Home / Sistemi operativi & mobile / Windows / Controllo processi in Windows tramite shell
Mattepuffo

Controllo processi in Windows tramite shell

Controllo processi in Windows tramite shell

Ogni tanto anche "DOS" riserva qualche sorpresa.

Per gli amanti della riga di comando ho scoperto che è possibile listare tutti i processi tramite un semplice comando.

Aprite il Prompt dei comandi e digitate:

C:\Documents and Settings\Administrator>tasklist

Nome immagine                PID Nome sessione    Sessione Utilizzo mem
========================= ====== ================ ======== ============
System Idle Process            0 Console                 0         28 K
System                         4 Console                 0        240 K
smss.exe                     520 Console                 0        436 K
csrss.exe                    568 Console                 0      4.332 K
winlogon.exe                 592 Console                 0      4.424 K
services.exe                 636 Console                 0      3.640 K
lsass.exe                    648 Console                 0      1.752 K
vmacthlp.exe                 808 Console                 0      2.584 K
svchost.exe                  824 Console                 0      5.232 K
svchost.exe                  900 Console                 0      4.364 K
svchost.exe                 1020 Console                 0     32.440 K
svchost.exe                 1072 Console                 0      3.972 K
svchost.exe                 1132 Console                 0      3.996 K
spoolsv.exe                 1436 Console                 0      6.748 K
explorer.exe                1536 Console                 0     25.800 K
TSVNCache.exe               1688 Console                 0      4.588 K
VMwareTray.exe              1860 Console                 0      4.936 K
VMwareUser.exe              1928 Console                 0     11.708 K
egui.exe                    1944 Console                 0      6.244 K
realsched.exe               1984 Console                 0        644 K
jusched.exe                 1996 Console                 0      2.876 K
ctfmon.exe                  2040 Console                 0      3.652 K
taskbarshuffle.exe           152 Console                 0      4.204 K
SSScheduler.exe              280 Console                 0      2.152 K
svchost.exe                  972 Console                 0      3.796 K
DCServce.exe                1192 Console                 0      2.744 K
ekrn.exe                    1248 Console                 0     62.284 K
jqs.exe                     1344 Console                 0      1.432 K
rsync.exe                   1368 Console                 0      3.172 K
svchost.exe                 1584 Console                 0      4.232 K
vmtoolsd.exe                1756 Console                 0      9.244 K
VMUpgradeHelper.exe         1616 Console                 0      4.124 K
imapi.exe                   2212 Console                 0      4.148 K
TPAutoConnSvc.exe           2500 Console                 0      4.392 K
alg.exe                     2740 Console                 0      3.636 K
TPAutoConnect.exe           3668 Console                 0      4.900 K
wmiapsrv.exe                3772 Console                 0      4.612 K
devenv.exe                  3372 Console                 0    260.632 K
WPFFontCache_v0400.exe      1480 Console                 0      8.740 K
firefox.exe                 2928 Console                 0    174.704 K
plugin-container.exe        3448 Console                 0     20.196 K
cmd.exe                     3480 Console                 0      2.776 K
tasklist.exe                3420 Console                 0      5.076 K
wmiprvse.exe                3996 Console                 0      5.908 K

Ovviamente possiamo usare altre opzioni interessanti.

Con /SVC otteniamo la lista dei processi e gli eventuali servizi collegati:

C:\Documents and Settings\Administrator>tasklist /SVC

Nome immagine                PID Servizi
========================= ====== =============================================
System Idle Process            0 N/D
System                         4 N/D
smss.exe                     520 N/D
csrss.exe                    568 N/D
winlogon.exe                 592 N/D
services.exe                 636 Eventlog, PlugPlay
lsass.exe                    648 PolicyAgent, SamSs
vmacthlp.exe                 808 VMware Physical Disk Helper Service
svchost.exe                  824 DcomLaunch, TermService
svchost.exe                  900 RpcSs
svchost.exe                 1020 AudioSrv, BITS, Browser, CryptSvc, Dhcp,
dmserver, ERSvc, EventSystem,
FastUserSwitchingCompatibility, helpsvc,
lanmanserver, lanmanworkstation, Netman,
Nla, RasMan, Schedule, seclogon, SENS,
SharedAccess, ShellHWDetection, srservice,
TapiSrv, Themes, TrkWks, W32Time, winmgmt,
wuauserv, WZCSVC
svchost.exe                 1072 Dnscache
svchost.exe                 1132 LmHosts, RemoteRegistry, SSDPSRV
spoolsv.exe                 1436 Spooler
explorer.exe                1536 N/D
TSVNCache.exe               1688 N/D
VMwareTray.exe              1860 N/D
VMwareUser.exe              1928 N/D
egui.exe                    1944 N/D
realsched.exe               1984 N/D
jusched.exe                 1996 N/D
ctfmon.exe                  2040 N/D
taskbarshuffle.exe           152 N/D
SSScheduler.exe              280 N/D
svchost.exe                  972 WebClient
DCServce.exe                1192 DeltaCopyService
ekrn.exe                    1248 ekrn
jqs.exe                     1344 JavaQuickStarterService
rsync.exe                   1368 N/D
svchost.exe                 1584 stisvc
vmtoolsd.exe                1756 VMTools
VMUpgradeHelper.exe         1616 VMUpgradeHelper
imapi.exe                   2212 ImapiService
TPAutoConnSvc.exe           2500 TPAutoConnSvc
alg.exe                     2740 ALG
TPAutoConnect.exe           3668 N/D
wmiapsrv.exe                3772 WmiApSrv
devenv.exe                  3372 N/D
WPFFontCache_v0400.exe      1480 WPFFontCache_v0400
firefox.exe                 2928 N/D
plugin-container.exe        3448 N/D
cmd.exe                     2324 N/D
tasklist.exe                3140 N/D
wmiprvse.exe                2708 N/D

Infine con l'opzione /M otteniamo la lista completa dei moduli usati (non vi riporto l'outpu perchè è bello lungo).

Insomma anche Windows ogni tanto ha delle sorprese.....