This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected with Worm.Alcra.F and other nasties

291 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi mschroe919
I have now deleted the combofix icon and the saved files. However the Application.NirCmd is still showing.Herewith the log from spyware doctor and a HJT log.

PC Tools Spyware Doctor
Date Status
05/03/2008 19:29:47:359 Immuniser Results
ActiveX section has been immunised. No items were processed.
05/03/2008 19:31:39:531 Scan Started
Scan Type - Intelli-Scan

05/03/2008 19:32:26:265 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, combofix_wow

05/03/2008 19:32:26:281 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, Runs

05/03/2008 19:32:26:281 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, snapshot

05/03/2008 19:32:26:296 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware

05/03/2008 19:32:26:328 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME, NextInstance

05/03/2008 19:32:26:343 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Service

05/03/2008 19:32:26:343 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Legacy

05/03/2008 19:32:26:343 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, ConfigFlags

05/03/2008 19:32:26:343 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Class

05/03/2008 19:32:26:343 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, ClassGUID

05/03/2008 19:32:26:343 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, DeviceDesc

05/03/2008 19:32:26:359 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Capabilities

05/03/2008 19:32:26:359 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Driver

05/03/2008 19:32:26:359 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000\LogConf

05/03/2008 19:32:26:359 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000\Control

05/03/2008 19:32:26:359 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000

05/03/2008 19:32:26:359 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME

05/03/2008 19:32:26:406 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, Type

05/03/2008 19:32:26:406 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, ErrorControl

05/03/2008 19:32:26:406 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, Start

05/03/2008 19:32:26:406 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, ImagePath

05/03/2008 19:32:26:406 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, Group

05/03/2008 19:32:26:406 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum, 0

05/03/2008 19:32:26:421 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum, Count

05/03/2008 19:32:26:421 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum, NextInstance

05/03/2008 19:32:26:421 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum

05/03/2008 19:32:26:421 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme

05/03/2008 19:32:28:187 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile, (Default)

05/03/2008 19:32:28:187 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shell\open, EditFlags

05/03/2008 19:32:28:187 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shell\open\command, (Default)

05/03/2008 19:32:28:187 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shell\open\command

05/03/2008 19:32:28:187 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shell\open

05/03/2008 19:32:28:187 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shell

05/03/2008 19:32:28:187 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shellex\DropHandler, (Default)

05/03/2008 19:32:28:187 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shellex\DropHandler

05/03/2008 19:32:28:203 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\PifProps, (Default)

05/03/2008 19:32:28:203 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\PifProps

05/03/2008 19:32:28:203 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\ShimLayer Property Page, (Default)

05/03/2008 19:32:28:203 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\ShimLayer Property Page

05/03/2008 19:32:28:203 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Value
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}, (Default)

05/03/2008 19:32:28:234 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}

05/03/2008 19:32:28:234 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers

05/03/2008 19:32:28:234 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile\shellex

05/03/2008 19:32:28:250 Infection was detected on this computer
Threat Name - Application.NirCmd
Type - Registry Key
Risk Level - Info & PUAs
Infection - HKEY_CLASSES_ROOT\crexefile

05/03/2008 19:34:27:921 Scan Finished
Scan Type - Intelli-Scan
Items Processed - 159624
Threats Detected - 1
Infections Detected - 44
Infections Ignored - 0

