Computer SLOWS periodically Freezes NirCmd found

Discussion in 'Malware Help (A Specialist Will Reply)' started by beckylousiana, Nov 16, 2009.

  1. beckylousiana

    beckylousiana Corporal

    I have recently reinstalled Windows on my Desktop Dell Deminsion, running XP Professional, with SP3. I just basically wanted to remove all unwanted programs and leftovers from years, (approx 4 years old) as it would slow and freeze periodically.
    Everything seemed to be working fine, except with issues with IE8, and Firefox. I have reverted back to IE7, and Firefox still shuts down periodically, I am not sure why??
    I was running avast, but when I tried to open it up to do a scan, it gave me an error message "Unknow Error, Skin could not load" I felt something may be wrong. I uninstalled Avast, and installed PC Tools, ran a scan with 3 results of Application.NirCmd
    I couldn't figure out with all the research whether to delete or not, so I just quarantined them. Now I just had an alert with PC Tools "swxcacls.exe Infection Application.NirCmd" and I quarantined that also. I have done the Read and Run Me and have attached the logs.
    I WILL ATTACH COMBOFIX Log in a post to follow, since I cannot attach more than 4 attachments to this post....
    I haven't noticed anything for the last hour or so, but would like for someone to look at the logs just to help me sleep at night... :)
     

    Attached Files:

  2. beckylousiana

    beckylousiana Corporal

    Here is Combo Fix Log...
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The more recent versions of firefox have been unstable for many despite the fact they keep knocking out stability updates. I have not had time to visit the mozilla forums to see this being discussed however for me it crashes alot, often when opening up a new tab or closing one down.

    nircmd.exe is not a problem. This file is use by a variety of malware cleaning tools. One of the tools that uses it is SmitFraudFix.

    Your MGlogs.zip is incomplete. Can I ask you, when you ran MGTools did you receive any error messages at all? If so could you try your best to remember what they were, or even better if you noted them down.

    Also could you tell me if perhaps you could have exited out of the program before it ran completely? Could protection software have got in the way?
    Did you agree to the Hijackthis license agreement?

    Please refer to the below link for information on error messages:

    Using MGtools

    *scroll down to possible error messages section*

    I suspect that you are malware free, however you need to try to get MGTools to run completely so we can rule it out for certain.

    Thanks
    Kes13!
     
  4. beckylousiana

    beckylousiana Corporal

    HI!

    I have ran the MGTools again, and have attached the log. I do recall an issue when I ran it previously, as my Comodo Firewall was not deactivated, and created a conflict, but it appeared to run normally after I shut down the firewall, so I didn't think about running it again.... Hopefully this one will be complete...

    I guess I should just use IE7 for now?

    thanx!!!!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    2. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\Documents and Settings
    
    Folder::
    c:\program files\Alwil Software     
    c:\program files\AVG
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    4. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. beckylousiana

    beckylousiana Corporal

    Hi again!
    I got an error/warning message when running ComboFix about "Real Time" protection being enable, and that it may interfere. I had EXITED PCTools, but before exiting, I did not turn off the Real Time Intelliguard... which was the same problem as before, i need to remember that....
    I tried to exit out of ComboFix window to then restart it after disabling the real time, but it would not let me. So I disabled Real Time protection on PCTools, and allowed ComboFix to run.
    I walked out of the room and I believe that it "restarted" my computer, as when I returned, my virus/firewall/spyware programs were coming back on, and the ComboFix window was displaying the message "Preparing Log Report. Do not run any programs until combo fix has finished. I waited about 10 min or so, then I just closed out that window.
    I then turned everything OFF, including the real scan, and ran ComboFix again with all the proper settings.
    I have attached the logs.

    I have not been on the computer very much since my first post, i was out of town, I am using IE7 and don't seem to be have any problems thus far.
    Maybe just a few little slow openings. However, I am unable to Update my Comodo Firewall program. Usually I just hit the update button, but now it is bringing me to a page to download the programs, and not button to update?!?!?!? I have asked their support forum for guidance, but have not received a response...

    Thanx!!!!!!!!!!!!!!!!!!!!
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then I would like to see the other log it produced too please. :)
     
  8. beckylousiana

    beckylousiana Corporal

    I think that the new log covered the old one up??? I can't find it??
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not to worry.... I need to head out for a while now as I start work soon, however I shall review your logs as soon as I possibly can and get back to you with a response. :)

    Thanks for your patience
    Kes13!
     
  10. beckylousiana

    beckylousiana Corporal

    Just fyi, when the computer apparently "restarted" on it's on when I was out of the room and PCTools started back up, it noted the same Infection, FILE: c:\windows\swxcacls.exe INFECTION: Application.Nircmd.
    I selected to Quarantine it, and now there are several instances in my Quarantied file. Should I release them? How can I get PCTools to quit labeling it as an infection?
    Thanx!!!!!! I really appreciate your help!!
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes and this is something that you will have to post and report as a false positive on their forums. It is not malware, it is from running combofix or smitfraud removal tools. It can sometimes be used by malware however this is not the case as I am not seeing anything suspicious in you logs. The link to their forum is as follows:

    http://www.pctools.com/forum/

    So it's up to you whether you want to pursue reporting it as a false positive. But you will find that once combofix is uninstalled which you will do after following my final steps, that you will no longer have it reporting the file.

    Your logs are clean :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. beckylousiana

    beckylousiana Corporal

    Great!! I am very grateful for your quick, thorough, and comprehensive assistance!! Best support I have received on this forum! This post will help several people that may have questions about the Application.NirCmd Because when I initially searched this forum before posting, it failed to find anything to help me better understand.
    I am actually in a boxblind out in the woods, will have to get back to my puter Sunday night and follow the steps you suggested. Hopefully everything will go smoothly!!
    Have a Great weekend!!! You deserve it!!
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome :) Enjoy your weekend also.
     
  14. beckylousiana

    beckylousiana Corporal

    Uh Oh!
    I have tried to run the program to uninstall ComboFix Twice, but it just runs the scan again. I copied and pasted the program into the Run Box....
    Is there something missing? I don't see it in Add Remove Programs, or my CC Cleaner list of programs. I also then tried to uninstall HiJack This, and it could not find the file to remove it, somehow it got uninstalled...
    any advice? Thanx!!!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    • "%userprofile%\Desktop\combofix" /uninstall
    • Notes: The space between the combofix" and the /uninstall, it must be there.
    • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
     
  16. beckylousiana

    beckylousiana Corporal

    I tried to run this, and it gave me an error stating that the file could not be found. I did a search for any file with Combo, and if found a Folder with 1 log in it?? Weird, but I guess it is uninstalled, because I can't find it. Thanx!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds