Nircmd Sophos



  1. Nircmd Sophos
  2. Sophos Nircmd.exe

NirCmd is a small command-line utility that allows you to do some useful tasks without displaying any user interface. The NirCmd (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Antivirus 'False Positive' Problems

Sometimes Antivirus scanner reports that a program is infected with a Virus or Trojan,even when the program is not really infected with any malicious code.This kind of problem is known as 'False Positive' or 'False Alert',and it's quite a common problem in some of the password recovery tools provided in NirSoft Web site.

Nircmd Sophos

Nircmd

The following table contains the latest 'False Positive' problems reported by users of NirSoft utilities. If your Antivirus scanner reports that a program you downloaded from NirSoft is infected with a Virus or Trojan, and that virus/trojan is not listed in the table below, please report about that to nirsofer@yahoo.com, and specify the name of your Antivirus scanner, and the name of the Virus/Trojan that it detects. It's also recommended to contact your Antivirus company, and ask them to fix this 'False Positive' problem.

Notice: Due to large amount of false positives I receive on daily basis, I decided to stop updating this list.
Instead, I posted this article on my Blog: Antivirus companies cause a big headache to small developers
I hope it'll eventually help me and other developers to decrease the false positives problems.If you want to check the current false positives issues for specific utility, you can use VirusTotal Web site to get virus alerts list in 40 Antivirus programs.

Sophos Nircmd.exe

Nircmd sophos

If you want to send a report about a false positive to the Antivirus company, readthe following article that explains how to do it:
How to Report Malware or False Positives to Multiple Antivirus Vendors Store app for mac.



DescriptionMessenPassDrWeb antivirus detects MessenPass as infected with Trojan.Inject.458001/12/2008
ProduKeyAVG McAfee VirusScan Enterprise 8.50 detect ProduKey as infected with Generic PWS.y (Trojan)26/10/2008
22/10/2008
17/10/2008
15/10/2008
15/10/2008
14/10/2008
11/10/2008
01/10/2008
05/05/2008
28/04/2008
17/04/2008
17/04/2008
WebVideoCapAVG detect WebVideoCap as Trojan Horse Proxy.XJS.12/01/2008
ProduKeySymantec Antivirus detect ProduKey utility as 'Security Assessment Tool'.07/12/2007
IE PassViewAVG AntiSpyware reports that iepv.exe isinfected with Dropper.Agent.IU03/09/2007
Protected Storage PassViewTrojan Hunter reports that Protected Storage PassView is infected with PWSteal.ICQSmiley.10214/06/2007
ShellExViewBitdefender reports that ShellExView is infected with Win32.Freetrip.C@mm.04/04/2007
CurrPortsNorton Antivirus Corporate reports that CurrPorts utility is infected with backdoor.trojan 05/02/2007
Network Password RecoveryTrend Micro Antivirus reports that netpass.exe is infected with PE_Generic virus.05/02/2007
Network Password RecoveryMcAfee VirusScan Enterprise reports that Network Password Recovery utilityis infected with PWCrack-NetPass.22/12/2006
Protected Storage PassViewBitDefender 8 reports that Protected Storage PassView is infected with Trojan.PWS.Iqsmile.A06/09/2006
IPNetInfoTrend Micro Antivirus detect IPNetInfo utility as a keylogger.12/05/2006
Mail PassViewAVG 7.1 Pro Antivirus reports that Mail PassView is infected with 'BackDoor.Generic2.Joo' trojan.02/03/2006
17/02/2006
16/01/2006
05/01/2006
Protected Storage PassViewBitdefender 8.x/9.x antivirus reports that Protected Storage PassView is infected with Application.passview.A05/01/2006
Protected Storage PassViewAVG Antivirus reports that Protected Storage PassView is infected with Downloader.Generic.KZA Trojan 13/12/2005
Protected Storage PassViewNorton Antivirus Corporate Edition identifies Protected Storage PassView as Hacktool.Passreminder.17/11/2005
Protected Storage PassViewNOD32 Antivirus (v2.50) detect Protected Storage PassView as Win32/PassView.1_62. 23/09/2005
23/08/2005
IconsExtractMcAfee VirusScan detects IconsExtract as infected with PassDump.b Trojan.23/06/2005
13/03/2005
StartupRun'Spybot Search And Destroy' reports that StartupRun utility is a malware.09/12/2004
03/12/2004
30/11/2004
10/11/2004
DialupassNorton Anti-Virus reports that dialupass.exe is infected with PWSteal.Trojan09/09/2004