——————————————

Logfile of HijackThis v1.99.1
Scan saved at 19:46:02, on 05/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virgin Broadband\PCguard\Fws.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Virgin Broadband\PCguard\rpsupdaterR.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Virgin Broadband\PCguard\SwchMonR.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe
C:\Program Files\Virgin Broadband\PCguard\Rps.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Spyware Doctor\pctsGui.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\Scanner.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Virgin Broadband\PCguard\pkR.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Broadbandadvisor.exe] "C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" /AUTORUN
O4 - HKLM\..\Run: [PCguard] "C:\Program Files\Virgin Broadband\PCguard\Rps.exe"
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Virgin Broadband\PCguard\ZkRunOnceR.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [IndexCleaner] "C:\Program Files\Virgin Broadband\PCguard\IdxClnR.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Virgin Broadband\PCguard\IdxClnR.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {34F12AFD-E9B5-492A-85D2-40FA4535BE83} (AxProdInfoCtl Class) - http://www.symantec.com/techsupp/activedata/nprdtinf.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Virgin Broadband PCguard Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Virgin Broadband\PCguard\rpsupdaterR.exe
O23 - Service: PCguard Firewall (RP_FWS) - Virgin Media - C:\Program Files\Virgin Broadband\PCguard\Fws.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
Hi EAGLE,

Your doing well

NEXT:
Open notepad and copy and paste next present in the quote box below in it:

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\swearware]


Save this as fix.reg Choose to save as all files and place it on your desktop.

Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes.

after this reboot and tell me how PC is behaving
good luck mschroe919
Hi mschroe919 I have performed the latest instructions. Unfortunately the Application.NirCmd still appears. Pse see the log below : PC Tools Spyware Doctor Date Status 05/03/2008 19:29:47:359 Immuniser Results ActiveX section has been immunised. No items were processed. 05/03/2008 19:31:39:531 Scan Started Scan Type - Intelli-Scan 05/03/2008 19:32:26:265 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, combofix_wow 05/03/2008 19:32:26:281 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, Runs 05/03/2008 19:32:26:281 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware, snapshot 05/03/2008 19:32:26:296 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SOFTWARE\swearware 05/03/2008 19:32:26:328 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME, NextInstance 05/03/2008 19:32:26:343 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Service 05/03/2008 19:32:26:343 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Legacy 05/03/2008 19:32:26:343 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, ConfigFlags 05/03/2008 19:32:26:343 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Class 05/03/2008 19:32:26:343 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, ClassGUID 05/03/2008 19:32:26:343 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, DeviceDesc 05/03/2008 19:32:26:359 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Capabilities 05/03/2008 19:32:26:359 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Driver 05/03/2008 19:32:26:359 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000\LogConf 05/03/2008 19:32:26:359 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000\Control 05/03/2008 19:32:26:359 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000 05/03/2008 19:32:26:359 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME 05/03/2008 19:32:26:406 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, Type 05/03/2008 19:32:26:406 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, ErrorControl 05/03/2008 19:32:26:406 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, Start 05/03/2008 19:32:26:406 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, ImagePath 05/03/2008 19:32:26:406 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, Group 05/03/2008 19:32:26:406 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum, 0 05/03/2008 19:32:26:421 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum, Count 05/03/2008 19:32:26:421 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum, NextInstance 05/03/2008 19:32:26:421 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum 05/03/2008 19:32:26:421 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme 05/03/2008 19:32:28:187 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile, (Default) 05/03/2008 19:32:28:187 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shell\open, EditFlags 05/03/2008 19:32:28:187 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shell\open\command, (Default) 05/03/2008 19:32:28:187 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shell\open\command 05/03/2008 19:32:28:187 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shell\open 05/03/2008 19:32:28:187 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shell 05/03/2008 19:32:28:187 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\DropHandler, (Default) 05/03/2008 19:32:28:187 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\DropHandler 05/03/2008 19:32:28:203 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\PifProps, (Default) 05/03/2008 19:32:28:203 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\PifProps 05/03/2008 19:32:28:203 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\ShimLayer Property Page, (Default) 05/03/2008 19:32:28:203 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\ShimLayer Property Page 05/03/2008 19:32:28:203 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}, (Default) 05/03/2008 19:32:28:234 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA} 05/03/2008 19:32:28:234 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers 05/03/2008 19:32:28:234 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex 05/03/2008 19:32:28:250 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile 05/03/2008 19:34:27:921 Scan Finished Scan Type - Intelli-Scan Items Processed - 159624 Threats Detected - 1 Infections Detected - 44 Infections Ignored - 0 05/03/2008 19:56:28:734 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:02:34:31 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:04:54:843 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:06:18:218 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:10:49:656 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:11:41:390 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:16:52:203 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:20:37:984 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:24:38:187 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:30:47:546 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:36:36:312 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:42:50:390 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:48:51:46 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 20:54:51:937 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 21:00:53:46 OnGuard Detection Cleaned Threat Name - Application.TrackingCookies Type - Cookie Risk Level - Low Infection - adecn.com/ adecn.com 05/03/2008 21:28:49:859 Service Stopped Spyware Doctor Service Application Stopped 05/03/2008 21:30:50:812 Service Started Spyware Doctor Service Application started 05/03/2008 21:30:51:15 OnGuards status All OnGuards were Enabled 05/03/2008 21:30:52:46 Immuniser Results ActiveX section has been immunised. No items were processed. 05/03/2008 21:34:16:734 Scan Started Scan Type - Intelli-Scan 05/03/2008 21:34:58:15 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME, NextInstance 05/03/2008 21:34:58:31 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Service 05/03/2008 21:34:58:31 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Legacy 05/03/2008 21:34:58:31 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, ConfigFlags 05/03/2008 21:34:58:31 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Class 05/03/2008 21:34:58:31 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, ClassGUID 05/03/2008 21:34:58:46 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, DeviceDesc 05/03/2008 21:34:58:62 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Capabilities 05/03/2008 21:34:58:62 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Driver 05/03/2008 21:34:58:62 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000\LogConf 05/03/2008 21:34:58:62 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000\Control 05/03/2008 21:34:58:62 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000 05/03/2008 21:34:58:62 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME 05/03/2008 21:34:58:93 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, Type 05/03/2008 21:34:58:93 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, ErrorControl 05/03/2008 21:34:58:93 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, Start 05/03/2008 21:34:58:93 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, ImagePath 05/03/2008 21:34:58:93 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, Group 05/03/2008 21:34:58:93 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum, 0 05/03/2008 21:34:58:93 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum, Count 05/03/2008 21:34:58:93 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum, NextInstance 05/03/2008 21:34:58:93 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum 05/03/2008 21:34:58:93 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme 05/03/2008 21:34:59:984 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile, (Default) 05/03/2008 21:34:59:984 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shell\open, EditFlags 05/03/2008 21:34:59:984 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shell\open\command, (Default) 05/03/2008 21:35:00:0 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shell\open\command 05/03/2008 21:35:00:0 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shell\open 05/03/2008 21:35:00:0 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shell 05/03/2008 21:35:00:0 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\DropHandler, (Default) 05/03/2008 21:35:00:0 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\DropHandler 05/03/2008 21:35:00:0 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\PifProps, (Default) 05/03/2008 21:35:00:0 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\PifProps 05/03/2008 21:35:00:15 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\ShimLayer Property Page, (Default) 05/03/2008 21:35:00:15 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\ShimLayer Property Page 05/03/2008 21:35:00:15 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Value Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}, (Default) 05/03/2008 21:35:00:15 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA} 05/03/2008 21:35:00:15 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex\PropertySheetHandlers 05/03/2008 21:35:00:15 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile\shellex 05/03/2008 21:35:00:15 Infection was detected on this computer Threat Name - Application.NirCmd Type - Registry Key Risk Level - Info & PUAs Infection - HKEY_CLASSES_ROOT\crexefile 05/03/2008 21:36:45:500 Scan Finished Scan Type - Intelli-Scan Items Processed - 179343 Threats Detected - 1 Infections Detected - 40 Infections Ignored - 0
Hi EAGLE,
looks like thery put the name Application.NirCmd on all infractions
Unless spyware doctor doesn't name the threaat I think your allrighrt;
the name Application.NirCmd refers to see below.

Application.NirCmd is a collection of third party tools packed in one executable that can be used to remove threats in an infected machine. However it can also be used by users with malicious intent to do a different activity.

NEXT:
Open HJT and click on Open the Misc Tools section
Click Open Uninstall Manager…
Click Save list… and save it to your Desktop.
Copy and paste the file uninstall_list.txt here
NEXT:
Since you can't run F-Secure on line (of course we could try again.
If not lets run your spybot S&D
let me know if found anything that couldn't be fixed
make sure you spybot is updated
mschroe929.
Hi mschroe919 Things are looking good , after running spybot S & D no virus was found. On the hijackthis uninstall list I saw authentium antivirus listed . I dont remember loading this software. It doesnt show under add/remove programs. I would like to get rid of this software I am not aware of. I have pasted below the HJT uninstall_list . 3D Groove Playback Engine Acoustica Effects Pack Ad-Aware 2007 Adobe Flash Player ActiveX Adobe Reader 8.1.1 Adobe Shockwave Player Adobe® Photoshop® Album Starter Edition 3.2 Amazing Adventures The Lost Tomb Apple Mobile Device Support Apple Software Update Audacity 1.2.4 Authentium AntiVirus SDK - 2 AVG Anti-Spyware 7.5 Azureus Vuze BCM V.92 56K Modem Bonjour Dell Picture Studio - Dell Image Expert DivX DivX Player Driving Test Success 2005/6 EPSON Attach To Email EPSON Easy Photo Print EPSON File Manager EPSON Printer Software EPSON Scan Assistant EPSON Web-To-Page Family Tree Maker 2005 FIFA 2005 DEMO Full Marks Key Stage 3 Science Google Toolbar for Internet Explorer Hijackthis 1.99.1 HijackThis 1.99.1 HP Customer Participation Program 7.0 HP Imaging Device Functions 7.0 HP Photosmart Essential HP Photosmart, Officejet and Deskjet 7.0.A HP Software Update HP Solution Center 7.0 Intel® Extreme Graphics Driver InterActual Player iTunes Java™ 6 Update 2 Java™ SE Runtime Environment 6 Update 1 Jimmy Neutron Boy Genius Jimmy Neutron vs. Jimmy Negatron Macromedia Flash Player 8 Microsoft Office PowerPoint Viewer 2003 Microsoft Works 7.0 MSN MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) Nero 6 Enterprise Edition Nokia PC Suite OCR Software by I.R.I.S 7.0 Paint Shop Pro 7 PerfectDisk PowerDVD PowerISO PPSDKRedistributables QuickTime Radialpoint Security Services RPS Ad Blocker RPS AntiFraud RPS AntiSpyware RPS AntiVirus RPS App Detector RPS AsRealtime RPS Backup RPS Burn RPS Diagnostic Utility RPS Firewall RPS ParentalControl RPS Performance Tool RPS PopupBlocker RPS Privacy Manager RPS RpsCore RPS Security Cleanup RPS Zip Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB942615) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944533) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB946026) SoundMAX Spybot - Search & Destroy 1.4 Spyware Doctor 5.5 SpywareBlaster v3.5.1 SpywareGuard v2.2 SUPERAntiSpyware Free Edition Symantec Technical Support Web Controls The Lion (remove only) Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB942840) Update for Windows XP (KB946627) VideoLAN VLC media player 0.8.6d Virgin Broadband advisor 1.5.14 Virgin Broadband PCguard Warblade v1.2Y.6 WG111v2 Configuration Utility Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Yahoo! Toolbar
Hi Eagle,
Things are looking great. Your log is clean.
So I say again, pat yourself on the back, you did a great job cleaning
your PC.
To remove (Authentium AntiVirus SDK - 2) you can do it this way:
To access the Uninstall Manager you would do the following:
Start HijackThis
Click on the Config button
Click on the Misc Tools button
Click on the Open Uninstall Manager button.
You will now be presented with a screen similar to the one below:
[external image: Posted Image]

click on Authentium AntiVirus SDK - 2 to highlite it. then click on the delete this entery.
This being done there is only one more step to take.
==========================================================

This is the canned speech I give at rthe end of all cleaned PC's:
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Note you may have some of theses programs allready, if so just a reminder to keep updated.

