|
|
本帖最后由 likeyouli 于 2025-12-19 20:23 编辑
见图, c:\windows\system32\svchost.exe 老是连接4.145.79.81、4.145.79.80 , 貌似是Windows推送通知的,用防火墙禁止了一下,才算好了。 系统版本:win11 24h2 企业版 三蛋精简
对了,不方便查看的可以用如下代码查看,管理员打开powershell,粘贴回车即可看到:
function myprocessxin {
[CmdletBinding()]
param(
[Parameter(Mandatory = $false)]
[int]$ProcessId
)
if ($ProcessId) {
# 如果有指定 ProcessId,只查询该进程
Get-CimInstance -ClassName Win32_Process -Filter "ProcessId = $ProcessId" |
Select-Object Name, ProcessId, ExecutablePath, CreationDate, ParentProcessId
}
else {
# 如果没有指定参数,查询所有进程
Get-CimInstance -ClassName Win32_Process |
Select-Object Name, ProcessId, ExecutablePath|
Format-Table -Wrap -AutoSize
}}
Get-NetTCPConnection -State Established | ForEach-Object {
$conn = $_
$proc = myprocessxin -processId $conn.OwningProcess -ErrorAction SilentlyContinue
if ($proc) {
[PSCustomObject]@{
ProcessName = $proc.Name
weizhi=$proc.ExecutablePath
createdate=$proc.CreationDate
PID = $conn.OwningProcess
RemoteAddress = $conn.RemoteAddress
LocalAddress = $conn.LocalAddress
LocalPort = $conn.LocalPort
RemotePort = $conn.RemotePort
State = $conn.State } }}|out-gridview
|
-
..png
(206.21 KB, 下载次数: 4)
|