i found after extensively looking arround the internet, that cmdService edits it's registry permissions, to protect it from automatic or manual deletion, becuase full control to the key was removed by the Command Service.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cmdService
To remove these keys using Regedit i needed to then do is change the permissions to these keys enabling administrator full control to them.
By right clicking on the key:
[selecting permissions] then clicking on administrator or the account your using, full controal, apply ok.
Or Alternativly these this can be done using Safernetworkings Reganalizer.
By right clicking on the key:
[selecting grant full permissions to evryone in this folder]
Then for both Regedit or Reganliser
Delete the keys using the the editor, or run spybot again.
Is their any way that spybot could automaticly detect spyware registry keys? preventing removal in this way?
As only spybot and trend antispyware detected them, neither of which could remove them. :
[Microsoft Defender and Ad-Aware didn't evan detect them as at 20/04/06am]