File details
File name: cmd.exe
Name: Sistema operativo Microsoft® Windows®
Description: Procesador de comandos de Windows
Version: 6.2.9200.16384 (win8_rtm.120725-1247)
Product version: 6.2.9200.16384
Size: 341.5 KB
Original file name: Cmd.Exe.MUI
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0022838237%
Privileged CPU:
0.0015883223%

User CPU:
0.00069550141656%

Privileged CPU time: 150.81 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
343,262,471
CPU cycle count /min: 558,788
 | Memory utilization averages |
Committed memory:
15.04 MB
Peak committed memory: 17.49 MB
Paged memory:
1.61 MB
Peak paged memory: 1.98 MB
Paged system memory:
28.81 KB
Non-paged system memory: 3.45 KB
Working set memory:
2.68 MB
Peak working set memory: 2.78 MB
Min working set memory: 2.65 MB
Private memory:
1.61 MB
Page faults:
990
Page faults /min: 1
 | Process I/O averages |
Total read operations:
28
Read operations /min: 1
Total read transfer: 1.05 MB
Read transfer /min: 3.74 KB
Total other operations:
568
Other operations /min: 1
Total other transfer: 17.14 KB
Other Transfer /min: 4 Bytes
Resources
Handle count average: 23
Thread count average: 1
Thread resource averages
Total CPU: 0.000415502814%
Privileged CPU: 0.000401624698%
User CPU: 0.000013878116%
CPU Cycle count /sec: 123,619
Module memory size: 356 KB
Process details
Runs as (owner): User
Integrety level: High
Windows platform: 32-bit
Parent Processes
Child Process
Process Commands
cmd.exe /c ""C:\users\user\appdata\Local\Temp\81280GUN.bat" "C:\users\user\appdata\Local\Temp\Rar$EXa0.250\DmC Devil May Cry [www.BaziKids.com]\Setup.exe" "
cmd /c ""C:\users\user\appdata\Roaming\ActiveWords 2.0\BatchOptimize.bat" "
"C:\Windows\system32\cmd.exe" /c set /p x= & del /f /s "C:\users\user\appdata\Local\Temp\Bunndle\BUNNDL~1.DLL" & rd /s /q "C:\users\user\appdata\Local\Temp\Bunndle"
Startup files (user) run once details
Name: Uninstall C:\Users\Juan Paulo Castro\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112
Command: C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.2003.1112"
Image hashes
MD5: 5996c79fb52bde3fa10f77396654ae42
SHA-1: ac4d87e771010698cdc82116f289abfcf7d67027
SHA-256: 910d521315b83bb0d805eaceac3c83169aa791d1d1e64b417077c01ae21feb66
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++
File packed: No
Import Table
api-ms-win-core-apiquery-l1-1-0.dll

ApiSetQueryApiSetPresence
api-ms-win-core-console-l1-1-0.dll

GetConsoleMode
SetConsoleMode
GetConsoleOutputCP
SetConsoleCtrlHandler
ReadConsoleW
WriteConsoleW
api-ms-win-core-console-l2-1-0.dll

SetConsoleTitleW
FillConsoleOutputCharacterW
SetConsoleCursorPosition
ScrollConsoleScreenBufferW
FillConsoleOutputAttribute
SetConsoleTextAttribute
GetConsoleScreenBufferInfo
FlushConsoleInputBuffer
GetConsoleTitleW
api-ms-win-core-datetime-l1-1-1.dll

GetDateFormatW
GetTimeFormatW
api-ms-win-core-delayload-l1-1-1.dll

DelayLoadFailureHook
ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-1.dll

UnhandledExceptionFilter
SetUnhandledExceptionFilter
SetLastError
SetErrorMode
GetLastError
api-ms-win-core-file-l1-2-0.dll

FindFirstFileExW
GetDiskFreeSpaceExW
GetFileSize
CompareFileTime
RemoveDirectoryW
SetFilePointer
GetFileAttributesW
CreateFileW
GetFullPathNameW
FindFirstFileW
SetFileTime
DeleteFileW
SetEndOfFile
SetFileAttributesW
CreateDirectoryW
FindNextFileW
GetFileType
FindClose
ReadFile
FlushFileBuffers
FileTimeToLocalFileTime
WriteFile
SetFilePointerEx
GetVolumeInformationW
GetVolumePathNameW
GetDriveTypeW
GetFileAttributesExW
api-ms-win-core-file-l2-1-0.dll

