This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

bleepingcomputer's USB Disinfector - false positive, or actual vir

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was reading this post about detecting and removing possible infections from USB flash drives:

http://forums.whatthetech.com/index.php?sh…st&p=687749

which references this utility: http://download.bleepingcomputer.com/sUBs/…Disinfector.exe

I downloaded it, renaming it as I saved it to disk, and I scanned it with Avira and it found an unwanted program in it… " APPL/NirCmd.2 application"

Is this a false positive, or is the flash disinfector tool infected? If so, how do I get an uninfected copy? I'm new to Avira - how do I empty the quarantine area?
THANKS!

From Avira's log:
Begin scan in 'C:\Users\Linda\Downloads\FlashDisinfect from bleeping computers.exe'
C:\Users\Linda\Downloads\FlashDisinfect from bleeping computers.exe
[DETECTION] Contains recognition pattern of the APPL/NirCmd.2 application

[0] Archive type: RAR SFX (self extracting)
–> nircmd.exe
[DETECTION] Contains recognition pattern of the APPL/NirCmd.2 application

_______________________________

FULL AVIRA LOG (Hijackthis is after this one):

Avira AntiVir Personal
Report file date: Friday, May 13, 2011 09:05

Scanning for 2725385 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows 7
Windows version : (Service Pack 1) [6.1.7601]
Boot mode : Normally booted
Username : Linda
Computer name : LAMPC

Version information:
BUILD.DAT : 10.0.0.648 Bytes 4/1/2011 18:36:00
AVSCAN.EXE : 10.0.4.2 442024 Bytes 4/2/2011 00:07:43
AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/2/2011 00:07:57
LUKE.DLL : 10.0.3.2 104296 Bytes 4/2/2011 00:07:53
LUKERES.DLL : 10.0.0.1 12648 Bytes 2/11/2010 07:40:49
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 17:05:36
VBASE001.VDF : 7.11.0.0 13342208 Bytes 12/14/2010 23:15:47
VBASE002.VDF : 7.11.3.0 1950720 Bytes 2/9/2011 23:15:47
VBASE003.VDF : 7.11.5.225 1980416 Bytes 4/7/2011 05:07:26
VBASE004.VDF : 7.11.5.226 2048 Bytes 4/7/2011 05:07:27
VBASE005.VDF : 7.11.5.227 2048 Bytes 4/7/2011 05:07:27
VBASE006.VDF : 7.11.5.228 2048 Bytes 4/7/2011 05:07:27
VBASE007.VDF : 7.11.5.229 2048 Bytes 4/7/2011 05:07:27
VBASE008.VDF : 7.11.5.230 2048 Bytes 4/7/2011 05:07:27
VBASE009.VDF : 7.11.5.231 2048 Bytes 4/7/2011 05:07:27
VBASE010.VDF : 7.11.5.232 2048 Bytes 4/7/2011 05:07:27
VBASE011.VDF : 7.11.5.233 2048 Bytes 4/7/2011 05:07:27
VBASE012.VDF : 7.11.5.234 2048 Bytes 4/7/2011 05:07:28
VBASE013.VDF : 7.11.6.28 158208 Bytes 4/11/2011 05:07:28
VBASE014.VDF : 7.11.6.74 116224 Bytes 4/13/2011 05:07:29
VBASE015.VDF : 7.11.6.113 137728 Bytes 4/14/2011 05:07:29
VBASE016.VDF : 7.11.6.150 146944 Bytes 4/18/2011 05:07:30
VBASE017.VDF : 7.11.6.192 138240 Bytes 4/20/2011 05:07:30
VBASE018.VDF : 7.11.6.237 156160 Bytes 4/22/2011 05:07:30
VBASE019.VDF : 7.11.7.45 427520 Bytes 4/27/2011 05:07:31
VBASE020.VDF : 7.11.7.64 192000 Bytes 4/28/2011 05:07:31
VBASE021.VDF : 7.11.7.97 182272 Bytes 5/2/2011 05:07:32
VBASE022.VDF : 7.11.7.127 467968 Bytes 5/4/2011 05:07:32
VBASE023.VDF : 7.11.7.183 185856 Bytes 5/9/2011 05:07:33
VBASE024.VDF : 7.11.7.218 133120 Bytes 5/11/2011 05:07:33
VBASE025.VDF : 7.11.7.234 139776 Bytes 5/11/2011 05:07:33
VBASE026.VDF : 7.11.7.235 2048 Bytes 5/11/2011 05:07:34
VBASE027.VDF : 7.11.7.236 2048 Bytes 5/11/2011 05:07:34
VBASE028.VDF : 7.11.7.237 2048 Bytes 5/11/2011 05:07:34
VBASE029.VDF : 7.11.7.238 2048 Bytes 5/11/2011 05:07:34
VBASE030.VDF : 7.11.7.239 2048 Bytes 5/11/2011 05:07:34
VBASE031.VDF : 7.11.7.254 68608 Bytes 5/12/2011 05:07:34
Engineversion : 8.2.4.228
AEVDF.DLL : 8.1.2.1 106868 Bytes 3/28/2011 23:15:27
AESCRIPT.DLL : 8.1.3.61 1253754 Bytes 5/13/2011 05:07:39
AESCN.DLL : 8.1.7.2 127349 Bytes 3/28/2011 23:15:27
AESBX.DLL : 8.1.3.2 254324 Bytes 3/28/2011 23:15:26
AERDL.DLL : 8.1.9.9 639347 Bytes 3/25/2011 19:21:38
AEPACK.DLL : 8.2.6.0 549237 Bytes 5/13/2011 05:07:38
AEOFFICE.DLL : 8.1.1.22 205178 Bytes 5/13/2011 05:07:38
AEHEUR.DLL : 8.1.2.113 3494263 Bytes 5/13/2011 05:07:37
AEHELP.DLL : 8.1.16.1 246134 Bytes 3/28/2011 23:15:20
AEGEN.DLL : 8.1.5.4 397684 Bytes 5/13/2011 05:07:36
AEEMU.DLL : 8.1.3.0 393589 Bytes 3/28/2011 23:15:19
AECORE.DLL : 8.1.20.2 196982 Bytes 5/13/2011 05:07:35
AEBB.DLL : 8.1.1.0 53618 Bytes 3/28/2011 23:15:19
AVWINLL.DLL : 10.0.0.0 19304 Bytes 3/28/2011 23:15:31
AVPREF.DLL : 10.0.0.0 44904 Bytes 4/2/2011 00:07:42
AVREP.DLL : 10.0.0.9 174120 Bytes 5/13/2011 05:07:39
AVREG.DLL : 10.0.3.2 53096 Bytes 4/2/2011 00:07:42
AVSCPLR.DLL : 10.0.4.2 84840 Bytes 4/2/2011 00:07:43
AVARKT.DLL : 10.0.22.6 231784 Bytes 4/2/2011 00:07:38
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 4/2/2011 00:07:41
SQLITE3.DLL : 3.6.19.0 355688 Bytes 6/17/2010 22:27:22
AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/28/2011 23:15:30
NETNT.DLL : 10.0.0.0 11624 Bytes 3/28/2011 23:15:39
RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 4/2/2011 00:07:58
RCTEXT.DLL : 10.0.58.0 97128 Bytes 3/28/2011 23:15:52

