Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 7.04%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.47%
6.2.9200.16384 (win8_rtm.120725-1247) 17.37%
6.2.9200.16384 (win8_rtm.120725-1247) 1.88%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 17.84%
6.1.7601.17514 (win7sp1_rtm.101119-1850) 37.09%
6.1.7600.16385 (win7_rtm.090713-1255) 3.29%
6.1.7600.16385 (win7_rtm.090713-1255) 2.82%
6.0.6000.16386 (vista_rtm.061101-2205) 7.51%
6.0.6000.16386 (vista_rtm.061101-2205) 0.47%
5.1.2600.5512 (xpsp.080413-2111) 4.23%


Parent process
Child process
RevertToSelf, SaferRecordEventLogEntry, ImpersonateLoggedOnUser, SaferCloseLevel, SaferComputeTokenFromLevel, SaferIdentifyLevel, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegEnumKeyW, RegDeleteValueW, RegOpenKeyW, RegDeleteKeyW, RegSetValueW, CreateProcessAsUserW, RegSetValueExW, RegCreateKeyExW, LookupAccountSidW, GetSecurityDescriptorOwner, GetFileSecurityW
FlushConsoleInputBuffer, LoadLibraryA, InterlockedExchange, FreeLibrary, LocalAlloc, GetVDMCurrentDirectories, CmdBatNotification, GetModuleHandleA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetThreadLocale, GetDiskFreeSpaceExW, CompareFileTime, RemoveDirectoryW, GetCurrentDirectoryW, SetCurrentDirectoryW, TerminateProcess, WaitForSingleObject, GetExitCodeProcess, CopyFileW, SetFileAttributesW, DeleteFileW, SetFileTime, CreateDirectoryW, FillConsoleOutputAttribute, SetConsoleTextAttribute, ScrollConsoleScreenBufferW, FormatMessageW, DuplicateHandle, FlushFileBuffers, HeapReAlloc, HeapSize, GetFileAttributesExW, LocalFree, GetDriveTypeW, InitializeCriticalSection, SetConsoleCtrlHandler, GetWindowsDirectoryW, GetConsoleTitleW, GetModuleFileNameW, GetVersion, EnterCriticalSection, LeaveCriticalSection, ExpandEnvironmentStringsW, SearchPathW, WriteFile, GetVolumeInformationW, SetLastError, MoveFileW, SetConsoleTitleW, MoveFileExW, GetBinaryTypeW, GetFileAttributesW, GetCurrentThreadId, CreateProcessW, LoadLibraryW, ReadProcessMemory, SetErrorMode, GetConsoleMode, SetConsoleMode, VirtualAlloc, VirtualFree, SetEnvironmentVariableW, GetEnvironmentVariableW, GetCommandLineW, GetEnvironmentStringsW, GetLocalTime, GetTimeFormatW, FileTimeToLocalFileTime, GetDateFormatW, GetLastError, CloseHandle, SetThreadLocale, GetProcAddress, GetModuleHandleW, SetFilePointer, lstrcmpW, lstrcmpiW, HeapAlloc, GetProcessHeap, HeapFree, MultiByteToWideChar, ReadFile, WriteConsoleW, FillConsoleOutputCharacterW, SetConsoleCursorPosition, ReadConsoleW, GetConsoleScreenBufferInfo, GetStdHandle, GetFileType, VirtualQuery, RaiseException, GetCPInfo, GetConsoleOutputCP, WideCharToMultiByte, GetFileSize, CreateFileW, FindClose, FindNextFileW, FindFirstFileW, GetFullPathNameW, GetUserDefaultLCID, GetLocaleInfoW, SetLocalTime, SystemTimeToFileTime, GetSystemTime, FileTimeToSystemTime, FreeEnvironmentStringsW, SetEnvironmentStringsW, GetConsoleWindow, GetStartupInfoW, DeleteProcThreadAttributeList, UpdateProcThreadAttribute, InitializeProcThreadAttributeList, NeedCurrentDirectoryForExePathW, SetFilePointerEx, CancelSynchronousIo, HeapSetInformation, OpenThread, SetEndOfFile, FindNextStreamW, FindFirstStreamW, DeviceIoControl, ResumeThread, SetProcessAffinityMask, GetSystemInfo, GetVolumePathNameW, CreateSymbolicLinkW, CreateHardLinkW, InterlockedCompareExchange, Sleep, LoadLibraryExA, DelayLoadFailureHook, GetThreadGroupAffinity, GetNumaNodeProcessorMaskEx, FindFirstFileExW, GetACP, GlobalAlloc, GlobalFree, GetNumaHighestNodeNumber, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegDeleteValueW, RegDeleteKeyExW, QueryFullProcessImageNameW, RegSetValueExW, RegCreateKeyExW
RtlDosPathNameToNtPathName_U, NtFsControlFile, RtlFreeHeap, NtQueryInformationProcess, NtSetInformationProcess, RtlNtStatusToDosError, NtQueryInformationToken, NtClose, NtOpenProcessToken, NtOpenThreadToken, RtlFindLeastSignificantBit
GetUserObjectInformationW, GetThreadDesktop, MessageBeep, GetProcessWindowStation


