|
|
mdyblog 发表于 2013-8-3 22:57 
用这个脚本切换吧。
比原来的可靠。
谢谢M大在辛苦付出,2D3.3测试了下,还是有内存不能为READ问题,不过在切换用户后,用在最新这个脚本,确定后不影响使用,进程为0 0 0 10181093263 130200855663243769
4 0 0 0 130200855663243769
220 4 900 12948083 130200855663243769 \SystemRoot\System32\smss.exe \SystemRoot\System32\smss.exe
292 276 3508 5460035 130200855663243769 X:\Windows\system32\csrss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
340 276 3832 3120020 130200855663243769 X:\Windows\system32\wininit.exe wininit.exe
348 332 8732 57564369 130200855663243769 X:\Windows\system32\csrss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
400 332 5848 7488048 130200855663243769 X:\Windows\system32\winlogon.exe winlogon.exe
412 340 9796 34164219 130200855663243769 X:\Windows\system32\services.exe X:\Windows\system32\services.exe -setup
428 340 8940 14976096 130200855663243769 X:\Windows\system32\lsass.exe X:\Windows\system32\lsass.exe -setup
536 412 5312 12792082 130200855663243769 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k DcomLaunch
580 412 6288 35412227 130200855663243769 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k RPCSS
624 412 10980 14664094 130200855663243769 X:\Windows\System32\svchost.exe X:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
652 412 11996 17160110 130200855663243769 X:\Windows\System32\svchost.exe X:\Windows\System32\svchost.exe -k netsvcs
748 400 792 4524029 130200855663243769 X:\Windows\system32\PECMD.EXE PECMD.EXE MAIN %Windir%\system32\PECMD.INI
756 400 10252 81120520 130200855663243769 X:\Windows\system32\dwm.exe "dwm.exe"
932 412 5792 29484189 130200855663243769 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
788 812 2696 1872012 130200855663243769 X:\Windows\system32\cmd.exe cmd /c Y:\MMC64\WPSOffice\SETUP.CMD
248 788 4128 780005 130200855663243769 X:\Windows\system32\conhost.exe \??\X:\Windows\system32\conhost.exe 0x4
928 412 7880 7488048 130200855663243769 X:\Windows\System32\vds.exe X:\Windows\System32\vds.exe
1276 412 9020 6084039 130200855663243769 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k LocalService
284 412 26624 57564369 130200855663243769 X:\Windows\system32\svchost.exe X:\Windows\system32\svchost.exe -k NetworkService
916 748 2932 1404009 130200855663243769 X:\Windows\system32\PECMD.EXE PECMD **pecmd-cmd **pecmd-hide /L *PE AUTO_USBDISK ;; TEAM LOCK --try #auto_usbdisk| FIND $0=&ERROR,! EXIT FILE ;; FORX * C D E F G H I J K L M N O P Q R S T U V W X Y Z ,&&DRV, TEAM FORM -raw &&T,&&B=:| FIND $-1 = ,!! SHOW *, ;; TEAM WAIT 100| SHOW *U:0,,,U| WAIT 1200| ENVI @@DeskTopFresh=1
1708 884 28988 138840890 130200855663243769 X:\Windows\system32\csrss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
576 884 8124 5304034 130200855663243769 X:\Windows\system32\winlogon.exe winlogon.exe
1848 576 61884 238057526 130200855663243769 X:\Windows\system32\dwm.exe "dwm.exe"
1532 1472 1032 2028013 130200855663243769 X:\Windows\System32\PECMD_MAIN.exe PECMD_MAIN TEAM | KILL PECMD_MAIN| WAIT 50| MAIN **u X:\Windows\System32\Admin.ini
2672 1560 4488 2964019 130200855663243769 X:\Windows\SYSTEM32\CTFMON.EXE X:\Windows\SYSTEM32\CTFMON.EXE
2580 536 3436 156001 130200855663243769 X:\Windows\system32\DllHost.exe X:\Windows\system32\DllHost.exe /Processid:{478B41E6-3257-4519-BDA8-E971F9843849}
1108 1532 43960 176281130 130200855663243769 X:\Windows\explorer.exe X:\Windows\explorer.exe
2784 748 24436 13260085 130200855663243769 X:\Windows\EXPLORER.EXE X:\Windows\EXPLORER.EXE
1776 536 63168 436178796 130200855663243769 X:\Windows\explorer.exe X:\Windows\explorer.exe /factory,{ceff45ee-c862-41de-aee2-a022c81eda92} -Embedding
1104 1776 27556 2866674376 130200855663243769 X:\Users\Administrator\Desktop\工\WimTool.EXE "X:\Users\Administrator\Desktop\工\WimTool.EXE"
2504 1108 18028 81744524 130200855663243769 Y:\MMC64\WinContig\WinContig64.exe "Y:\MMC64\WinContig\WinContig64.exe"
2460 1108 85544 207637331 130200855663243769 Y:\MMC64\Opera\opera.exe "Y:\MMC64\Opera\opera.exe"
2652 624 0 0 130200855663243769
2088 1776 5136 2652017 130200855663243769 X:\Windows\system32\PECMD.EXE "PECMD.EXE" LOAD G:\sources\进程.wcs |
|