I have a problem with this popping up suddenly without warning or anything, then it will go back to wherever it came from. This has been happening for the last few months and I cannot figure out why in order to fix it. I am not entering anything at machine level when this happens.
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
system32/cmd.exe
Home » Forums » AskWoody support » Windows » Windows 10 » Questions: Win10 » system32/cmd.exe
- This topic has 9 replies, 5 voices, and was last updated 3 years, 8 months ago.
Tags: cmd.exe
Viewing 6 reply threadsAuthorReplies-
Alex5723
AskWoody Plus -
Rick Corbett
AskWoody MVPJuly 14, 2021 at 3:03 pm #2377732What you are seeing is the result of a process firing (from a scheduled task or registry Run key?) and, as a result, triggering cmd.exe… so why not use a tool that monitors processes?
Sysinternals/TechNet‘s small, free, portable Process Monitor (ProcMon) can be set to filter for cmd.exe firing and should show what triggered it.
1. Download and unzip ProcMon. (I save/unzip it to a C:\Support folder I’ve created to store portable utilities/tools.)
2. Create a new shortcut to procmon.exe and amend the shortcut’s properties so it uses Run as administrator (a) and uses a /NoConnect switch (b), as per the following screenshot:
(The latter is so ProcMon doesn’t start capturing events automatically when it’s run.)
3. Start ProcMon from the shortcut and accept the EULA. You only need to do this the first time you use it.
4. When the main ProcMon window appears, press CTRL+L to bring up the Filter dialog.
5. Change the top line (a) to match the screenshot below, then click on the Add button (b) then click on the OK button (c) to dismiss the dialog.
That’s your filter set which will watch for any event that triggers the command processor cmd.exe, i.e. any flashing CMD window you see.
6. Click the Filter menu and make sure Drop Filtered Events is enabled:
The reason for this that ProcMon captures ALL events by default to your device’s swapfile… and if you are capturing events for a while (e.g. looking for events which may only happen once every hour or two) then it’s easy to exhaust the swapfile.
7. Now that ProcMon has been configured, press CTRL+E to start capturing events (or click on the icon 3rd in from the left in the toolbar).
You can now minimise ProcMon whilst you continue using your device. If you spot a CMD window appearing then look at ProcMon to see if the event has been captured and shows the process which triggered it (in the second default column – Process Name). Once the event has been captured you can press CTRL+E again to stop capturing.
Hope this helps…
[IMPORTANT: I’m very aware that the latest version of ProcMon has “issues” (and uses different-looking toolbar icons… see Microsoft’s ProcMon support forum for more info.) but I think (hope?) the basic functionality of ProcMon hasn’t been compromised by any MS bod diddling about with such a long-standing and well-respected utility. However, after testing of the latest version – and disappointment – I have reverted back to an earlier version (v3.50) of ProcMon.]
2 users thanked author for this post.
-
SuzyQ777
AskWoody Plus -
Rick Corbett
AskWoody MVPJuly 15, 2021 at 7:45 pm #2377996Where can I get that older version 3.50 of Process Monitor
The only legitimate site I could find to download v3.50 is:
http://www.3dfxzone.it/programs/?objid=17070
I’ve just download the zip from there, unpacked it and checked the Procmon.exe file with VirusTotal:
(Note that VirusTotal doesn’t like that I haven’t updated Firefox.
)
I advise you to do the same.
Hope this helps…
1 user thanked author for this post.
-
SuzyQ777
AskWoody Plus -
Rick Corbett
AskWoody MVPJuly 16, 2021 at 10:08 am #2378095Another issue has now emerged with the latest version of Process Monitor (ProMon) – v3.83 – so, for the time being, I suggest you avoid it.
This, unfortunately, means you will need to search for earlier versions of ProcMon. After checking posts in the Microsoft Community Q&A for ProcMon, it looks like there were issues with several previous versions – 3.82, 3.81 and 3.80 – as well so, for the moment, I’m sticking with 3.50. It may be old now by comparison but I use it freqently and have yet to find an issue with it. I provided a download link for 3.50 in my last post.
Important: I’ve been doing a quick check for availability of earlier versions of ProcMon. An online search will show dozens of sites purporting to have ProcMon available for download. Unfortunately a great number of these sites really want you to download their copy of ProcMon using their own ‘Download Manager’… which is often just a vehicle for add-ons that you really, really do not want. So please be careful.
