Loading |
VBScript |
JavaScript |
Powershell |
Search Options: WMI Win32_ProcessStartTrace QueryContent of WMI Win32_ProcessStartTrace Query.vbsMD5 Hash: F42A72A1135A580ED77E7DBCE6D64984 |
||
On Error Resume Next
strComputer = "." Set objWMIService = GetObject("winmgmts:\\" & strComputer & "\root\cimv2") Set colItems = objWMIService.ExecQuery("Select * from Win32_ProcessStartTrace",,48) For Each objItem in colItems Wscript.Echo "PageDirectoryBase: " & objItem.PageDirectoryBase Wscript.Echo "ParentProcessID: " & objItem.ParentProcessID Wscript.Echo "ProcessID: " & objItem.ProcessID Wscript.Echo "ProcessName: " & objItem.ProcessName Wscript.Echo "SECURITY_DESCRIPTOR: " & objItem.SECURITY_DESCRIPTOR Wscript.Echo "SessionID: " & objItem.SessionID Wscript.Echo "Sid: " & objItem.Sid Wscript.Echo "TIME_CREATED: " & objItem.TIME_CREATED Next | ||
© 2008 - 2013 Boris Toll :: Scripts available: 6.481 :: :: scriptbox.toll.at :: :: powered by www.toll.at :: |