Windows Command Processor by Microsoft

Version:   5.1.2600.5512 (xpsp.080413-2111)
MD5:   6d778e0f95447e6546553eeea709d03c
SHA1:   811a005cf787c6ccbe0d9f1c36c1d49a9cb71fd1
SHA256:   62abed7d45040381bbced97ea7b6c697b418448fd3322fd4bfb2bbfdb6155eb4
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is cmd.exe?

Command processor in windows is the command prompt(cmd).
To start Windows command processor use winkey + R this will open Run window.Just type in cmd and this will open command prompt of windows where you can run various commands.You can create,delete files and folders, list the directory contents and can perform many other functions in command prompt.


cmd.exe executes as a process with the local user's privileges typically within the context of its parent BunndleOfferManager.dll (Bunndle Offer Manager by Bunndle). It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). It is installed with a couple of know programs including Sophos AutoUpdate published by Sophos Limited, NVIDIA Drivers from NVIDIA Corporation and NVIDIA Drivers by NVIDIA Corporation. This version is installed on Windows XP and is compiled as a 32 bit program.


File name:cmd.exe
Publisher:Microsoft Corporation
Product name:Windows Command Processor
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\cmd.exe
Original name:Cmd.Exe.MUI
File version:5.1.2600.5512 (xpsp.080413-2111)
Product version:5.1.2600.5512
Size:380 KB (389,120 bytes)
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C++
More details


The following programs will install this file
authorGEN Technologies Private Limited
6% remove
8% remove
NVIDIA Corporation
2% remove
The NVIDIA Driver is the software driver for NVIDIA Graphics GPU installed on the PC. It is a program used to communicate from the Windows PC OS to the device. This software is required in most cases for the hardware device to function properly. In most cases, drivers come with Windows or can be found by going to Windows Update in Control Panel and checking for updates as well as downloaded from the NVIDIA support website.
Sophos Limited
4% remove
Sophos AutoUpdate is the updater program which runs with Windows (in the background as a service) and automatically starts up when your computer boots. It checks for updates and automatically downloads and installs them if found based on the user's settings. This is the AutoUpdate service, run as 'System User'.When the service first starts up it performs an update check to the CID.ALSvc.exe runs a scheduler that triggers scheduled updat...