Configuration settings for the scan:
Jobname………………………..: ShlExt
Configuration file………………: C:\Users\Linda\AppData\Local\Temp\4ae8a431.avp
Logging………………………..: low
Primary action………………….: interactive
Secondary action………………..: ignore
Scan master boot sector………….: on
Scan boot sector………………..: on
Boot sectors……………………: C:,
Process scan……………………: off
Scan registry…………………..: off
Search for rootkits……………..: off
Integrity checking of system files..: off
Scan all files………………….: Intelligent file selection
Scan archives…………………..: on
Recursion depth…………………: 20
Smart extensions………………..: on
Macro heuristic…………………: on
File heuristic………………….: medium
Deviating risk categories………..: +APPL,+PFS,

Start of the scan: Friday, May 13, 2011 09:05

Starting the file scan:

Begin scan in 'C:\Users\Linda\Downloads\FlashDisinfect from bleeping computers.exe'
C:\Users\Linda\Downloads\FlashDisinfect from bleeping computers.exe
[DETECTION] Contains recognition pattern of the APPL/NirCmd.2 application

[0] Archive type: RAR SFX (self extracting)
–> nircmd.exe
[DETECTION] Contains recognition pattern of the APPL/NirCmd.2 application

Beginning disinfection:
C:\Users\Linda\Downloads\FlashDisinfect from bleeping computers.exe
[DETECTION] Contains recognition pattern of the APPL/NirCmd.2 application
[NOTE] The file was moved to the quarantine directory under the name '4a12f3ff.qua'.


End of the scan: Friday, May 13, 2011 09:06
Used time: 00:00 Minute(s)

The scan has been done completely.

0 Scanned directories
7 Files were scanned
1 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
6 Files not concerned
1 Archives were scanned
0 Warnings
1 Notes
__________________

hijackthis log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:26:55 AM, on 5/13/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Users\Linda\CoreTemp32\Core Temp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\System32\taskmgr.exe
C:\Windows\explorer.exe
C:\Program Files\Avira\AntiVir Desktop\avscan.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Linda\Desktop\HiJackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [PC Tools AntiVirus Free] C:\Users\Linda\Desktop\avinstall pctools from download.cnet.com.exe -min
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

–
End of file - 3141 bytes
Good. You may want to download and install Secunia Personal Software Inspector (PSI) to help keeping system up-to-date.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI