Content

HTool-Xcmd

Type
Program
SubType
Tool
Discovery Date
12/18/2009
Minimum DAT
5836 (12/18/2009)
Updated DAT
5836 (12/18/2009)
Minimum Engine
5.2.00
Description Added
12/18/2009
Description Modified
01/13/2010 2:12 PM (PT)

Tab Navigation

Characteristics

This is detection for a potentially unwanted program Xcmd.

There are two main componets to this application:

  • xcmd.exe
  • xcmdsvc.exe

The xcmdsvc.exe binary is held within the resource section of the xcmd.exe executable. When executed, the combination of xcmd.exe and xcmdsvc.exe can allow for remote application execution. Xcmd.exe is used to initiate remote execution and Xcmdsvc.exe allows for the named pipe communication. Applications can be executed without the need to install the typical server/client configuration.

Removal

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Aliases

Aliases

    N/A