CreateSymbolicLinkW
CreateHardLinkW
MoveFileWithProgressW
MoveFileExW
GetFileInformationByHandleEx
api-ms-win-core-handle-l1-1-0.dll

CloseHandle
DuplicateHandle
api-ms-win-core-heap-l1-2-0.dll

GetProcessHeap
HeapFree
HeapAlloc
HeapSize
HeapReAlloc
HeapSetInformation
api-ms-win-core-heap-obsolete-l1-1-0.dll

GlobalFree
LocalFree
GlobalAlloc
api-ms-win-core-interlocked-l1-2-0.dll

InterlockedCompareExchange
InterlockedExchange
api-ms-win-core-io-l1-1-1.dll

api-ms-win-core-kernel32-legacy-l1-1-0.dll

api-ms-win-core-libraryloader-l1-1-1.dll

GetModuleFileNameW
GetModuleHandleA
LoadLibraryExW
GetProcAddress
GetModuleHandleW
api-ms-win-core-localization-l1-2-0.dll

GetThreadLocale
GetUserDefaultLCID
GetLocaleInfoW
SetThreadLocale
GetCPInfo
GetACP
FormatMessageW
api-ms-win-core-memory-l1-1-1.dll

VirtualFree
VirtualAlloc
ReadProcessMemory
VirtualQuery
api-ms-win-core-processenvironment-l1-2-0.dll

SearchPathW
ExpandEnvironmentStringsW
GetEnvironmentStringsW
SetEnvironmentVariableW
SetEnvironmentStringsW
GetStdHandle
SetCurrentDirectoryW
FreeEnvironmentStringsW
GetCurrentDirectoryW
GetCommandLineW
GetEnvironmentVariableW
NeedCurrentDirectoryForExePathW
api-ms-win-core-processthreads-l1-1-1.dll

InitializeProcThreadAttributeList
DeleteProcThreadAttributeList
GetStartupInfoW
CreateProcessAsUserW
CreateProcessW
GetCurrentProcessId
GetCurrentProcess
ResumeThread
GetExitCodeProcess
UpdateProcThreadAttribute
TerminateProcess
GetCurrentThreadId
OpenThread
api-ms-win-core-processtopology-l1-1-0.dll

api-ms-win-core-processtopology-obsolete-l1-1-0.dll

api-ms-win-core-profile-l1-1-0.dll

api-ms-win-core-registry-l1-1-0.dll

RegCreateKeyExW
RegSetValueExW
RegDeleteKeyExW
RegEnumKeyExW
RegQueryValueExW
RegDeleteValueW
RegOpenKeyExW
RegCloseKey
api-ms-win-core-string-l1-1-0.dll

MultiByteToWideChar
WideCharToMultiByte
api-ms-win-core-string-obsolete-l1-1-0.dll

api-ms-win-core-synch-l1-2-0.dll

ReleaseSRWLockShared
LeaveCriticalSection
ReleaseSRWLockExclusive
EnterCriticalSection
InitializeCriticalSection
TryAcquireSRWLockExclusive
WaitForSingleObject
AcquireSRWLockShared
Sleep
api-ms-win-core-sysinfo-l1-2-0.dll

GetSystemTime
SetLocalTime
GetLocalTime
GetWindowsDirectoryW
GetSystemTimeAsFileTime
GetTickCount
GetVersion
api-ms-win-core-systemtopology-l1-1-0.dll

GetNumaNodeProcessorMaskEx
GetNumaHighestNodeNumber
api-ms-win-core-timezone-l1-1-0.dll

FileTimeToSystemTime
SystemTimeToFileTime
api-ms-win-security-base-l1-2-0.dll

RevertToSelf
GetSecurityDescriptorOwner
GetFileSecurityW
msvcrt.dll
ntdll.dll

RtlFreeHeap
NtOpenThreadToken
NtClose
NtOpenProcessToken
NtQueryInformationToken
NtFsControlFile
RtlDosPathNameToNtPathName_U
RtlFindLeastSignificantBit
RtlFreeUnicodeString
RtlReleaseRelativeName
NtOpenFile
RtlDosPathNameToRelativeNtPathName_U_WithStatus
NtSetInformationFile
NtQueryVolumeInformationFile
NtSetInformationProcess
NtQueryInformationProcess
RtlNtStatusToDosError
NtCancelSynchronousIoFile
RtlCreateUnicodeStringFromAsciiz