File details
File name: cmd.exe
Name: Windows Command Processor
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 336.5 KB
Original file name: Cmd.Exe.MUI
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000027009%
Privileged CPU:
0.0000013504%

User CPU:
0.00000135044778%

Privileged CPU time: 7.8 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
44,134,137
CPU cycle count /min: 39,437
 | Memory utilization averages |
Committed memory:
39.04 MB
Peak committed memory: 39.04 MB
Paged memory:
2.01 MB
Peak paged memory: 2.22 MB
Paged system memory:
79.31 KB
Non-paged system memory: 4.34 KB
Working set memory:
172 KB
Peak working set memory: 2.63 MB
Min working set memory: 144 KB
Private memory:
2.01 MB
Page faults:
1,006
Page faults /min: 2
 | Process I/O averages |
Total read operations:
8
Read operations /min: 1
Total read transfer: 1.34 MB
Read transfer /min: 303 Bytes
Total write operations:
21
Write operations /min: 1
Total write transfer: 1.24 MB
Write transfer /min: 282 Bytes
Total other operations:
262
Other operations /min: 1
Total other transfer: 2.52 KB
Other Transfer /min: 3 Bytes
 | GUI Object Averages |
GDI objects:
4
Peak GDI objects: 4
USER objects:
1
Peak USER objects: 1
Resources
Handle count average: 20
Thread count average: 1
Thread resource averages
Total CPU: 0.000011234430%
Privileged CPU: 0.000005617215%
User CPU: 0.000005617215%
CPU Cycle count /sec: 243
Module memory size: 352 KB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Parent Process
Process Command
"C:\Windows\System32\cmd.exe"
Startup files (all users) run once details
Name: Del1203196625
Command: cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
Startup files (user) run once details
Name: Uninstall C:\Users\James Toupin\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64
Command: C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64"
Startup files (all users) run details
Name: Adobe Flash Player SU
Command: C:\Windows\System32\cmd.exe /k start httC://3zz.info/ && exit
Startup files (user) run details
Name: Bomgar_Cleanup_ZD12543155818005
Command: cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-au" & reg delete HKCU\Software\Microsoft\Windows\ CurrentVersion\Run /v Bomgar_Cleanup_ZD12543155818005 /f
Scheduled task details
Name: BoostApp
Command: \BoostApp
Image hashes
MD5: 6960d29abe74341fab8300db3e6f883d
SHA-1: 4bbbd51de263b20d9553560f57b6eff526fcb55e
SHA-256: 8651e663d5effb9022046ab46452a102d1f31f5edb90ac87d8db023fe54b92f0
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++
File packed: No
Import Table
advapi32.dll

RevertToSelf
SaferRecordEventLogEntry
ImpersonateLoggedOnUser
SaferCloseLevel
SaferComputeTokenFromLevel
SaferIdentifyLevel
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
RegEnumKeyW
RegDeleteValueW
RegOpenKeyW
RegDeleteKeyW
RegSetValueW
CreateProcessAsUserW
RegSetValueExW
RegCreateKeyExW
LookupAccountSidW
GetSecurityDescriptorOwner
GetFileSecurityW
kernel32.dll

FlushConsoleInputBuffer
LoadLibraryA
InterlockedExchange
FreeLibrary
LocalAlloc
GetVDMCurrentDirectories
CmdBatNotification
GetModuleHandleA
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetCurrentProcess
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetThreadLocale
GetDiskFreeSpaceExW
CompareFileTime
RemoveDirectoryW
GetCurrentDirectoryW
SetCurrentDirectoryW
TerminateProcess
WaitForSingleObject
GetExitCodeProcess
CopyFileW
SetFileAttributesW
DeleteFileW
SetFileTime
CreateDirectoryW
FillConsoleOutputAttribute
SetConsoleTextAttribute
ScrollConsoleScreenBufferW
FormatMessageW
DuplicateHandle
FlushFileBuffers
HeapReAlloc
HeapSize
GetFileAttributesExW
LocalFree
GetDriveTypeW
InitializeCriticalSection
SetConsoleCtrlHandler
GetWindowsDirectoryW
GetConsoleTitleW
GetModuleFileNameW
GetVersion
EnterCriticalSection
LeaveCriticalSection
ExpandEnvironmentStringsW
SearchPathW
WriteFile
GetVolumeInformationW
SetLastError
MoveFileW
SetConsoleTitleW
MoveFileExW
GetBinaryTypeW
GetFileAttributesW
GetCurrentThreadId
CreateProcessW
LoadLibraryW
ReadProcessMemory
SetErrorMode
GetConsoleMode
SetConsoleMode
VirtualAlloc
VirtualFree
SetEnvironmentVariableW
GetEnvironmentVariableW
GetCommandLineW
GetEnvironmentStringsW
GetLocalTime
GetTimeFormatW
FileTimeToLocalFileTime
GetDateFormatW
GetLastError
CloseHandle
SetThreadLocale
GetProcAddress
GetModuleHandleW
SetFilePointer
lstrcmpW
lstrcmpiW
HeapAlloc
GetProcessHeap
HeapFree
MultiByteToWideChar
ReadFile
WriteConsoleW
FillConsoleOutputCharacterW
SetConsoleCursorPosition
ReadConsoleW
GetConsoleScreenBufferInfo
GetStdHandle
GetFileType
VirtualQuery
RaiseException
GetCPInfo
GetConsoleOutputCP
WideCharToMultiByte
GetFileSize
CreateFileW
FindClose
FindNextFileW
FindFirstFileW
GetFullPathNameW
GetUserDefaultLCID
GetLocaleInfoW
SetLocalTime
SystemTimeToFileTime
GetSystemTime
FileTimeToSystemTime
FreeEnvironmentStringsW
SetEnvironmentStringsW
GetConsoleWindow
GetStartupInfoW
DeleteProcThreadAttributeList
UpdateProcThreadAttribute
InitializeProcThreadAttributeList
NeedCurrentDirectoryForExePathW
SetFilePointerEx
CancelSynchronousIo
HeapSetInformation
OpenThread
SetEndOfFile
FindNextStreamW
FindFirstStreamW
DeviceIoControl
ResumeThread
SetProcessAffinityMask
GetSystemInfo
GetVolumePathNameW
CreateSymbolicLinkW
CreateHardLinkW
InterlockedCompareExchange
Sleep
LoadLibraryExA
DelayLoadFailureHook
GetThreadGroupAffinity
GetNumaNodeProcessorMaskEx
FindFirstFileExW
GetACP
GlobalAlloc
GlobalFree
GetNumaHighestNodeNumber
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
RegDeleteValueW
RegDeleteKeyExW
QueryFullProcessImageNameW
RegSetValueExW
RegCreateKeyExW
msvcrt.dll
ntdll.dll

RtlDosPathNameToNtPathName_U
NtFsControlFile
RtlFreeHeap
NtQueryInformationProcess
NtSetInformationProcess
RtlNtStatusToDosError
NtQueryInformationToken
NtClose
NtOpenProcessToken
NtOpenThreadToken
RtlFindLeastSignificantBit
user32.dll

GetUserObjectInformationW
GetThreadDesktop
MessageBeep
GetProcessWindowStation
winbrand.dll
