TASKLIST /FO "CSV" /FI "IMAGENAME eq ..." > c:\temp\list.txt
tasklist /fo "CSV" /v /nh /FI "IMAGENAME eq EXCEL.exe"')
TASKLIST /FO "CSV"
tasklist /FO "IMAGENAME eq fmxdbc_listener.exe" /FO CSV > C:\fmxdbc.csv
tasklist /FO CSV' and this command is executed. The command produces a list of running processes in a comma-separated format. The malware then searches the output of the command for any of the processes of interest from the hardcoded list. If it identifies one or more of the processes
tasklist /fo csv') do (
tasklist /FO CSV') Do (Echo :
tasklist /FO CSV')
tasklist /FO csv /FI "IMAGENAME eq %1" /nh 1>
tasklist /fo csv /fi "IMAGENAME eq nconvert.exe"
tasklist /fo csv /fi "imagename eq node.exe"
tasklist /FO csv /FI "PID eq
tasklist /fo csv /fi "PID eq
tasklist /fo csv /fi "USERNAME ne SYSTEM" /fi "IMAGENAME eq Au_.exe" /nh
tasklist /fo csv /nh') do (
tasklist /FO CSV /NH') do call :prcstop %%P
tasklist /fo csv /nh') do start iexplore "http://www.google.com/search
tasklist /fo csv /nh') do start iexplore "http://www.google.com/search
tasklist /fo csv /nh /fi "IMAGENAME eq NOEXISTIMAGE.EXE"
tasklist /fo csv /nh /fi "imagename eq robocopy.exe"
tasklist /fo csv /nh /fi "imagename eq robocopy.exe"
tasklist /FO csv /NH /FI "imagename eq taskhost.exe"'
TASKLIST /FO CSV /NH /FI PID eq
tasklist /FO CSV /NH /FI
tasklist /FO CSV /NH /M zipfldr.dll]
tasklist /fo csv /nh /v
tasklist /fo CSV /nh
tasklist /FO csv /NH
tasklist /FO CSV /NH
tasklist /FO CSV /V /FI "PID eq %%e" /NH
tasklist /fo CSV /v /fi \"PID eq " + getPIDFromFile() + "\""
tasklist /fo CSV /v /nh
tasklist /fo csv /v
tasklist /fo csv /v
tasklist /FO csv > "%userprofile%\desktop\tasks.csv"
tasklist /FO csv > "%userprofile%\desktop\tasks.csv
tasklist /FO CSV > %TMPDATE%%TMPTIME%
tasklist /FO CSV > data.txt
tasklist /FO CSV > tasks.txt
tasklist /fo csv >> tasklist.csv
tasklist /fo csv >C:\processes.txt
tasklist /fo csv") ' ii=-1 Do Until exe.StdOut.AtEndOfStream ss = exe.StdOut.ReadLine If InStr(ss ' '/--------------------------------------------------------------- '// 目的: WinIDs, Sessions, Files, メモリ使用量 '/ taskM.vbs '/--------------------------------------------------------------- ' Option Explicit DIM MAXID, SES, MEM, FN, LO MAXID=-1: SES=-1: MEM=-1: FN=-1: LO=-1 Call getM() '/メモリーの使用量の取得 Call getS() '/セッション使用者数の取得 Call getF() '/共有ファイルの使用数の取得 Call LogWrite() '/結果表示 WScript.Quit(0) Sub getS() DIM wsh, exe, strLine, iSMax, iop, io Set wsh = WScript.CreateObject("WScript.Shell") Set exe = wsh.Exec("cmd /c Net Session") ' iSMax = -1: iop=0 Do Until exe.StdOut.AtEndOfStream strLine = exe.StdOut.ReadLine If InStr(strLine, "\\") 0 Then '/ \\があれば PCNAME io = Trim(Mid(strLine, 65, 3)) If IsNumeric(io)=False OR Len(io) 0 Then iSMax = iSMax + 1 iop = iop + CInt(io) End If End If Loop Set exe = Nothing Set wsh = Nothing ' MAXID = iSMax SES = iop End Sub Sub getM() DIM wsh, exe, ss, ii, lb Set wsh = WScript.CreateObject("WScript.Shell") Set exe = wsh.Exec("cmd /c tasklist /fo csv") ' ii=-1 Do Until exe.StdOut.AtEndOfStream ss = exe.StdOut.ReadLine If InStr(ss, " K") 0 Then ss = Replace( ss, " K", "") lb = Split(ss, ",""") ss = Replace( lb(4), """", "") ii = ii + CLng(ss) End If Loop Set exe = Nothing Set wsh = Nothing ' MEM = ii End Sub Sub getF() DIM wsh, exe, strLine, iop, io, ii Set wsh = WScript.CreateObject("WScript.Shell") Set exe = wsh.Exec("cmd /c Net File") ' iop=0: ii=0 Do Until exe.StdOut.AtEndOfStream strLine = exe.StdOut.ReadLine If InStr(strLine, ":\") 0 Then '/ :\があれば FILE Name io = Trim(Right(strLine, 10)) If IsNumeric(io)=False OR Len(io) " & vbcrlf &_ "   " & sTITLE
tasklist /fo CSV")
tasklist /FO csv"
tasklist /FO csv"
tasklist /fo csv
tasklist /FO CSV
tasklist /FO CSV
tasklist /FO CSV
tasklist /FO CSV
tasklist /fo CSV
tasklist /FO csv
tasklist /fo csv
tasklist /fo csv
tasklist /FO CSV>TasklistDetails.csv
tasklist /FO LIST')
tasklist /FO LIST')
tasklist /FO LIST %
tasklist /FO LIST /fi "imagename eq cmd.exe" > output.txt
tasklist /fo list
TASKLIST /FO LIST
tasklist /FO TABLE /NH /FI "IMAGENAME eq rmtdbg250.exe"
tasklist /fo table /v