Posted by: ibmadmin | May 15, 2011

Windows Management Instrumentation Command-line (WMIC) Tool

Windows Management Instrumentation Command-line (WMIC) Tool

We have various Windows command to get to know about the system details. But there is one command which will give all the details about the Windows System. The command is

WMIC – Windows Management Instrumentation Command-Line

There are two way to execute the WMIC command. We can run the WMIC command in the interactive mode (i.e. like command prompt) and we can use the command in batch file sequence as statements.

First we will see about how we can use the WMIC command in the Interactive mode.

Interactive Mode:

Note:  Copy and paste the following output into Notepad++ for the clear formatting as it shown here as wrapped format.

C:\WindowsScripts\Scriptomatic>wmic

wmic:root\cli>/?

[global switches] <command>

The following global switches are available:
/NAMESPACE           Path for the namespace the alias operate against.
/ROLE                Path for the role containing the alias definitions.
/NODE                Servers the alias will operate against.
/IMPLEVEL            Client impersonation level.
/AUTHLEVEL           Client authentication level.
/LOCALE              Language id the client should use.
/PRIVILEGES          Enable or disable all privileges.
/TRACE               Outputs debugging information to stderr.
/RECORD              Logs all input commands and output.
/INTERACTIVE         Sets or resets the interactive mode.
/FAILFAST            Sets or resets the FailFast mode.
/USER                User to be used during the session.
/PASSWORD            Password to be used for session login.
/OUTPUT              Specifies the mode for output redirection.
/APPEND              Specifies the mode for output redirection.
/AGGREGATE           Sets or resets aggregate mode.
/AUTHORITY           Specifies the <authority type> for the connection.
/?[:<BRIEF|FULL>]    Usage information.

For more information on a specific global switch, type: switch-name /?

The following alias/es are available in the current role:
ALIAS                    – Access to the aliases available on the local system
BASEBOARD                – Base board (also known as a motherboard or system board) management.
BIOS                     – Basic input/output services (BIOS) management.
BOOTCONFIG               – Boot configuration management.
CDROM                    – CD-ROM management.
COMPUTERSYSTEM           – Computer system management.
CPU                      – CPU management.
CSPRODUCT                – Computer system product information from SMBIOS.
DATAFILE                 – DataFile Management.
DCOMAPP                  – DCOM Application management.
DESKTOP                  – User’s Desktop management.
DESKTOPMONITOR           – Desktop Monitor management.
DEVICEMEMORYADDRESS      – Device memory addresses management.
DISKDRIVE                – Physical disk drive management.
DISKQUOTA                – Disk space usage for NTFS volumes.
DMACHANNEL               – Direct memory access (DMA) channel management.
ENVIRONMENT              – System environment settings management.
FSDIR                    – Filesystem directory entry management.
GROUP                    – Group account management.
IDECONTROLLER            – IDE Controller management.
IRQ                      – Interrupt request line (IRQ) management.
JOB                      – Provides  access to the jobs scheduled using the schedule service.
LOADORDER                – Management of system services that define execution dependencies.
LOGICALDISK              – Local storage device management.
LOGON                    – LOGON Sessions.
MEMCACHE                 – Cache memory management.
MEMLOGICAL               – System memory management (configuration layout and availability of memory).
MEMPHYSICAL              – Computer system’s physical memory management.
NETCLIENT                – Network Client management.
NETLOGIN                 – Network login information (of a particular user) management.
NETPROTOCOL              – Protocols (and their network characteristics) management.
NETUSE                   – Active network connection management.
NIC                      – Network Interface Controller (NIC) management.
NICCONFIG                – Network adapter management.
NTDOMAIN                 – NT Domain management.
NTEVENT                  – Entries in the NT Event Log.
NTEVENTLOG               – NT eventlog file management.
ONBOARDDEVICE            – Management of common adapter devices built into the motherboard (system board).
OS                       – Installed Operating System/s management.
PAGEFILE                 – Virtual memory file swapping management.
PAGEFILESET              – Page file settings management.
PARTITION                – Management of partitioned areas of a physical disk.
PORT                     – I/O port management.
PORTCONNECTOR            – Physical connection ports management.
PRINTER                  – Printer device management.
PRINTERCONFIG            – Printer device configuration management.
PRINTJOB                 – Print job management.
PROCESS                  – Process management.
PRODUCT                  – Installation package task management.
QFE                      – Quick Fix Engineering.
QUOTASETTING             – Setting information for disk quotas on a volume.
RECOVEROS                – Information that will be gathered from memory when the operating system fails.
REGISTRY                 – Computer system registry management.
SCSICONTROLLER           – SCSI Controller management.
SERVER                   – Server information management.
SERVICE                  – Service application management.
SHARE                    – Shared resource management.
SOFTWAREELEMENT          – Management of the  elements of a software product installed on a system.
SOFTWAREFEATURE          – Management of software product subsets of SoftwareElement.
SOUNDDEV                 – Sound Device management.
STARTUP                  – Management of commands that run automatically when users log onto the computer system.
SYSACCOUNT               – System account management.
SYSDRIVER                – Management of the system driver for a base service.
SYSTEMENCLOSURE          – Physical system enclosure management.
SYSTEMSLOT               – Management of physical connection points including ports,  slots and peripherals, and proprietary connections points.
TAPEDRIVE                – Tape drive management.
TEMPERATURE              – Data management of a temperature sensor (electronic thermometer).
TIMEZONE                 – Time zone data management.
UPS                      – Uninterruptible power supply (UPS) management.
USERACCOUNT              – User account management.
VOLTAGE                  – Voltage sensor (electronic voltmeter) data management.
VOLUMEQUOTASETTING       – Associates the disk quota setting with a specific disk volume.
WMISET                   – WMI service operational parameters management.