Note also that sites like Chocolatey and PortableApps offer download links to earlier versions of ProcMon… but, when used, actually download the latest version instead.
-
EricB
AskWoody Plus
-
-
Rick Corbett
AskWoody MVPJuly 16, 2021 at 10:51 am #2378100For what it’s worth, the license agreement for Sysinternals software does not allow for redistribution.
It’s a good point… but therein lies a problem. The Sysinternals/TechNet website for Process Monitor offers no changelog, no ability to download previous versions nor any method to submit bug reports either via the website or from within the utility.
All Sysinternals tools are offered ‘as is’ with no official Microsoft support. (Licensing FAQ)
This explains why posts reporting issues on the Microsoft Community Q&A for ProcMon show no replies.
-
EricB
AskWoody PlusJuly 16, 2021 at 11:18 am #2378116I haven’t been 100% diligent by I try to keep old versions of process monitor, process explorer, etc. as I download the newest versions. So although I have a personal fallback, my hands are tied as far as sharing older versions is concerned. Its unfortunate that Microsoft does not maintain an authorized and available archive of superseded versions to afford fallback options when bugs manifest in the currently offered version.
-
Viewing 6 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
My 3 monitors go black & then the Taskbar is moved to center monitor
by
saturn2233
3 hours, 42 minutes ago -
Apple backports fixes
by
Susan Bradley
3 hours, 51 minutes ago -
Win 11 24H2 will not install
by
Michael1950
3 hours, 56 minutes ago -
Advice to convert MBR to GPT and install Windows 11 Pro on unsupported PC
by
Andy M
3 hours, 27 minutes ago -
Photos from iPhone to Win 10 duplicating/reformatting to .mov
by
J9438
5 hours, 34 minutes ago -
Thunderbird in trouble. Here comes Thundermail
by
Alex5723
3 hours, 43 minutes ago -
Get back ” Open With” in context menus
by
CWBillow
16 hours, 36 minutes ago -
Many AMD Ryzen 9800X3D on ASRock have died
by
Alex5723
20 hours, 23 minutes ago -
simple general stupid question
by
WSaltamirano
14 hours, 23 minutes ago -
April 2025 Office non-Security updates
by
PKCano
1 day, 7 hours ago -
Microsoft wants to hear from you
by
Will Fastie
7 hours, 30 minutes ago -
Windows 11 Insider Preview Build 22635.5160 (23H2) released to BETA
by
joep517
1 day, 10 hours ago -
Europe Seeks Alternatives to U.S. Cloud Providers
by
Alex5723
1 day, 16 hours ago -
Test post
by
Susan Bradley
1 day, 18 hours ago -
Used Systems to delete Temp files Gone WRONG what does this mean?
by
Deo
1 day, 20 hours ago -
SSD shuts down on its own
by
CWBillow
1 day, 11 hours ago -
OneDrive File Sharing Changes
by
David Clark
2 days, 4 hours ago -
OneDrive File Sharing Changes
by
David Clark
2 days, 6 hours ago -
Win 10 Pro 22H2 to Win 11 Pro 23H2 Conversion Guide
by
doneager
1 day, 6 hours ago -
Today is world backup day
by
Alex5723
1 day, 22 hours ago -
Windows .exe on Mint
by
Slowpoke47
3 hours, 9 minutes ago -
Reviewing your licensing options
by
Susan Bradley
4 hours, 3 minutes ago -
Apple has been analyzing your photos since September 2024
by
B. Livingston
1 day, 3 hours ago -
What Windows 11 24H2 offers beyond bugs
by
Lance Whitney
23 hours, 12 minutes ago -
Making sense of Settings in Windows 11
by
Simon Bisson
1 day ago -
Windows 11 pro fails to log in after upgrading Win 10 pro to Win 11 pro 24h2
by
ben_sitaud
2 days, 4 hours ago -
23H2 / 24H2 / Local v. Microsoft Account.
by
CWBillow
2 days, 2 hours ago -
YouTube Ad Blocker Blocker
by
bbearren
2 days, 2 hours ago -
Obscure historical facts about Windows
by
Cybertooth
2 days, 3 hours ago -
Microsoft Backup
by
Linda2019
1 day, 19 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.