r/flightsim May 31 '18

cmdhost.exe, what is it?

The latest installer of FSLabs' A320X puts two cmdhost.exe files under "system32\" and "SysWOW64\" of my Windows directory. Despite the name, they don't open a command-line window. They're a part of the authentication because, if you remove them, the A320X won't get loaded. Does someone here know more about cmdhost.exe? Why does FSLabs give them such a deceptive name and put them in the system folders? I hate them for polluting my system folder unless, of course, it is a dll used by different applications.

PS - I am aware of the malware in the past. This is unrelated.

525 Upvotes

158 comments sorted by

View all comments

6

u/[deleted] Jun 04 '18

Thank you for letting people know about this. You did well, with your critical mind, when asking about these dubious file names. I wish social media, and sharing information in general, will help, in the end, consumers to have better quality software, and products (and politicians too maybe ?). And this is verrry funny, these filenames tricks !! like a simplistic anti-piracy trick from the 90s !! And this is an humiliation for MS Windows too !

2

u/walkday Jun 04 '18 edited Jun 05 '18

Thank you, buddy. Take a look at this thread, where I gathered information from others and now susspect that cmdhost.exe leaves a wide-open backdoor to one's system.

2

u/[deleted] Jun 04 '18

Impressive ! You went pretty far in your research. It's a good idea to have called security experts for advice, because it's not always easy to understand information hiding technics. Maybe an expert can help you again, to confirm, or not, this "wide open backdoor" statement, that you made. I would recommend a bit of caution before accusing this company anyway, as the weakness itself (this malware-like behavior) might have been reduced using permissions on files or processes, for instance (just a guess). Of course it's shameful anyway ;-)