|
方法一
1.tasklist 能列出所有的进程,和相应的信息。taskkill可以清除进程
C:\Documents and Settings\Administrator>tasklist
映像名称 PID 会话名 会话# 内存使用
========================= ====== ================ =========== ============
System Idle Process 0 Console 0 16 K
System 4 Console 0 48 K
smss.exe 308 Console 0 48 K
csrss.exe 364 Console 0 4,580 K
winlogon.exe 452 Console 0 4,444 K
services.exe 496 Console 0 9,964 K
lsass.exe 508 Console 0 4,916 K
svchost.exe 680 Console 0 1,500 K
svchost.exe 728 Console 0 1,096 K
svchost.exe 888 Console 0 3,168 K
svchost.exe 904 Console 0 3,376 K
svchost.exe 932 Console 0 19,236 K
spoolsv.exe 1072 Console 0 4,276 K
msdtc.exe 1104 Console 0 872 K
CheckWD.exe 1224 Console 0 232 K
svchost.exe 1244 Console 0 104 K
ConSvr.exe 1276 Console 0 424 K
svchost.exe 1320 Console 0 1,004 K
explorer.exe 1528 Console 0 22,216 K
rundll32.exe 1632 Console 0 3,556 K
realsched.exe 1640 Console 0 124 K
S7ubTstx.exe 1700 Console 0 3,672 K
Student3.exe 1736 Console 0 6,524 K
ctfmon.exe 1744 Console 0 2,760 K
dbsrv7.exe 1768 Console 0 5,344 K
almsrvx.exe 1832 Console 0 9,624 K
dfssvc.exe 1896 Console 0 3,332 K
svchost.exe 172 Console 0 3,720 K
NetNCClt.exe 1056 Console 0 5,328 K
wmiprvse.exe 1732 Console 0 4,596 K
TTraveler.exe 1348 Console 0 13,888 K
pyintau.exe 1136 Console 0 4,424 K
taskmgr.exe 2584 Console 0 1,304 K
conime.exe 2620 Console 0 2,568 K
wmiprvse.exe 2796 Console 0 5,012 K
cmd.exe 3416 Console 0 1,524 K
tasklist.exe 3420 Console 0 3,420 K
如果要删除taskmgr.exe,可通过下述方式
C:\Documents and Settings\Administrator>taskkill /pid 2584
成功: 给进程发送了终止信号,进程的 PID 为 2584。
用ntsd -c -q -p PID 也可以删除 |
|
|