For more information on a specific alias, type: alias /?

CLASS     – Escapes to full WMI schema.
PATH      – Escapes to full WMI object paths.
CONTEXT   – Displays the state of all the global switches.
QUIT/EXIT – Exits the program.

For more information on CLASS/PATH/CONTEXT, type: (CLASS | PATH | CONTEXT) /?

WMI Scripts Using the Scriptomatic Utility
wmic:root\cli>PROCESS
Caption                    CommandLine                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                CreationClassName  CreationDate               CSCreationClassName   CSName                 Description                ExecutablePath                                                                                                ExecutionState  Handle  HandleCount  InstallDate  KernelModeTime  MaximumWorkingSetSize  MinimumWorkingSetSize  Name               OSCreationClassName    OSName                                                                     OtherOperationCount  OtherTransferCount  PageFaults  PageFileUsage  ParentProcessId  PeakPageFileUsage  PeakVirtualSize  PeakWorkingSetSize  Priority  PrivatePageCount  ProcessId  QuotaNonPagedPoolUsage  QuotaPagedPoolUsage  QuotaPeakNonPagedPoolUsage  QuotaPeakPagedPoolUsage  ReadOperationCount  ReadTransferCount  SessionId  Status  TerminationDate  ThreadCount  UserModeTime  VirtualSize  WindowsVersion  WorkingSetSize  WriteOperationCount  WriteTransferCount
System Idle Process                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   Win32_Process                                 Win32_ComputerSystem  IBMADMIN_HOST-495B58E  System Idle Process                                                                                                                              0       0                         744163906250                                                  System Idle Process        Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  0                    0                   0           0              0                0                  0                0                   0         0                 0          0                       0                    0                           0                        0                   0                  0                                   4            0             0            5.1.2600        28672           0                    0
System                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Win32_Process                                 Win32_ComputerSystem  IBMADMIN_HOST-495B58E  System                                                                                                                                           4       1059                      2291718750      1413120                0                      System                     Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  34673                204998              5442        0              0                0                  3158016          2428928             8         28672             4          0                       0                    0                           0                        137                 1176068            0                                   72           0             1929216      5.1.2600        241664          4754                 17079296
smss.exe                   \SystemRoot\System32\smss.exe                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Win32_Process      20110515124015.828125-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  smss.exe                   C:\WINDOWS\System32\smss.exe                                                                                          668     19                        2968750         1413120                204800                 smss.exe                   Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  141                  4102                200         176128         4                1757184            14983168         458752              11        176128            668        640                     6172                 792                         27644                    9                   4122               0                                   3            156250        3899392      5.1.2600        438272          4                    4
csrss.exe                  C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               Win32_Process      20110515124019.140625-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  csrss.exe                  C:\WINDOWS\system32\csrss.exe                                                                                         724     756                       2975000000      1413120                204800                 csrss.exe                  Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  1605188              30985149            121633      10424320       668              11169792           66158592         15499264            13        10424320          724        8808                    112308               9528                        145652                   418777              137239605          0                                   14           2183593750    51740672     5.1.2600        4972544         0                    0
winlogon.exe               winlogon.exe                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               Win32_Process      20110515124021.078125-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  winlogon.exe               C:\WINDOWS\system32\winlogon.exe                                                                                      748     338                       28437500        1413120                204800                 winlogon.exe               Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  4042                 217652              7712        4972544        668              9781248            57331712         14757888            13        4972544           748        8512                    91060                9880                        98580                    316                 3051390            0                                   15           5937500       52170752     5.1.2600        1630208         165                  13877