FIRST:
You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.
===================================================================
NEXT:
Make your Internet Explorer more secure - This can be done by following these simple instructions:

1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.

1. Change the Download signed ActiveX controls to Prompt
2. Change theDownload unsigned ActiveX controls to Disable
3. Change the Initialise and script ActiveX controls not marked as safe to Disable
4. Change the Installation of desktop items to Prompt
5. Change the Launching programs and files in an IFRAME to Prompt
6. Change the Navigate sub-frames across different domains to Prompt
7. When all these settings have been made, click on the OK button.
8. If it prompts you as to whether or not you want to save the settings, press the Yes button.

Next press the Apply button and then the OK to exit the Internet Properties page.
====================================================================

Use an Anti Virus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See these links for a listing of some on line & their stand-alone anti virus programs:
If you don't have one here are some of the better AV products.

Symantec/Norton Antivirus: http://www.symantec.com/nav/nav_9xnt/
Kapersky AV: http://www.kaspersky.com/buyonline.html?info=25
Nod32 : http://www.nod32.com/home/home.htm
Panda AV: http://www.pandasoftware.com/
McAfee Virusscan: http://us.mcafee.com/root/package.asp?pkgid=100
AVG Anti-Virus (Free version available) http://www.grisoft.com/

Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.
============================================================
NEXT:

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly.
If you don't have one see link below for a free firewall:

ZoneAlarm:
http://www.zonelabs.com/store/content/cata….jsp?lid=nav_za

Sunbelt Kerio:
http://www.sunbelt-software.com/Kerio.cfm

OutPost:
http://www.agnitum.com/products/outpostfree/download.php
================================================================================

Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.

This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software

Get the download and tutorial for Spybot S&D here:
http://www.bleepingcomputer.com/tutorials/tutorial43.html
=========================================================================

Install Ad-Aware
Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. The download and tutorial on installing & using Ad-aware can be found here:
http://www.bleepingcomputer.com/tutorials/tutorial48.html

====================================================================

Install SpywareBlaster
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here:

http://www.javacoolsoftware.com/spywareblaster.html
========================================================================

Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.
Happy surfing the net

I only ask one thing….please
Please post back and let us know what you think about our forum, we are all volunteers and would like a little smile.


Good luck Mschroe919
Hi mschroe919
The pat on the back should certainly be yours. I cannot thank you enough. All that work you do , going through those miles and miles of logs I posted. I am really really grateful for all your assistance my PC is a lot better now.
Oh one thing I forgot to ask you, at some point during the pc clean-ups I got a warning from spyware guard that an attempt was being made to change my browser home-page to what it is now i.e http://uk.msn.com. I cant remember what it was before I should have taken note of it. But anyway I accepted the change and clicked ok. Is this the authentic page for msn or some fake one. And I have just got this warning again from spyware guard.. WARNING ! Your IE default search url has been changed. Your Internet Explorer local machine default search url has been changed http://go.microsoft.com/fwlink/?Linkld
to http://www.google.com/ie
Again is this okay or not ?

Regards
Hi EAGLE,
Yes it is a authentic page:
However you can change it to anything you want,
I have www.google.com as my home page.
Here easy steps to change:
First click on TOOLS on the main menu at the top of the screen, then click on INTERNET OPTIONS as see fig 1.1 below:

🖼Click to load external image (Posted Image)

next you will see the Internet Options dialogue box as shown below in fig 1.2

🖼Click to load external image (Posted Image)

Type in the address of the homepage you would like to set, or if it is the one you are currently visiting just click Use Current.

then simply click on the OK button.


Happy surfing mschroe919
Hi mschroe919 So I am clean now ! Once again I would like to say thank you very much for your help in cleaning my PC. I really appreciate it. You guys are doing a wonderful job. Take care and God bless. Regards Eagle
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI