Removing adware from registry

G

Guest

I got nailed with something that Norton AV 2005 didn't catch. I've run both
MSAS and Spybot in safe mode in the admin acct several times. MSAS doesn't
find anything but Spybot keeps finding something called Command Services.
It's found under HKEY_LOCAL MACHINE\system\control set 003, 001 and current
control set\cmdservices. When I tell it to fix it says it can't because it's
running. When I go to regedit and try to delete manually it won't let me.
How do I get rid of this persistant lil bugger?
Any and all help is greatly appreciated. Thanks!
 
G

Guest

I took a second look at the reference after replying and realized that the
O.P had quite a collection of stuff--perhaps a more complex case than
yours--however, that isn't unusual, so perhaps there's more than one bug
involved on your system as well.
 
G

Guest

Hi LJ

Hopefully you found the solution, its worth posting your log at one of the
support forums Bill suggests to make sure its only this you have to deal with
but here's abit of info if its detecting 'cmdService' which may help.

http://www.f-secure.com/sw-desc/cmdservices.shtml

The site behind this is 'csx.adservs.com' but Ive seen it install from this
IP address 194.187.45.55, this site also has Qoologic and Trojan Clicker
Variants stored, They are forcing the installs without consent as the initial
download from 194.187.45.55 is a Trojan Downloader called 'Win32.Small.buy'
which then contacts
'Command.adservs.com' to download and run the Command Installation file.

In Hijack This it will show like this :

O23 - Service: Command Service (cmdService) - Unknown owner -
C:\WINDOWS\RUpyturFioIFJZ2VycwAA\command.exe

**Note that is a random named folder, the second time I ran the installer it
was called :

C:\WINDOWS\QW5keU1hbmNoZXN0YQ\command.exe

Then

C:\WINDOWS\YRDyb42z\command.exe

The folder and files are hidden so if you was going to remove this manually
you would have to enable hidden files & folders and also enable Operating
System Files so you can find the folder. (Let us know if you need help with
that)

Its not possible to stop command.exe using task manager as it will give a
access denied message so first get rid of the service then boot into safe
mode and delete the folder.

If you have the above entry showing in the Hijack Log, make a note of what
the folder is called then place a check next to it and close all other open
windows except Hijack This, Then press Fix Checked.

goto start then run and type

cmd

press OK then copy and paste this onto the cmd screen

sc delete cmdService

press enter then type exit and press enter again.

Reboot and enable hidden files and folders and Operating system files then
look for the folder which was shown in the 023 entry of Hijack This and it
will delete without problems. Then run Spybot again while in safe mode.

On my system I had these files inside the random named folder:

kqc4yoY1vAhCtrhXsk.vbs
MD5 387edbb90a5275d1b464eb31f3162c40

asappsrv.dll
MD5 0f8deb5a57d8310b2d7ef90b84480f13

command.exe
MD5 3e2c234dde711c6754f2df994fb3cc94

And also the installer was stored in the temp folder

C:\Documents and Settings\Your UserName\Local Settings\Temp\

cmdinst.exe - Command Desktop Setup
MD5 6aeb8d5c9353739feca9c7759c937bfc

you could run Ccleaner if you have it to remove the temp files, If not then
goto start and run and type cleanmgr and press ok , place checks next to
temporary files and recycle bin then press ok to remove them,

If you have any other problems run Ewido Security Suite on your system as
its free and has daily updates so does great against New infections ( Its
shows its a 14 day trial but it performs fine after that expires, you will
just need to update the scanner manually as the auto updates are part of the
trial)

http://www.ewido.net/en/download/

When installing, under "Additional Options" uncheck "Install background
guard" and "Install scan via context menu". Click on update in the left menu,
then click the Start update button.

After the update finishes click on 'scanner' from the main menu then click
'Complete System Scan' When ewido finds something, it will pop up a
notification. Select "Remove" and check the boxes "Perform action with all
infections" and "Create encrypted backup" then click on ok.When the scan
finishes, click on "Save Report" and save it to your desktop or c:/drive
incase you need it again.

Hope that helps but let us know if you have any problems

All The Best

Andy
 
G

Guest

Hi Andy,
So far I'm still waiting for an answer from the folks over at SWI.
Yesterday I installed and ran ewido which found a bunch of stuff. I removed
some stuff in Hijack This that had files missing. I didn't see anything like
you described. I booted up in safe mode and ran Ad Aware, MAS, Spybot, Ewido
and Hijack This and NAV. Everything came up clean except for Command
Services still showing up in Spybot.

The computer seems to be running ok with no more warnings from NAV but now I
have a weird problem. My desktop theme and background settings have
disappeared. I can't get it to change so that my pictures are used as the
background although I did get some of the colors to change. Also Outlook is
now blue and gray which is really uncomfortable to look at. Any idea what
might have caused this?
 
G

Guest

Hi LJ

Hijack This does have a small bug where if the file isnt found in the system
folders some entries are shown as file missing even though they do exist so
be cautious about what you remove untill someone from the SWI team reply, If
you have Hijack This in a permanent folder then it will create backups of
anything thats fixed so you can add them back if you have problems.

The Fine team at SWI will soon get you clean as it will be easier to help
after seeing the Hijack Log and it sounds like you may need SmitRem to repair
the desktop settings or a reg fix to reset the values to Microsofts default,
I'm pretty sure it is this cmdService that I post removal instructions for
which Spybot is detecting, Ive run cmdService again and used Spybot but it
doesnt detect the files in the random named folder which is the .exe , .vbs &
..dll file, Spybot does detect the service registry entries and shows that its
stopping the service, Then shows the entries will be removed after reboot but
shows the same messages next time it runs and keeps asking to reboot again,

Here's the spybot scan log:

Command Service: Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService

Command Service: System Service (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService

Command Service: Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService

Give it a day or two for SWI to respond and I'm sure it will not take them
long to get you cleaned up and its not worth us changing things at this stage
if you have already post the log but if you have problems let us know.

Happy Christmas :)

Andy
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top