services.exe               C:\WINDOWS\system32\services.exe                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           Win32_Process      20110515124023.500000-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  services.exe               C:\WINDOWS\system32\services.exe                                                                                      792     314                       58593750        1413120                204800                 services.exe               Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  2202                 21742               2231        1859584        748              2281472            26963968         4046848             9         1859584           792        7472                    38828                8864                        41340                    337                 19176              0                                   15           9062500       22769664     5.1.2600        4009984         428                  37077
lsass.exe                  C:\WINDOWS\system32\lsass.exe                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Win32_Process      20110515124023.781250-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  lsass.exe                  C:\WINDOWS\system32\lsass.exe                                                                                         804     447                       67812500        1413120                204800                 lsass.exe                  Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  46201                308156              2647        4198400        748              4321280            45756416         6852608             9         4198400           804        9328                    74212                11448                       77404                    23956               2170163            0                                   23           17031250      44175360     5.1.2600        6836224         21439                1740200
vmacthlp.exe               “C:\Program Files\VMware\VMware Tools\vmacthlp.exe”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Win32_Process      20110515124025.484375-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  vmacthlp.exe               C:\Program Files\VMware\VMware Tools\vmacthlp.exe                                                                     964     26                        937500          1413120                204800                 vmacthlp.exe               Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  109                  2590                797         626688         792              806912             34238464         2752512             8         626688            964        1800                    32148                2000                        65636                    6                   2341               0                                   1            156250        16228352     5.1.2600        2572288         3                    2218
svchost.exe                C:\WINDOWS\system32\svchost -k DcomLaunch                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Win32_Process      20110515124026.093750-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  svchost.exe                C:\WINDOWS\system32\svchost.exe                                                                                       980     245                       5156250         1413120                204800                 svchost.exe                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  5253                 115698              3482        2973696        792              23973888           66465792         5713920             8         2973696           980        6464                    74476                7440                        77660                    131                 440872             0                                   21           2812500       64770048     5.1.2600        5652480         27                   1848
svchost.exe                C:\WINDOWS\system32\svchost -k rpcss                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       Win32_Process      20110515124026.750000-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  svchost.exe                C:\WINDOWS\system32\svchost.exe                                                                                       1068    315                       17500000        1413120                204800                 svchost.exe                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  445                  15286               1496        1966080        792              2015232            38576128         4775936             8         1966080           1068       13848                   70700                16072                       71332                    111                 439276             0                                   10           7031250       37531648     5.1.2600        4759552         6                    300
svchost.exe                C:\WINDOWS\System32\svchost.exe -k netsvcs                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 Win32_Process      20110515124027.109375-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  svchost.exe                C:\WINDOWS\System32\svchost.exe                                                                                       1164    1327                      107187500       1413120                204800                 svchost.exe                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  16606                910340              73618       17059840       792              24711168           127819776        32411648            8         17059840          1164       61536                   188788               71264                       195964                   15030               95540331           0                                   66           51875000      124424192    5.1.2600        24764416        2674                 437539
svchost.exe                C:\WINDOWS\system32\svchost.exe -k NetworkService                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Win32_Process      20110515124027.328125-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  svchost.exe                C:\WINDOWS\system32\svchost.exe                                                                                       1268    104                       38750000        1413120                204800                 svchost.exe                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  6445                 464768              5397        1966080        792              2088960            35934208         4419584             8         1966080           1268       3320                    55604                10802                       65884                    111                 418410             0                                   6            7812500       34623488     5.1.2600        4354048         4                    92
