Tasklist

Last updated
tasklist
Developer(s) Microsoft, The AROS Development Team
Operating system Microsoft Windows, AROS Research Operating System
Type Command

In computing, tasklist is a command available in Microsoft Windows [1] and in the AROS shell. [2]

Contents

It is equivalent to the ps command in Unix and Unix-like operating systems and can also be compared with the Windows task manager (taskmgr).

Windows NT 4.0, the Windows 98 Resource Kit, the Windows 2000 Support Tools, and ReactOS [3] include the similar tlist command. Additionally, Microsoft provides the similar PsList command as part of Windows Sysinternals. [4]

Usage

Microsoft Windows

On Microsoft Windows tasklist shows all of the different local computer processes currently running. tasklist may also be used to show the processes of a remote system by using the command: tasklist /S "SYSTEM".

Optionally, they can be listed sorted by either the imagename, the PID or the amount of computer usage. But by default, they are sorted by chronological order:

 C:\Users\Gigabyte>'''tasklist'''    Image Name                     PID Session Name        Session#    Mem Usage  ========================= ======== ================ =========== ============  [[System Idle Process]]              0 Services                   0         20 K  System                           4 Services                   0      1,008 K  [[smss.exe]]                       300 Services                   0         84 K  [[csrss.exe]]                      468 Services                   0        600 K  [[wininit.exe]]                    532 Services                   0        132 K  [[services.exe]]                   636 Services                   0      4,672 K  [[lsass.exe]]                      644 Services                   0      6,532 K  [[svchost.exe]]                    752 Services                   0      4,824 K  nvvsvc.exe                     788 Services                   0        208 K  nvSCPAPISvr.exe                812 Services                   0      1,464 K  svchost.exe                    856 Services                   0      5,260 K  svchost.exe                    916 Services                   0      9,308 K  svchost.exe                    944 Services                   0     26,012 K  svchost.exe                    128 Services                   0     13,720 K  svchost.exe                    364 Services                   0     52,152 K  BootRacerServ.exe             1060 Services                   0        948 K  svchost.exe                   1108 Services                   0      9,408 K  spoolsv.exe                   1276 Services                   0        648 K  svchost.exe                   1308 Services                   0     16,184 K  sqlwriter.exe                 1700 Services                   0        160 K  svchost.exe                   1720 Services                   0        204 K  MsMpEng.exe                   1752 Services                   0     64,556 K  WUDFHost.exe                  2148 Services                   0        220 K  svchost.exe                   2188 Services                   0      5,876 K  svchost.exe                   2636 Services                   0      7,116 K  dasHost.exe                   2808 Services                   0      5,740 K  dllhost.exe                   1056 Services                   0        388 K  DkService.exe                 2708 Services                   0      4,648 K  FABS.exe                      3580 Services                   0        152 K  daemonu.exe                   3200 Services                   0      5,584 K  csrss.exe                     3872 Glass                      1        116 K  [[winlogon.exe]]                  5928 Glass                      1        156 K  [[Windows NT startup process#Authentication|LogonUI.exe]]                   1772 Glass                      1        512 K  [[dwm.exe]]                       4596 Glass                      1        108 K  csrss.exe                     5968 Glass                      4        128 K  winlogon.exe                  3364 Glass                      4        156 K  LogonUI.exe                   6108 Glass                      4        524 K  dwm.exe                       4764 Glass                      4        136 K  csrss.exe                     1408 Glass                      2        136 K  winlogon.exe                  7732 Glass                      2        160 K  LogonUI.exe                   2036 Glass                      2        524 K  dwm.exe                       6236 Glass                      2        144 K  PresentationFontCache.exe     9928 Services                   0        332 K  csrss.exe                     4948 Glass                      5        128 K  winlogon.exe                  3708 Glass                      5        156 K  LogonUI.exe                   5992 Glass                      5        528 K  dwm.exe                       8756 Glass                      5        152 K  csrss.exe                     8068 Glass                      8        136 K  winlogon.exe                  9000 Glass                      8        164 K  LogonUI.exe                   8240 Glass                      8        524 K  dwm.exe                       5576 Glass                      8        156 K  hamachi-2.exe                 6936 Services                   0      1,544 K  csrss.exe                     6644 Glass                      6        140 K  winlogon.exe                  4000 Glass                      6        168 K  LogonUI.exe                   2968 Glass                      6        516 K  dwm.exe                       6932 Glass                      6        148 K  csrss.exe                     2452 Glass                      9        136 K  winlogon.exe                  6244 Glass                      9        160 K  LogonUI.exe                   1996 Glass                      9        520 K  dwm.exe                        384 Glass                      9        148 K  svchost.exe                   2060 Services                   0        176 K  csrss.exe                      268 Glass                      7        140 K  winlogon.exe                 13088 Glass                      7        172 K  LogonUI.exe                   4256 Glass                      7        528 K  dwm.exe                       6700 Glass                      7        156 K  csrss.exe                     3516 Glass                     10        136 K  winlogon.exe                  3104 Glass                     10        172 K  csrss.exe                     6820 Console                   12      1,856 K  winlogon.exe                  5228 Console                   12        184 K  LogonUI.exe                  12020 Glass                     10        528 K  dwm.exe                       7280 Console                   12     10,200 K  dwm.exe                      12236 Glass                     10        176 K  nvxdsync.exe                 12648 Console                   12        316 K  nvvsvc.exe                     892 Console                   12        440 K  taskhostex.exe               11880 Console                   12      3,132 K  [[explorer.exe]]                 12224 Console                   12     35,076 K  LiveComm.exe                 11624 Console                   12      6,756 K  RuntimeBroker.exe             5408 Console                   12      8,244 K  RAVCpl64.exe                 11200 Console                   12        332 K  ZPSTray.exe                  11100 Console                   12        304 K  Mini_Monitor.exe             11740 Console                   12      4,532 K  firefox.exe                     88 Console                   12    201,512 K  plugin-container.exe         13120 Console                   12      1,148 K  FlashPlayerPlugin_11_5_50    11484 Console                   12        612 K  FlashPlayerPlugin_11_5_50     9276 Console                   12      1,748 K  [[Taskmgr.exe]]                   7908 Console                   12     24,588 K  [[Windows Management Instrumentation|WmiPrvSE.exe]]                 12568 Services                   0      5,284 K  [[cmd.exe]]                       3020 Console                   12      2,092 K  conhost.exe                   7352 Console                   12      4,676 K  tasklist.exe                  9072 Console                   12      5,516 K  WmiPrvSE.exe                  6384 Services                   0      5,708 K    C:\Users\Gigabyte>[[taskkill]]/PID 0409/F

