PDA

View Full Version : cmdService.. ;_;



Dionysus
2006-10-03, 03:07
Gah, I'm sorry to be of a bother, but alas, like other cases, my computer is unable to remove it. Curse you, merciful Poseidon! (Arr, a failed attempt of humor), the process seems to be constantly running, to my dismay. Seems to be the root of my strife against 'teh internetz'. I'm very sorry for bothering, as I know you all have busy lives. T__T; Thank you, and here's the HijackThis Log. ;o

Logfile of HijackThis v1.99.1
Scan saved at 6:01:32 PM, on 10/2/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msgr.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\R2VlQm90MjAwOTk\command.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\SoniczeEdgeOg\Yinstall.exe
C:\Program Files\Common Files\{AC12701E-0298-1033-0620-000930190001}\Update.exe
c:\windows\temp\ja.exe
C:\Documents and Settings\SoniczeEdgeOg\Desktop\HijackThis.exe
C:\Program Files\hijackthis\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\ldwfp.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,wyeiaag.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3C12701E-0298-1033-0620-000930190001}\MyToolBar.dll
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [explorer] C:\Documents and Settings\SoniczeEdgeOg\Yinstall.exe
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [ms0308077794-14] C:\WINDOWS\ms0308077794-14.exe
O4 - HKLM\..\Run: [win32104-140807779] C:\WINDOWS\win32104-140807779.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ikfr] C:\PROGRA~1\COMMON~1\ikfr\ikfrm.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs:
O20 - Winlogon Notify: DateTime - C:\WINDOWS\system32\ccb.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\R2VlQm90MjAwOTk\command.exe

tashi
2006-10-05, 10:34
Hello. :)

No Anti Virus program and No Windows Updates?


Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Please see:
You and Windows, a joint effort (http://forums.spybot.info/showpost.php?p=25290&postcount=4)

Did you read this sticky about an on-line scan and running Spybot-S&D in safe mode:
"BEFORE you POST" -Preliminary Steps (http://forums.spybot.info/showthread.php?t=288) ;)

tashi
2006-10-12, 01:23
This topic has been archived.

If you need it re-opened please send me a private message (pm) and provide a link to the thread.
Applies only to the original topic starter.