Startup files (all users) run once
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce'
  • 'FastFoxUninstall5' → cmd.exe /C rmdir /Q "C:\users\user\appdata\Roaming\NCH Software"
  • 'FastFoxUninstall4' → cmd.exe /C rmdir /Q "C:\users\user\appdata\Roaming\NCH Software\Program Files"
  • 'FastFoxUninstall3' → cmd.exe /C rmdir /S /Q "C:\users\user\appdata\Roaming\NCH Software\Program Files\FastFox"
  • 'FastFoxUninstall2' → cmd.exe /C rmdir /Q "C:\Program Files\NCH Software\FastFox"
  • 'FastFoxUninstall' → cmd.exe /C rmdir /S /Q "C:\Program Files\NCH Software\FastFox"
  • 'DelTr4467046' → cmd.exe /c rd /s /q "C:\users\user\appdata\Roaming\mysearchdial"
  • 'Del1639781' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Del125888062' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Del95943703' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Del32322796' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Del160256437' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Del43786750' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Del43774332' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Del1203196625' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Del94878045' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Del326931' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Del136013075' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'removeiMeshdatamngr' → cmd.exe /c RD /S /Q "C:\Program Files\Search Results Toolbar"
  • 'Del52821423' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'removeiLividdatamngr' → cmd.exe /c RD /S /Q "C:\Program Files\Search Results Toolbar"
  • 'Del153953127' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'removeSearchqutoolbar' → cmd.exe /c RD /S /Q "C:\Program Files\Searchqu Toolbar\Datamngr\ToolBar"
Startup files (user) run once
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce'
  • 'Uninstall C:\Users\Adilson\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.4029.0217\amd64"
  • 'Uninstall C:\Users\StoneyBC\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64"
  • 'Uninstall C:\Users\StoneyBC\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64"
  • 'DelTr4467046' → cmd.exe /c rd /s /q "C:\users\user\appdata\Roaming\mysearchdial"
  • 'Del1639781' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Uninstall C:\Users\Brandon\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
  • 'Uninstall C:\Users\Brandon\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64"
  • 'Uninstall C:\Users\Татьяна\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
  • 'Del32322796' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Uninstall C:\Users\centrogum\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
  • 'Del43786750' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Del43774332' → cmd.exe /Q /D /c del "C:\users\user\appdata\Local\Temp\0.del"
  • 'Uninstall C:\Users\Janine\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530_1\amd64' → C:\Windows\System32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.2010.0530_1\amd64"
  • 'Uninstall C:\Users\prettymomma\AppData\Local\Microsoft\SkyDrive\16.4.6012.0828\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\16.4.6012.0828\amd64"
  • 'Uninstall C:\Users\Angela Doran\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.2011.0627"
  • 'Uninstall C:\Users\Angela Doran\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.2011.0627\amd64"
  • 'Uninstall C:\Users\Angela Doran\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.2010.0530"
  • 'Uninstall C:\Users\Angela Doran\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.2010.0530\amd64"
  • 'Uninstall C:\Users\Angela Doran\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314_5' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.2006.0314_5"
  • 'Uninstall C:\Users\Angela Doran\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314_5\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.2006.0314_5\amd64"
  • 'Uninstall C:\Users\Angela Doran\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112_5\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.2003.1112_5\amd64"
  • 'Uninstall C:\Users\Eric Feller\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64' → C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\users\user\appdata\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64"
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'CMD' → cmd.exe /k if %datC:~6,4%%datC:~3,2%%datC:~0,2% LEQ 20130909 (exit) else (start httC:// && exit)
  • 'Adobe Flash Player SU' → C:\Windows\System32\cmd.exe /k start httC:// && exit
  • 'AMD AVT' → Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'Bomgar_Cleanup_ZD12543155818005' → cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-au" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD12543155818005 /f
Scheduled tasks
  • The job 'BoostApp' runs in the path '\BoostApp'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Total CPU:0.00037487%
Kernel CPU:0.00022683%
User CPU:0.00014804%
Kernel CPU time:322 ms/min
Private memory:2.01 MB
21.59 MB
Private (maximum):2.18 MB
Private (minimum):1.63 MB
Non-paged memory:2.01 MB
21.59 MB
Virtual memory:29.75 MB
140.96 MB
Virtual memory (peak):36.22 MB
169.69 MB
Working set:1.7 MB
18.61 MB
Working set (peak):2.75 MB
37.95 MB
Page faults:821/min
I/O read transfer:24 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
I/O write transfer:735 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
I/O other transfer:122 Bytes/sec
448.09 KB/min
I/O other operations:2/sec
Resource allocations
GUI GDI count:5
GUI USER count:1

BehaviorsProcess properties

Integrety level:Undefined
Command lines:
  • "C:\Windows\System32\cmd.exe"
  • "C:\Windows\System32\cmd.exe" /c set /p x= & del /f /s "C:\DOCUME~1\user\Locals~1\temp\bunndle\bunndl~1.dll"
Parent processes:

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 33.00%
Windows 7 Ultimate 17.00%
Windows 8 Pro 9.50%
Windows 7 Professional 6.00%
Windows 8 5.50%
Windows Vista Home Premium 5.00%
Windows 7 Home Basic 4.50%
Windows 8.1 4.50%
Microsoft Windows XP 4.00%
Windows 8 Pro with Media Center 2.50%
Windows 8.1 Pro 1.50%
Windows 7 Ultimate N 1.50%
Windows 7 Starter 1.00%
Windows Vista Home Basic 1.00%
Windows 8.1 Single Language 0.50%
Windows 8.1 Enterprise Evaluation 0.50%
Windows 8.1 Pro with Media Center 0.50%
Windows Vista Ultimate 0.50%
Windows 8.1 Pro Preview with Media Center 0.50%
Windows 8 Pro N 0.50%
Windows 8 Enterprise N 0.50%
21 other Windows OS version

Distribution by countryDistribution by country

United States installs about 49.75% of Windows Command Processor.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 26.84%
Dell 18.95%
Toshiba 13.68%
ASUS 11.58%
Acer 7.89%
Lenovo 7.37%
Samsung 3.68%
Sony 3.16%
Gateway 1.05%
Intel 1.05%
Compaq 1.05%