See also

Related Research Articles

Windows Management Instrumentation (WMI) consists of a set of extensions to the Windows Driver Model that provides an operating system interface through which instrumented components provide information and notification. WMI is Microsoft's implementation of the Web-Based Enterprise Management (WBEM) and Common Information Model (CIM) standards from the Distributed Management Task Force (DMTF).

In computing, kill is a command that is used in several popular operating systems to send signals to running processes.

cmd.exe Command prompt program

cmd.exe is the default command-line interpreter for the OS/2, eComStation, ArcaOS, Microsoft Windows, and ReactOS operating systems. The name refers to its executable filename. It is also commonly referred to as cmd or the Command Prompt, referring to the default window title on Windows. The implementations differ on the various systems but the behavior and basic set of commands is generally consistent. cmd.exe is the counterpart of COMMAND.COM in DOS and Windows 9x systems, and analogous to the Unix shells used on Unix-like systems. The initial version of cmd.exe for Windows NT was developed by Therese Stowell. Windows CE 2.11 was the first embedded Windows release to support a console and a Windows CE version of cmd.exe. On Windows CE .NET 4.2, Windows CE 5.0 and Windows Embedded CE 6.0 it is also referred to as Command Processor Shell. The ReactOS implementation of cmd.exe is derived from FreeCOM, the FreeDOS command line interpreter.

CHKDSK System tool in DOS, OS/2 and Windows

In computing, CHKDSK is a system tool and command in DOS, Digital Research FlexOS, IBM/Toshiba 4690 OS, IBM OS/2, Microsoft Windows and related operating systems. It verifies the file system integrity of a volume and attempts to fix logical file system errors. It is similar to the fsck command in Unix and similar to Microsoft ScanDisk which co-existed with CHKDSK in Windows 9x and MS-DOS 6.x.

Winlogon

In computing, Winlogon is the component of Microsoft Windows operating systems that is responsible for handling the secure attention sequence, loading the user profile on logon, and optionally locking the computer when a screensaver is running. The actual obtainment and verification of user credentials is left to other components. Winlogon is a common target for several threats that could modify its function and memory usage. Increased memory usage for this process might indicate that it has been "hijacked". In Windows Vista and later operating systems, Winlogon's roles and responsibilities have changed significantly.

Svchost.exe is a system process that can host from one or more Windows services in the Windows NT family of operating systems. Svchost is essential in the implementation of shared service processes, where a number of services can share a process in order to reduce resource consumption. Grouping multiple services into a single process conserves computing resources, and this consideration was of particular concern to NT designers because creating Windows processes takes more time and consumes more memory than in other operating systems, e.g. in the Unix family. However, if one of the services causes an unhandled exception, the entire process may crash. In addition, identifying component services can be more difficult for end users. Problems with various hosted services, particularly with Windows Update, get reported by users as involving svchost.

In computing, SUBST is a command on the DOS, IBM OS/2, Microsoft Windows and ReactOS operating systems used for substituting paths on physical and logical drives as virtual drives.

