Results 1 to 5 of 5
  1. #1
    Join Date
    Jan 2007
    Location
    Australia
    Posts
    410

    Default 'Flash_Disinfector.exe' problem

    When running Flash Disinfector (http://www.techsupportforum.com/sect...isinfector.exe) 2 files are flagged with dire warnings and blocked by Threatfire. (see image).

    I've not previously used Flash Disinfector but it comes from usually trusted sources. Is it really malicious?

    Pete
    Attached Images Attached Images

  2. #2
    mjq424's Avatar
    mjq424 is offline Moderator Volunteer Guru
    Subscriber
    Moderator
    Join Date
    Feb 2007
    Location
    UK
    Posts
    2,854

    Default

    Hi
    Both Nircmd.exe and pv.exe are command line tools that can be used for malicious purposes as well as useful purposes. I always thought that nircmd.exe was on the PUA list and should throw up a grey alert box, I'm not sure about pv.exe though.
    Do you get any alerts from ThreatFire? What other security programs do you have?
    Regards,
    Matt

    PC Tools Community Forum Volunteer

  3. #3
    Join Date
    Sep 2008
    Location
    Perth, Australia
    Posts
    243

    Default

    Hi,
    All
    See what Nircmd.exe is on this website http://www.google.com.au/search?q=Ni...ient=firefox-a and also see what pv.exe is http://www.google.com.au/search?q=pv...ient=firefox-a Click on those links to view.
    They are unwanted software and may harm the computer.

    Hope it helps
    PC Tools - Providing Excellent Software + Performance Utility
    PC Tools Together - Share, Talk, Get Together
    ThreatFire - Zero-Day Behavior Protection

    My Computer Specs: ASUS K52J - Intel Core i5 450M, 500GB HDD, Windows 7 64bit, ATI Mobility Radeon HD 5145

  4. #4
    Join Date
    Jan 2007
    Location
    Australia
    Posts
    410

    Default

    Quote Originally Posted by mjq424 View Post
    Hi
    Both Nircmd.exe and pv.exe are command line tools that can be used for malicious purposes as well as useful purposes. I always thought that nircmd.exe was on the PUA list and should throw up a grey alert box, I'm not sure about pv.exe though.
    Do you get any alerts from ThreatFire? What other security programs do you have?
    Thanks for the info. This PC also has Avast Pro 4.8.1196 and WinPatrol 14.0.2007.1. See attached image for TF alerts.

    My question is why would a programmer use cryptic/silent commands for a legitimate purpose? I guess they just didn't think of it being detected.
    Attached Images Attached Images
    Last edited by PC-Pete; 12-17-2008 at 02:37 AM.

  5. #5
    mjq424's Avatar
    mjq424 is offline Moderator Volunteer Guru
    Subscriber
    Moderator
    Join Date
    Feb 2007
    Location
    UK
    Posts
    2,854

    Default

    Hi
    NirCmd is certainly used ("silently") in several community antimalware applications (like ComboFix/SmitfraudFix) for process/file interaction. Here it does seem that it may have been a legitimate detection though alongside the Trojan-PWS.Bancos.
    Hope that helps
    Regards,
    Matt

    PC Tools Community Forum Volunteer

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •