Nircmd Sophos



Movie about knives

ProgramWin32Pameseg.U is a hazardous ransomware which wants affected PC users to purchase some software programs that are freely available on the Internet. Nircmd.exe tagged by Sophos Anti-Virus. So I appreciate this isn't an issue with Prey per-se, but I do wonder if you're about to get a barrage of incoming email / support about it, and it might be useful to know. As of 'Threat Data: 5.39', Sophos Anti-Virus is detecting nircmd.exe as being spyware, and directing users to.

NameEngine
BHO.KEMAVG
Voronezh.1600.AN/A
Trojan.1Sunbelt
Trojan/Win32.GenomeAhnLab-V3
Trojan/Win32.Genome.genAntiy-AVL
Adware.Bho.405DrWeb
TrojWare.Win32.BHO.RBComodo
Trojan.Generic.1249573BitDefender
Trojan.Win32.Genome.ftdnKaspersky
TROJ_Generic.DIFN/A
W32/Suspicious_Gen.FKFMN/A
Win32/BHO.NUJNOD32
Trojan.Chepdu.FFN/A
Trojan/W32.Agent.176128.CRN/A
Adware/WebSearchPanda
Generic11.BLQDAVG
W32/Agent.IJE!trFortinet
Trojan.GenericN/A
Trojan/Win32.BHOAhnLab-V3
High Risk WormN/A
Trojan/BHO.bnyN/A
TR/BHO.GenAntiVir
Trojan.Siggen.1485DrWeb
TrojWare.Win32.Trojan.BHO.IJE0Comodo
Trojan.Generic.1217263BitDefender
Trojan.Win32.BHO.ijeKaspersky
Trojan.BHO-4379ClamAV
TROJ_Generic.F01N/A
W32/BHO.HAXN/A
Trojan HorseSymantec
W32/Trojan3.QCF-Prot
Win32/BHO.IJENOD32
Trojan.BHO.QPKN/A
Trojan/BHO.ijeN/A
Trojan.BHO.ijeCAT-QuickHeal
Trojan/W32.BHO.172032.NN/A
Artemis!D52A849BAAE0McAfee
AdWare.Win32.BHO.fgfN/A
Win32/Gamepass.MSKeTrust-Vet
Mal/BanLoad-NSophos
TR/Drop.Agen.241664AntiVir
a variant of Win32/Chepdu.ACNOD32
Trojan.Chepdu.RCAT-QuickHeal
Gen:Variant.Chepdu.1N/A
Trojan-Ransom.Win32.PinkBlocker!IKN/A
Artemis!44318FE27B32McAfee
Cryptic.CCFAVG
Gen.Variant.HilotiIkarus
Trojan.Win32.Generic.12758BCBN/A
Trojan.Agent/Gen-Kazy[FrameDbl]N/A
TR/Crypt.XPACK.Gen3AntiVir
a variant of Win32/Kryptik.KDHNOD32
Gen:Variant.Kazy.3358N/A
Trojan-Ransom.Win32.PinkBlockerIkarus
Trojan.Script.BAT.Agent.czN/A
PUA.Tool.Nirsofer.NirCmdClamAV
Virus in password protected archiveeSafe
23.44.00.08N/A
Artemis!A8C48C8994EBMcAfee
Bscope.Malware-Cryptor.TipN/A
Trojan/Win32.HilotiAhnLab-V3
Trojan.Agent/Gen-RogueDropN/A
Mal/Hiloti-DSophos
Trojan.Win32.Hiloti.mp (v)N/A
Gen:Variant.Hiloti.3BitDefender
TROJ_HILOTI.SME2N/A
Trojan.Script.BAT.StartPage.byN/A
Virus/Win32.Goblin.genAntiy-AVL
Trojan/Agent.dwspN/A
NirCmdSophos
Artemis!4C1BD6F803C2McAfee
Trojan-Downloader.Win32.Agent.daomN/A
Win-Trojan/Eggdrop.246532AhnLab-V3
Mal/Emogen-ESophos
Heuristic.LooksLike.Win32.Suspicious.JMcAfee-GW-Edition
PUA.Packed.PECompact-1ClamAV
Suspicious FileeSafe
W32/Suspicious.C4!genrN/A
W32/Threat-SysVenFakP-based!MaximusF-Prot
BackdoorK7AntiVirus
Backdoor.EggDrop.17CAT-QuickHeal
Trojan/W32.Agent.118272.BYN/A
Cryptic.BTQAVG
W32/BHO.BBPS!trFortinet
Gen.Variant.BuzyIkarus
Trojan.BHO.bbpsN/A
Win-Trojan/Bho.407040.BAhnLab-V3
TR/BHO.bbpsAntiVir
MalCrypt.Indus!Comodo
Gen.Variant.Buzy!IKN/A
Gen:Heur.Krypt.12BitDefender
Trojan.Win32.BHO.bbpsKaspersky
WS.Reputation.1Symantec
a variant of Win32/Kryptik.JQJNOD32
Trojan.BHO!DA5rNjq2Kw4N/A
Trojan/BHO.bbpsN/A
Artemis!934030D2B0DAMcAfee
Trojan/W32.BHO.407040N/A
Generic TrojanPanda
Generic20.CFSIAVG
W32/Palevo.BJD!wormFortinet
Gen.Trojan.HeurIkarus
Trojan.Win32.Generic.1274E0DFN/A
Worm.Kolab.srrN/A
Trojan/Win32.InjectorAhnLab-V3
Medium Risk MalwareN/A
Worm.Win32.Net-Kolab.60416N/A
Trojan/Pincav.llvN/A
Win32/Rimecud.CHFeTrust-Vet
Mal/Generic-LSophos
TR/Spy.36864.105AntiVir
Win32.HLLW.Autoruner.44501DrWeb
Gen.Trojan.Heur!IKN/A
Gen:Trojan.Heur.RP.cmW@augrWmbGBitDefender
Trojan.Win32.Pincav.axriKaspersky
Trojan.Pincav-86ClamAV
Win32.GenHeur.RP.CmweSafe
TROJ_LAMEWAR.VTGN/A
W32/Kolab.KKN/A
Win32/AutoRun.KSNOD32
Trojan.Pincav!wNZ8c82Vph8N/A
RiskwareK7AntiVirus
Artemis!CAB27BA7842BMcAfee
Trojan.Pincav.axriCAT-QuickHeal
Trojan.Win32.Generic.12778E2DN/A
High Risk Cloaked MalwareN/A
TR/Agent.53248.EGAntiVir
Trojan.Packed.21395DrWeb
Heur.SuspiciousComodo
Gen:Trojan.Heur.RP.dmW@aGX0tlhGBitDefender
Packed.Win32.Krap.igKaspersky
a variant of Win32/Injector.EOENOD32
Trj/Downloader.MDWPanda
BHO.GDMAVG
W32/Chepdu.SC!trFortinet
Trojan.Win32.ChepduIkarus
Trojan.Win32.Generic!BTSunbelt
Win32.BHO.NJGN/A
Trojan:Win32/Chepdu.BMicrosoft
Downloader.TrojanSymantec
Trojan/Win32.BHO.genAntiy-AVL
Heur:Trojan/BHON/A
Mal/BHO-QSophos
Trojan.BHO.172032McAfee-GW-Edition
TROJ_GEN.0Z0802TrendMicro
TR/BHO.172032AntiVir
Trojan.BhoSiggen.678DrWeb
Trojan.Generic.876032BitDefender
Trojan.Win32.BHO.puvKaspersky
Trojan.BHO-4562ClamAV
Win32:Trojan-genAvast
W32/BHO.MOSN/A
Trojan.Win32.Chepdu!IKa-squared
W32/BadBHO.J.gen!EldoradoF-Prot
Win32/BHO.NJGNOD32
Trojan.Chepdu.PN/A
Trojan.Win32.Malware.1K7AntiVirus
Trojan.Chepdu.bCAT-QuickHeal
Trojan/W32.Agent.167936.AKN/A
Generic.dxMcAfee+Artemis

