|
2012justion 发表于 2013-8-3 12:09 
0
再测试下其他
0 0 0 19161446829 130199766526566611
4 0 0 0 130199766526566611
268 4 896 7332047 130199766526566611 \SystemRoot\System32\smss.exe \SystemRoot\System32\smss.exe
332 316 3508 3276021 130199766526566611 X:\Windows\system32\csrss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
376 316 3876 1872012 130199766526566611 X:\Windows\system32\wininit.exe wininit.exe
392 384 8924 28704184 130199766526566611 X:\Windows\system32\csrss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
448 376 9608 14664094 130199766526566611 X:\Windows\system32\services.exe X:\Windows\system32\services.exe -setup
456 384 5852 4212027 130199766526566611 X:\Windows\system32\winlogon.exe winlogon.exe
472 376 11284 7800050 130199766526566611 X:\Windows\system32\lsass.exe X:\Windows\system32\lsass.exe -setup
584 448 5352 2340015 130199766526566611 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k DcomLaunch
628 448 5840 10140065 130199766526566611 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k RPCSS
668 448 10648 7488048 130199766526566611 X:\Windows\System32\svchost.exe X:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
700 448 11820 14664094 130199766526566611 X:\Windows\System32\svchost.exe X:\Windows\System32\svchost.exe -k netsvcs
764 456 764 1872012 130199766526566611 X:\Windows\system32\PECMD.EXE PECMD.EXE MAIN %Windir%\system32\PECMD.INI
772 456 10316 43836281 130199766526566611 X:\Windows\system32\dwm.exe "dwm.exe"
944 448 5600 10452067 130199766526566611 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
932 824 2712 1404009 130199766526566611 X:\Windows\system32\cmd.exe cmd /c Y:\MMC64\WPSOffice\SETUP.CMD
356 932 4060 468003 130199766526566611 X:\Windows\system32\conhost.exe \??\X:\Windows\system32\conhost.exe 0x4
1096 448 8192 3588023 130199766526566611 X:\Windows\System32\vds.exe X:\Windows\System32\vds.exe
1356 448 8080 4056026 130199766526566611 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k LocalService
1564 1184 5528 165049058 130199766526566611 X:\Windows\System32\PECMD.EXE "X:\Windows\System32\PECMD.EXE" Z:\DR64\DRVALL.INI
1956 448 20332 24024154 130199766526566611 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k NetworkService
1680 584 3488 156001 130199766526566611 X:\Windows\system32\DllHost.exe X:\Windows\system32\DllHost.exe /Processid:{478B41E6-3257-4519-BDA8-E971F9843849}
1496 764 2948 1404009 130199766526566611 X:\Windows\system32\PECMD.EXE PECMD **pecmd-cmd **pecmd-hide /L *PE AUTO_USBDISK ;; FORX * C D E F G H I J K L M N O P Q R S T U V W X Y Z ,&&DRV, TEAM FORM &&T,&&B=:| FIND $-1 = ,!! FIND $DRIVE_FIXED = , SHOW *, ;; TEAM WAIT 100| SHOW *U:0,,,U| WAIT 1000| ENVI @@DeskTopFresh=1
1240 560 7692 46956301 130199766526566611 X:\Windows\system32\csrss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
1388 560 8112 12792082 130199766526566611 X:\Windows\system32\winlogon.exe winlogon.exe
1704 764 27864 10452067 130199766526566611 X:\Windows\EXPLORER.EXE X:\Windows\EXPLORER.EXE
924 1388 26772 88764569 130199766526566611 X:\Windows\system32\dwm.exe "dwm.exe"
1712 732 36712 145392932 130199766526566611 X:\Windows\Explorer.EXE X:\Windows\Explorer.EXE
1112 1712 9632 1092007 130199766526566611 X:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe "X:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
116 584 39392 85956551 130199766526566611 X:\Windows\explorer.exe X:\Windows\explorer.exe /factory,{ceff45ee-c862-41de-aee2-a022c81eda92} -Embedding
2276 2108 2964 780005 130199766526566611 X:\Windows\system32\PECMD.EXE PECMD MAIN
1108 2108 4232 468003 130199766526566611 X:\Windows\SYSTEM32\CTFMON.EXE X:\Windows\SYSTEM32\CTFMON.EXE
2584 764 2956 780005 130199766526566611 X:\Windows\system32\PECMD.EXE PECMD **pecmd-cmd **pecmd-hide /L *PE AUTO_USBDISK ;; FORX * C D E F G H I J K L M N O P Q R S T U V W X Y Z ,&&DRV, TEAM FORM &&T,&&B=:| FIND $-1 = ,!! FIND $DRIVE_FIXED = , SHOW *, ;; TEAM WAIT 100| SHOW *U:0,,,U| WAIT 1000| ENVI @@DeskTopFresh=1
2840 764 2916 1248008 130199766526566611 X:\Windows\system32\PECMD.EXE PECMD **pecmd-cmd **pecmd-hide /L *PE AUTO_USBDISK ;; FORX * C D E F G H I J K L M N O P Q R S T U V W X Y Z ,&&DRV, TEAM FORM &&T,&&B=:| FIND $-1 = ,!! FIND $DRIVE_FIXED = , SHOW *, ;; TEAM WAIT 100| SHOW *U:0,,,U| WAIT 1000| ENVI @@DeskTopFresh=1
2856 1712 188912 144144924 130199766526566611 X:\Windows\System32\mstsc.exe "X:\Windows\System32\mstsc.exe"
2228 116 3172 1404009 130199766526566611 X:\Windows\system32\PECMD.EXE "PECMD.EXE" LOAD H:\sources\进程.wcs |
|