The Windows NT booting process is the process by which Windows NT 4.0, Windows 2000, Windows XP and Windows Server 2003 operating systems initialize. In Windows Vista and later, this process has changed significantly; see Windows NT 6 startup process for information about what has changed.

The Native API is a lightweight application programming interface (API) used by Windows NT and user mode applications. This API is used in the early stages of Windows NT startup process, when other components and APIs are still unavailable. Therefore, a few Windows components, such as the Client/Server Runtime Subsystem (CSRSS), are implemented using the Native API. The Native API is also used by subroutines such as those in kernel32.dll that implement the Windows API, the API based on which most of the Windows components are created.

In Windows NT operating systems, a Windows service is a computer program that operates in the background. It is similar in concept to a Unix daemon. A Windows service must conform to the interface rules and protocols of the Service Control Manager, the component responsible for managing Windows services. It is the Services and Controller app, services.exe, that launches all the services and manages their actions, such as start, end, etc.

Session Manager Subsystem, or smss.exe, is a component of the Microsoft Windows NT family of operating systems, starting in Windows NT 3.1. It is executed during the startup process of those operating systems, at which time it performs the following tasks:

Client Server Runtime Subsystem, or csrss.exe, is a component of the Windows NT family of operating systems that provides the user mode side of the Win32 subsystem and is included in Windows NT 3.1 and later. Because most of the Win32 subsystem operations have been moved to kernel mode drivers in Windows NT 4 and later, CSRSS is mainly responsible for Win32 console handling and GUI shutdown. It is critical to system operation; therefore, terminating this process will result in system failure. Under normal circumstances, CSRSS cannot be terminated with the taskkill command or with Windows Task Manager, although it is possible in Windows Vista if the Task Manager is run in Administrator mode. On Windows 7 and later, Task Manager will inform the user that terminating the process may result in system failure, and prompt if they want to continue. In Windows NT 4.0 however, terminating CSRSS without the Session Manager Subsystem (SMSS) watching will not crash the system. However in Windows XP, terminating CSRSS without SMSS watching will crash the system due to the critical bit being set in RAM for csrss.exe.

Process Explorer

Process Explorer is a freeware task manager and system monitor for Microsoft Windows created by SysInternals, which has been acquired by Microsoft and re-branded as Windows Sysinternals. It provides the functionality of Windows Task Manager along with a rich set of features for collecting information about processes running on the user's system. It can be used as the first step in debugging software or system problems.

The Windows booting process is the process by which the Microsoft Windows series of operating systems boots.

Temporary Internet Files is a folder on Microsoft Windows which serves as the browser cache for Internet Explorer to cache pages and other multimedia content, such as video and audio files, from websites visited by the user. This allows such websites to load more quickly the next time they are visited.

diskpart Command line program

In computing, diskpart is a command-line disk partitioning utility included in Windows 2000 and later Microsoft operating systems, replacing its predecessor, fdisk. The command is also available in ReactOS.

net (command)

In computing, net is a command in IBM OS/2, Microsoft Windows and ReactOS used to manage and configure the operating system from the command-line. It is also part of the IBM PC Network Program for DOS.

Service Control Manager (SCM) is a special system process under the Windows NT family of operating systems, which starts, stops and interacts with Windows service processes. It is located in the %SystemRoot%\System32\services.exe executable. Service processes interact with SCM through a well-defined API, and the same API is used internally by the interactive Windows service management tools such as the MMC snap-in Services.msc and the command-line Service Control utility sc.exe. Terminating this file is used as a method of causing the Blue Screen of Death.

Server Core is a minimalistic Microsoft Windows Server installation option, debuted in Windows Server 2008. Server Core provides a server environment with functionality scaled back to core server features, and because of limited features, it has reduced servicing and management requirements, attack surface, disk and memory usage. Andrew Mason, a program manager on the Windows Server team, noted that a primary motivation for producing a Server Core variant of Windows Server 2008 was to reduce the attack surface of the operating system, and that about 70% of the security vulnerabilities in Microsoft Windows from the prior five years would not have affected Server Core. Most notably, no Windows Explorer shell is installed. All configuration and maintenance is done entirely through command-line interface windows, or by connecting to the machine remotely using Microsoft Management Console (MMC), remote server administration tools, and PowerShell.

WinRM is Microsoft's implementation of WS-Management in Windows which allows systems to access or exchange management information across a common network. Utilizing scripting objects or the built-in command-line tool, WinRM can be used with any remote computers that may have baseboard management controllers (BMCs) to acquire data. Windows-based computers including WinRM certain data supplied by Windows Management Instrumentation (WMI) can also be obtained.

References

  1. "Tasklist | Microsoft Docs".
  2. "AROS Research Operating System".
  3. "Reactos/Reactos". GitHub . 4 November 2021.
  4. "PsList - Windows Sysinternals".

Further reading