs and I continued on.
    Did not find any of the files in windows\system32 which I was to rename.
    After RunThis.bat none of the remaining files I was to delete were found.
    And so here I am. Along with the .txt files I am to upload there will be two files listing the files I was unable to find, omitted files which should be on the list WERE FOUND AND DELT WITH AS INSTRUCTED.



    "Onward thru the Fog!" Roadcaptain
     

    Attached Files:

  10. roadcaptain

    roadcaptain Private E-2

    Only these were delt with.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should IMMEDIATELY start working thru the below link. However for you I recommend doing step 2 first, step 1 second, and then work thru the rest (but skip step 3 since you already have ZoneAlarm).


    How to Protect yourself from malware!
     
  12. roadcaptain

    roadcaptain Private E-2

    Ummm.....I am afraid I may not be totally clean. I still get pop-ups when browsing. Approx. 3 pages will load in rapid succession. I am glad to report that one of them I was seeing no longer appears!
    I shall refrain from completing the next step "How to protect yourself from Malware" until we have resolved the pop-up issue.

    Thank you for your patience
    Roadcaptain
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run the below and make sure Windows Messenger is uninstalled!

    Disable/Remove Windows Messenger

    Then complete step 2 and then step 1 of the How to protect thread. After completing those two steps (and also removing Windows Messenger), attach a new HJT log and tell me how things are working.
     
  14. roadcaptain

    roadcaptain Private E-2

    I now have Virus protection and have updated Windows2000 to SP4.
    Was besieged through out the entire process with pop ups..........would walk away for a few minutes and when I come back there is 15 or 20 pop ups.
    I have noticed one is Titled "About Blank".....this may be our culprit.
     

    Attached Files:

  15. roadcaptain

    roadcaptain Private E-2

    I just realized I have not done the "System Restore". My apologies.....I will wait for a response before proceeding further.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually you do not have a System Restore since you are running Windows 2000. That is a boiler plate message that is posted after all malware has been removed. I shouuld have edited out the System Restore part for your system.

    You HJT log is clean other than the below two Alexa related items that come preinstalled with Windows. You can fix these with HJT:

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    But you show no malware in your HJT log. If you are getting popups, it could be due to the sites you are connected to serving them.

    However let's just do an additional scan and see if anything comes up. Run the below and then attach the Ewido log:

    Running Ewido Anti-Malware
     
  17. roadcaptain

    roadcaptain Private E-2

    I don't think the sites I am connecting to are serving up the pop ups as I get them when the only window open is Windows Update or Major Geeks.
    None the less it seems as though Ewido was successful in locating a few more nasty "no-seeums".
    The log is attached.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run the below program to remove Windows Messenger? I know you mentioned it, but make sure it worked.

    Disable/Remove Windows Messenger

    You really should do this because Windows Messenger can be the source of unwanted popups like you are describing.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just for the heck of it, run the below procedure and attach the requested log:

    Look2Me VX2 Removal
     
  20. roadcaptain

    roadcaptain Private E-2

    I'm not sure if Remove Windows Messenger worked or not.....when I run it I get an error: could not locate INF file C:\windows\inf\msmsgs.inf

    after clicking ok on error, removal indicates Windows Messenger has been uninstalled.

    Ran look2me also...seemed to go fine.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Then it is more than likely gone. Look2Me Destroyer did not find anything which is good.

    Have you completed ALL the other steps in the How to protect thread? If not, please finish all of them.

    If you get any popups afterwards, please indicate exactly what the popups are for (include URLs too if you can see them). Also indicate how many browsers Windows were opened, which browers (IE, FireFox, etc) and what websites you were connected to at the time.
     
  22. roadcaptain

    roadcaptain Private E-2

    Good news! I have had my browser open for 1 1/2 hours and no pop-ups yet.
    I think I may be cured!
    I made sure all steps were completed in "How to Protect".
    But i chose to stay with IE.
     
  23. roadcaptain

    roadcaptain Private E-2

    Of the tools downloaded to kill the pop-ups which should I keep and which should I uninstall/delete?
     
  24. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Chaslang is gone today, possibly until tommorow night. Why are you running a popup blocker at all I wonder aloud, an additional program is not really needed nowadays... The latest IE has popup blocking, as does Opera and Firefox. A 3rd party add-on like Maxthon will add additional popup blocking as well as more features like tabbed browsing.

    http://majorgeeks.com/Maxthon_Standard_d1167.html

    Let us know if all remains well, Chaslang should be back tommorow.
     
  25. roadcaptain

    roadcaptain Private E-2

    So far all is well with the browser, resolved the CD Burner issue by uninstalling both the CD-ROM and the CD Burner, restarted twice then ran the CD Burners installation disk which resolved the driver issues and all is well.

    Thanks Guys!
    RoadCaptain
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds