Command Prompt-what Does This Mean??

Discussion in 'Software' started by jek1862, Nov 6, 2017.

  1. jek1862

    jek1862 Private E-2

    In this post, I am going to concentrate on one issue I have suspected was associated with a hacker from the beginning. And more so as time has gone by. It involves my command prompt box. Ever since all this suspicious behavior started on my machine, my command prompt box would come up at random times for about one second, no longer. Sometimes there is writing in the box, sometimes not. Because it goes by so fast have been unable to do a print screen. However, tonight I got lucky. I FINALLY got the screen printed and transferred it to my Paint. The box comes up daily, usually two or three times, as I said at very random times as I have kept records. Unfortunately, on the one I finally caught tonight, there was nothing in the box, but there was some writing across the border on the top. I am going to print here all it said, as I have NO IDEA what it means or may mean. I am hoping someone here may be able to look at this and give me some ideas about it or any information would help. Here is what it said: Select C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\installutil.exe
    If you know what that means or even part of it, or have some ideas or theories I would really like to hear them, as I cannot make heads or tails of any of it. It certainly looks "wrong".I do not activate the command prompt box EVER, it just comes up. I have read many things in the search engines that can possibly account for the command prompt box coming up, but have found nothing that relates to my situation. I have seen a few say they were worried it might indicate hacker or malicious activity, like maybe trying to "connect" and other various theories. Understand I NEVER had anything like this happen until all my "problems" began about 2 months ago. Thank you for any and all help.(Please don't ask me to run any scans because I have already done all that and there is no further need. I am POSITIVE a hacker is on my network, I do not need any more scans to convince me of that. I just want some help with this problem I am describing, PLEASE)
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this an HP machine? Perhaps you should try installing Net 4.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  4. MaxTurner

    MaxTurner Banned

    You have been advised at least a couple of times already in other threads to have your system tested for Malware by the trained experts here.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    YCLAHTW, BYCMHD!!
     
  6. MaxTurner

    MaxTurner Banned

    You haven't run anything. In three threads you have been advised to carry out specific steps so that a Trained Malware Expert (you are not anything remotely comparable) can analyse your system and you have refused.
    Don't expect help if you refuse to carry out steps needed.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you've run all the scans, then please attach them and I will move this thread back to the malware forum.
     
  8. Ewen

    Ewen Corporal

    TimW I can appreciate you writing full sentences in initial form but I can never remember what they mean and non English readers will be thoroughly baffled!
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You can lead a horse to water, but you can't make him drink! ;)
     
  10. AtlBo

    AtlBo Major Geek Extraordinaire

    Anyone who would like to see the command lines being used on a system, I recommend this program:

    http://downloads.novirusthanks.org/files/EXERadar_Pro_x86_x64_v3.1_15052015_BUILD1.exe

    In the case of this user, add installutil.exe to the list of vulnerable processes in the settings. I have put together a vulnerables list from various sources around the internet, and this is very effective monitoring (and security blocking also). The default list is decent and covers normal command line, but the appended list would also detect any command-line request made by the installutil.exe utility itself in case it ever became hijacked (and many other potential weak points in Windows). The list can be seen in the attached picture, but be warned it takes an hour or better to add them all. If you know how to use wildcards, NVT ERP does support wildcard editing of safe command lines (recorded in the Whitelist->Command lines area) in case you run into something, normal or nasty, that appears/reappears constanly under a random name. Best command-line monitoring program I have seen.

    NVT More Vulnerables All Others.png

    I have also added pics of the settings I use in a zip folder. They work very well. Install NVT ERP and let it run for about 20-30 minutes on a clean system. Then make the settings changes. NVT will detect many of the clean Windows processes during the initial run period and exempt them from monitoring other than command line monitoring. Then you will get tight protection for the undetected ones beyond that point with the settings.
     

    Attached Files:

    Last edited: Nov 13, 2017

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds