Need Help CMD pops up and starts file transfer.

Discussion in 'Apps - Questions & Help' started by quick maffs, Dec 27, 2017.

  1. quick maffs

    quick maffs Level 1

    Dec 27, 2017
    6
    7
    Jakarta
    Windows 7
    Malwarebytes
    #1 quick maffs, Dec 27, 2017
    Last edited: Dec 28, 2017
    Date of initial issues:
    12/15/2017
    Steps taken to resolve, but unsuccessful?:
    I ran a full-scan on Baidu Antivirus and also ran a threat scan on Malwarebytes but it's been unsuccesful.
    Operating System:
    Windows 7
    List current issues or symptoms:
    File Transfer?
    OS Architecture:
    64-bit
    It haven't caused any damage or anything whatsoever (That I know of) but it really made me concerned about this because it would happen on a daily basis, usually when I turn on my computer.

    I managed to obtain a screenshot of the process when I was trying to play Morrowind.

    EDIT: It seems that it is scheduled for when it runs... one of the time is 9:53 PM. Thanks for helping for those who tried to help.
     

    Attached Files:

  2. Slyguy

    Slyguy Level 21

    Jan 27, 2017
    1,090
    4,371
    Fortinet Engineer
    USA
    Other OS
    #2 Slyguy, Dec 27, 2017
    Last edited: Dec 27, 2017
    1) Is it a legit or cracked copy of the game?
    2) Do you have any mods installed? Sometimes mods update themselves.
    3) Have you run netstat -a and see open connections, then the IP where it is going?

    Also the fact it says 'zYBveIJK' causes concern. Our MSP sees a lot of malware use random letters for payloads, directories and file names. If it is a cracked version all bets are off. I strongly discourage pirated software not so much out of principle, but because so much of it is backdoored/compromised.
     
  3. AtlBo

    AtlBo Level 22

    Dec 29, 2014
    1,144
    4,513
    Qihoo 360
    AUTORUNS might help you see what this is to some extent. It's not so easy to set up, but you might consider installing NVT ERP. It will help you get a look at the exact command line that is spawing the cmd prompt. You will likely then also know what file is spawning it or if it is started by a scheduled task or runonce, etc.
     
    Marko :), tim one, shmu26 and 7 others like this.
  4. Vasudev

    Vasudev Level 22

    Nov 8, 2014
    1,109
    2,185
    Student
    India
    Windows 10
    Microsoft
    I think its a copying your docs to some networked PC and will lock out your PC in a few days. Best option is to run LiveCD AVs from Dr. Web, Kaspersky or ESET to clean up malware outside of windows environment.
     
  5. harlan4096

    harlan4096 Moderator
    Staff Member AV Tester

    Apr 28, 2015
    2,622
    20,663
    Almería (Spain)
    Windows 10
    Kaspersky
  6. Syafiq

    Syafiq Level 7

    May 8, 2017
    330
    2,134
    Student
    Indonesia
    Windows 10
    Emsisoft
    Marko :), tim one, Vasudev and 4 others like this.
  7. quick maffs

    quick maffs Level 1

    Dec 27, 2017
    6
    7
    Jakarta
    Windows 7
    Malwarebytes
    1) It's a cracked version that I got from a friend just yesterday when I took the screenshot. But the problem has been going on since 3 days ago.
    2) Yes, I have a couple of mods installed that I managed to set up by myself, but I don't think any of them can update themselves since well... I made them.
    3) I ran a netstat -a operation just now, but since I'm not too knowledgeable in CMD's... I can't really tell...

    But I thought CMD Pops up are discussed here.
     
  8. quick maffs

    quick maffs Level 1

    Dec 27, 2017
    6
    7
    Jakarta
    Windows 7
    Malwarebytes
    Oh since that's the case... I gotta delete Morrowind then ;-;
     
    Syafiq likes this.
  9. tim one

    tim one Level 18
    Trusted AV Tester

    Jul 31, 2014
    896
    9,022
    Europe
    Windows 10
    Emsisoft
    If your game copy is legit then the cmd message may be related to some module (updates, game levels saving, etc).
    If you are instead using a cracked copy then it is definitely better to get rid of the game and asking for assistance in the MRA forum as said above.
     
  10. quick maffs

    quick maffs Level 1

    Dec 27, 2017
    6
    7
    Jakarta
    Windows 7
    Malwarebytes
    Yes, I've rid the game from my computer. But I don't think my cracked copy of Morrowind is the cause of the problem since I just got Morrowind yesterday and the issue's been going on for 2+ days.
     
    Syafiq likes this.
  11. Slyguy

    Slyguy Level 21

    Jan 27, 2017
    1,090
    4,371
    Fortinet Engineer
    USA
    Other OS
    It's stunning to me that someone would use a cracked Morrowind when it sells for around $7 on Steam. I spent that on coffee this morning already.
     
    quick maffs and Syafiq like this.
  12. quick maffs

    quick maffs Level 1

    Dec 27, 2017
    6
    7
    Jakarta
    Windows 7
    Malwarebytes
    xD Well... I'm not a fan of The Elder Scroll series and I didn't know the price. My friend just gave it to me yesterday.
     
  13. Telos

    Telos Level 8

    Jan 29, 2017
    377
    991
    Baana
    Check Task Scheduler for run history and see what matches up with the CMD window appearance. As others have mentioned, Autoruns can help here too (and don't forget looking in msconfig).
     
    AtlBo likes this.
  14. Syafiq

    Syafiq Level 7

    May 8, 2017
    330
    2,134
    Student
    Indonesia
    Windows 10
    Emsisoft
    @quick maffs I noticed that you removed your Morrowind game, do you still experiencing cmd popups appear and then disappear ?
     
    AtlBo likes this.
  15. quick maffs

    quick maffs Level 1

    Dec 27, 2017
    6
    7
    Jakarta
    Windows 7
    Malwarebytes
    unfortunately, yes.
     
    AtlBo likes this.
  16. Syafiq

    Syafiq Level 7

    May 8, 2017
    330
    2,134
    Student
    Indonesia
    Windows 10
    Emsisoft
    #16 Syafiq, Dec 29, 2017
    Last edited: Dec 29, 2017
    Do you see any strange process running in the task manager, please provide us a screenshot. :)
    If you have found any strange process and it's malicious, then go to the Malware Removal Assistance For Windows and start posting. @TwinHeadedEagle will help you in that case :)
     
    AtlBo likes this.
Loading...
Similar Threads Forum Date
Cmd pops up every 2 hours and tries to download malware Malware Removal Assistance For Windows Nov 18, 2017
Cmd pops up every 3 hours and tries to download malware Malware Removal Assistance For Windows Nov 17, 2017
Need Help CMD prompt "Not sandboxed" pops us randomly and disappears Apps - Questions & Help Sep 26, 2017