|
mdyblog 发表于 2013-8-1 14:54 
用 下面的命令看进程, 看的详细, 能看看命令行:
FIND --pid*@ &&all,
MESS. %&all%
0 0 0 41083799356 130198139191042454
4 0 0 0 130198139191042454
264 4 912 7644049 130198139191042454 \SystemRoot\System32\smss.exe \SystemRoot\System32\smss.exe
328 312 3404 3276021 130198139191042454 X:\Windows\system32\csrss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
380 312 3856 1560010 130198139191042454 X:\Windows\system32\wininit.exe wininit.exe
388 372 8488 24804159 130198139191042454 X:\Windows\system32\csrss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
444 372 5840 4368028 130198139191042454 X:\Windows\system32\winlogon.exe winlogon.exe
452 380 9996 24804159 130198139191042454 X:\Windows\system32\services.exe X:\Windows\system32\services.exe -setup
460 380 11384 13884089 130198139191042454 X:\Windows\system32\lsass.exe X:\Windows\system32\lsass.exe -setup
580 452 5340 5304034 130198139191042454 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k DcomLaunch
624 452 6136 24180155 130198139191042454 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k RPCSS
664 452 11264 10140065 130198139191042454 X:\Windows\System32\svchost.exe X:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
696 452 11872 16380105 130198139191042454 X:\Windows\System32\svchost.exe X:\Windows\System32\svchost.exe -k netsvcs
780 444 968 2808018 130198139191042454 X:\Windows\system32\PECMD.EXE PECMD.EXE MAIN %Windir%\system32\PECMD.INI
788 444 10300 40716261 130198139191042454 X:\Windows\system32\dwm.exe "dwm.exe"
964 452 5672 8580055 130198139191042454 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
896 844 2696 1404009 130198139191042454 X:\Windows\system32\cmd.exe cmd /c Y:\MMC64\WPSOffice\SETUP.CMD
640 896 4080 156001 130198139191042454 X:\Windows\system32\conhost.exe \??\X:\Windows\system32\conhost.exe 0x4
1136 452 8024 4680030 130198139191042454 X:\Windows\System32\vds.exe X:\Windows\System32\vds.exe
1440 452 8180 4524029 130198139191042454 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k LocalService
252 452 18644 33384214 130198139191042454 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k NetworkService
1748 1048 8168 139308893 130198139191042454 X:\Windows\system32\csrss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
1204 1048 8200 5460035 130198139191042454 X:\Windows\system32\winlogon.exe winlogon.exe
336 1204 34820 384386464 130198139191042454 X:\Windows\system32\dwm.exe "dwm.exe"
1660 1848 9872 1092007 130198139191042454 X:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe "X:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
1832 1848 580 2808018 130198139191042454 X:\Windows\System32\PECMD.EXE "X:\Windows\System32\PECMD.EXE" MAIN **u X:\Windows\System32\Admin.ini
2224 780 2972 936006 130198139191042454 X:\Windows\system32\PECMD.exe PECMD /L *PE AUTO_USBDISK ;; FORX * C D E F G H I J K L M N O P Q R S T U V W X Y Z ,&&DRV, TEAM FORM &&T,&&B=:| FIND $-1 = ,!! FIND $DRIVE_FIXED = , SHOW *, ;; TEAM WAIT 100| SHOW *U:0,,,U| WAIT 1000| ENVI @@DeskTopFresh=1
2088 580 3484 312002 130198139191042454 X:\Windows\system32\DllHost.exe X:\Windows\system32\DllHost.exe /Processid:{478B41E6-3257-4519-BDA8-E971F9843849}
1132 780 2976 1248008 130198139191042454 X:\Windows\system32\PECMD.exe PECMD /L *PE AUTO_USBDISK ;; FORX * C D E F G H I J K L M N O P Q R S T U V W X Y Z ,&&DRV, TEAM FORM &&T,&&B=:| FIND $-1 = ,!! FIND $DRIVE_FIXED = , SHOW *, ;; TEAM WAIT 100| SHOW *U:0,,,U| WAIT 1000| ENVI @@DeskTopFresh=1
2780 872 4760 1560010 130198139191042454 X:\Windows\SYSTEM32\CTFMON.EXE X:\Windows\SYSTEM32\CTFMON.EXE
3036 2600 129724 541947474 130198139191042454 Y:\MMC64\Opera\opera.exe "Y:\MMC64\Opera\opera.exe"
2964 580 8128 7800050 130198139191042454 X:\Windows\system32\DllHost.exe X:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
1056 1832 44640 121368778 130198139191042454 X:\Windows\explorer.exe X:\Windows\explorer.exe
2364 580 44304 272533747 130198139191042454 X:\Windows\explorer.exe X:\Windows\explorer.exe /factory,{ceff45ee-c862-41de-aee2-a022c81eda92} -Embedding
1356 1056 189528 129480830 130198139191042454 X:\Windows\System32\mstsc.exe "X:\Windows\System32\mstsc.exe"
272 2364 8332 3120020 130198139191042454 X:\Windows\system32\NOTEPAD.EXE "X:\Windows\system32\NOTEPAD.EXE" Y:\WIMTOOL\boot.wim_0001\Windows\System32\su.ini
2888 2364 26256 2620660799 130198139191042454 C:\IE Cache\20130801\WimTool-V1.20.2010.718\WimTool.EXE "C:\IE Cache\20130801\WimTool-V1.20.2010.718\WimTool.EXE"
1012 1056 6308 312002 130198139191042454 X:\Windows\system32\notepad.exe "notepad.exe" X:\Users\Administrator\Desktop\a.wcs
2608 580 5028 156001 130198139191042454 X:\Windows\system32\DllHost.exe X:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
316 1056 3280 1716011 130198139191042454 X:\Windows\system32\PECMD.EXE "PECMD.EXE" LOAD X:\Users\Administrator\Desktop\a.wcs |
|