republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Spybot detects "Command Service" as malware
Search Topic:
Uniqs:
2216
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
HJT Log--five trojans evaded repair »
« (topic move) RPC Server unavailable  
AuthorAll Replies

BigPoppa44

join:2005-08-08
Washington, NC
·Embarq Now Century..

Spybot detects "Command Service" as malware

I updated Spybot S&D 1.4 and ran it today and it detected "Command Service" malware as 2 entries in the registry. Does anyone know if this is legitimate malware and what is it? I used "Spyware Guide" and tried to look it up but it came back as nothing found.


Vampirefo
Premium,MVM
join:2000-12-11
Huntington, WV
What are the reg entries?
--
Best RegardsVampirefo


gwion
wild colonial boy
Premium,ExMod 2001-08
join:2000-12-28
Pittsburgh, PA

reply to BigPoppa44
Could refer to the resource kit tools "Rcmdsvc.exe" (server end, service) and "rcmd.exe" (client end, command line app?

It's a server for remotely running command line programs. Obviously, that can create some issues. But it's not "malware", just something that can be abused to run malware, given the right set of circumstances...
--
Semper Eadem

Come all without, come all within,
You'll not see nothing like the mighty Quinn.


no

@comcast.net
reply to BigPoppa44
I got the same thing today and well I deleted the registry entries. Is this a false positive?:(


Jimbo40
Premium
join:2001-01-07
New York, NY
reply to BigPoppa44
same here


no

@comcast.net
reply to BigPoppa44
Well, I thought I was alone on this issue.:(


no

@comcast.net

reply to BigPoppa44
Here is my Spybot log of the fixed registry:

--- Report generated: 2005-12-02 16:45 ---

Command Service: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mchInjDrv

Command Service: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mchInjDrv

Command Service: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\mchInjDrv


Vampirefo
Premium,MVM
join:2000-12-11
Huntington, WV
·Comcast

TrojanHunter, spysweeper, a2 all add this registry entry, probably more security apps also.
mchInjDrv (Mad code hook injection driver)
malware can use it, but if you use any of the above security apps, then it's a false positive.
--
Best RegardsVampirefo


CajunTek
Insane Cajun
Premium,MVM
join:2003-08-08
Arlington, TX
·RoadRunner Cable

Yep Vampirefo is right on the money.. One piece of malware that does use it though is this one information on command.exe aka the Buddy trojan..
--
Lost in Texas


no

@comcast.net
reply to Vampirefo
So it's a false positive right?


Spy
Premium
join:2001-09-22
NE
Absolutely.

BigPoppa44

join:2005-08-08
Washington, NC
reply to Vampirefo
Vampirefo, Thanks for the info. I run Spysweeper V4.5 and A squared V1.6. I'm glad to know that it's a false positive for me.
Forums » Up and Running » Security » SecurityHJT Log--five trojans evaded repair »
« (topic move) RPC Server unavailable  


Wednesday, 10-Feb 03:40:28 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10.5 years online! © 1999-2010 dslreports.com.
page compression OFF
Most commented news this week
· [91] Verizon Wireless, Meet 4Chan
· [88] FBI Revamps Push For Two Year ISP Log Retention
· [72] Comcast Xfinity Rebranding Largely Laughed At
· [39] When MetroPCS Says 'No Contract,' They Mean 'Contract'
· [31] Instat: Average Connection is 7.12 Mbps
· [30] Fairpoint Files Bankruptcy Plan
· [23] Duh: Billing Companies Think Metered Billing 'Inevitable'
· [21] Google Lowers Nexus One ETF, Launches Phone Support
· [20] Cox Offers Free PS3s To Entire State Of Arizona
· [19] Qwest Still Shopping Itself Around
Most people now reading
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· ADSL-CO/2009-261 Case update.... [TekSavvy]
· Ashen Verdict Rep farming guide (ICC 10) [World of Warcraft]
· Love is in the Air-Lovely Charm Bracelet [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· Microsoft Security Bulletin(s) for February 9, 2010 [Security]
· [WIN7] Discovered Something I Think. (Tip) [Microsoft Help]
· Jury Duty again [General Questions]
· Who's the first to try Fibe 25? [Bell Canada]
· Docsis 3.0 modem [OptimumOnline]