Program:Win32/Pameseg.U Description

Nircmd Sophos

ProgramWin32Pameseg.U is a hazardous ransomware which wants affected PC users to purchase some software programs that are freely available on the Internet. Surviving mars: deluxe upgrade pack for mac. ProgramWin32Pameseg.U asks computer users to send SMS messages to premium numbers for a successful installation of some software products. ProgramWin32Pameseg.U comes bundled with some software installation tools. When ProgramWin32Pameseg.U enters the corrupted PC system, it displays pop-up alerts and interfaces of a foreign language, which informs the computer user that he/she should send an SMS message to a predefined number. After the infected computer user sends the SMS, he/she gets an activation code to activate any one of certain software products. The activation codes ProgramWin32Pameseg.U gives after the PC user sends the SMS to the premium number are falsified, and all of the software applications ProgramWin32Pameseg.U claims to be able to activate are freeware programs. Do not pay for a so-called activation of any of offered applications. ProgramWin32Pameseg.U also downloads and installs other malware infections to the corrupted machine. Remove ProgramWin32Pameseg.U as quickly as possible. Battlevoid: sector siege ost for mac.

Aliases: Hoax.Win32.ArchSMS!IK, Win32/Hoax.ArchSMS.KC [NOD32], SMSFraud.d [McAfee], Trojan.Win32.Generic.1287A426, Hoax/Win32.ArchSMS [Antiy-AVL], Joke/ArchSMS.hsgx.157 [AntiVir], NSIS:SMSSend-U [Avast], NSIS/Hoax.ArchSMS.G.Gen [NOD32], Artemis!F6613DC2E074 [McAfee], Trojan/Agent.dwsp, NirCmd [Sophos], PUA.Tool.Nirsofer.NirCmd [ClamAV], Artemis!03E4F116988E [McAfee], Hoax.Win32.ArchSMS [Ikarus] and Program:Win32/Pameseg.U [Microsoft].

Technical Information

File System Details

Program:Win32/Pameseg.U creates the following file(s):
#File NameSizeMD5Detection Count
1 D:messenger-b.exe 638,000 f6613dc2e0740d249a35b896acc2c46b 17
2 %USERPROFILE%Mis documentosto??oMessenger9.0.exe 3,064,879 6d7e702c602c5f89e4afd1ea13769a8e 3
3 %USERPROFILE%DesktopComboFix.exe 4,327,458 03e4f116988e0c156246ff953c66993e 2
4 E:Softwaremessenger.exe 637,848 97b8f379b3eb62db59dce579fdd0af22 1
5 ComboFix.exe N/A

Nircmd Sophos

Site Disclaimer

Sophos Nircmd.exe

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.
This article is provided 'as is' and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.