How to Remove “NirCmd.exe”

What is NIRCMD.exe?

NIRCMD.exe is a legitimate process file popularly known as NirCmd. It is associated with Nirmd by NirSoft. It is located in C:\Program files by default.

Malware programmers write virus files with malicious scripts and save them as NIRCMD.exe with an intention to spread virus on the internet.

Affected Platforms: Windows OS

How to determine if your computer is infected with NIRCMD.exe malware?

Look out for the these symptoms to check if your PC is infected with NIRCMD.exe malware:

  • Unstable internet connection
  • NIRCMD.exe occupies extra CPU space
  • PC processing speed slows down
  • Browser often redirects to irrelevant websites
  • Browser is bombarded with hordes of popup ads
  • Computer screen freezes repeatedly

Take the following steps to diagnose your PC for possible NIRCMD.exe malware attack:

Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.

Step 2: If you notice the file located outside C:\Program files perform an antivirus scan to get rid of the malware.

How to remove NIRCMD.exe malware from system using Comodo Antivirus?

Step 1: Download our award-winning Free Antivirus

Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.

Step 3: Select Customize Configuration option and arrange installers, configuration, and file location.

Step 4: Restart your PC after the installation gets over

Step 5: Wait for Comodo Internet Security to update the software for virus protection.

Step 6: Proceed with the quick scan that automatically begins after the update.

Step 7: If threats are found during the scanning, you will be notified through an alert screen.

Step 8: Comodo Antivirus will remove NIRCMD.exe malware from your computer including all other malwares!

Windows OS PC Security Softwares: 

11

Malware Entries

First Seen: 26 November 2011 at 8:57 am
No. Company File Type SHA1 MD5 Malware
Name
Digitally
Signed
File
Version
Product
Version
Submitted
From
Malware Behavior
1 NirSoft Executable 83a5992d191ce863
ff6da43493e5f84f
73e45544
452dab9ad01c10ac
f4f711659cb27c37
Virus.Win32.
Ramnit.K
No 2.46 2.46 156.209.101.58/32 N/A
2 NirSoft Executable 2de7f26f6e084b8e
5a61602c0a2c73dc
3cf83794
f8bf997c12aa28ec
fe957088baa57579
Virus.Win32.
Sality.gen
No 1.85 1.85 Brazil N/A
3 NirSoft Executable 4e9e5753e9adb8ad
503b016534753a41
f68b6a30
6a00c12491cb8da8
721c4e916e250e08
Packed.Win32
.MUPX.Gen
No 2.81 2.81 10.224.25.40/32 N/A
4 NirSoft Executable 5506afbaa7d2f286
5124f046ac1170f8
21b0a30c
8eaf0e1fff28237e
69e676d8aff93f4f
Packed.Win32
.MUPX.Gen
No 2.51 2.51 Ukraine N/A
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
34

Safe Entries

First Seen: 03 July 2008 at 12:21 pm
No. Company File Type SHA1 MD5 Digitally
Signed
File
Version
Product
Version
Submitted
From
1 NirSoft Executable 466cf02efdd7c1e6
086c95ab4b792cd4
44024da3
80cce4afc880cde9
f75dc4e8b497da80
No 2.75 2.75 10.108.51.116/32
2 NirSoft Executable 04bf7acc7d0aa74f
a750f7c32fdebbbe
1daf46f8
b417238213efb0d2
a23562674406cdf9
No 2.81 2.81 10.108.22.205/32
3 NirSoft Executable b4e8ff898639edfd
7ca94405beba7a91
824bab79
dd7686c33351e9b8
e67d6aa6b4352b73
No 2.65 2.65 10.224.1.62/32
4 NirSoft Executable 466cf02efdd7c1e6
086c95ab4b792cd4
44024da3
80cce4afc880cde9
f75dc4e8b497da80
No 2.75 2.75 10.108.51.216/32
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
 
Exclusive Offer
Get Free Endpoint Protection
Get Advanced
Endpoint
Protection

Award-Winning Security to Protect Your Clients from Cyber Attacks

Comodo Internet Security Pro

Antivirus Protection protection from hackers! Get the ultimate Antivirus solution to keep your PC clean and to remove viruses from a slow or infected PC. Improve the PC performance at home or use it on-the-go!

Get Comodo Internet Security Comodo Internet Security