svchost.exe                C:\WINDOWS\system32\svchost.exe -k LocalService                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Win32_Process      20110515124027.640625-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  svchost.exe                C:\WINDOWS\system32\svchost.exe                                                                                       1364    181                       13437500        1413120                204800                 svchost.exe                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  3118                 85974               1311        1642496        792              1667072            37195776         4300800             8         1642496           1364       5248                    68372                10390                       69116                    25                  24020              0                                   10           3750000       36933632     5.1.2600        4292608         24                   1532
spoolsv.exe                C:\WINDOWS\system32\spoolsv.exe                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Win32_Process      20110515124030.468750-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  spoolsv.exe                C:\WINDOWS\system32\spoolsv.exe                                                                                       1504    149                       5468750         1413120                204800                 spoolsv.exe                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  685                  7540                1821        3883008        792              4771840            47214592         6770688             8         3883008           1504       6672                    79092                8824                        83132                    6                   22744              0                                   11           625000        45592576     5.1.2600        5971968         5                    228
svchost.exe                C:\WINDOWS\system32\svchost.exe -k LocalService                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Win32_Process      20110515124036.828125-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  svchost.exe                C:\WINDOWS\system32\svchost.exe                                                                                       1984    117                       1093750         1413120                204800                 svchost.exe                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  275                  4848                1001        1372160        792              1396736            37531648         3940352             8         1372160           1984       3368                    68684                4408                        68796                    18                  913                0                                   5            312500        37269504     5.1.2600        3932160         15                   936
explorer.exe               C:\WINDOWS\Explorer.EXE                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Win32_Process      20110515124038.093750-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  explorer.exe               C:\WINDOWS\Explorer.EXE                                                                                               344     635                       353281250       1413120                204800                 explorer.exe               Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  27462                679005              27776       24076288       228              24424448           150450176        32202752            8         24076288          344        17160                   207372               19856                       265876                   2714                10668309           0                                   15           39687500      120664064    5.1.2600        13742080        39                   2622
beasvc.exe                 F:\Oracle\MIDDLE~1\WLSERV~1.3\server\bin\beasvc.exe                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Win32_Process      20110515124038.781250-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  beasvc.exe                 F:\Oracle\MIDDLE~1\WLSERV~1.3\server\bin\beasvc.exe                                                                   500     478                       267031250       1413120                204800                 beasvc.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  15494                455582              29175       82051072       792              86257664           319725568        66621440            8         82051072          500        17104                   63780                17728                       72964                    7280                38855004           0                                   22           767812500     315994112    5.1.2600        65961984        7                    617
ctfmon.exe                 ctfmon.exe                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 Win32_Process      20110515124038.859375-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  ctfmon.exe                 C:\WINDOWS\system32\ctfmon.exe                                                                                        512     126                       5781250         1413120                204800                 ctfmon.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  209                  4204                1080        1073152        344              1085440            36925440         4022272             8         1073152           512        4160                    64756                5400                        72044                    7                   22920              0                                   1            625000        33214464     5.1.2600        4022272         6                    432
nmesrvc.exe                E:\oracle\product\11g\db1\bin\nmesrvc.exe                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Win32_Process      20110515124039.203125-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  nmesrvc.exe                E:\oracle\product\11g\db1\bin\nmesrvc.exe                                                                             648     44                        312500          1413120                204800                 nmesrvc.exe                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  84                   724                 406         405504         792              409600             9474048          1683456             8         405504            648        1280                    16332                1464                        16476                    3                   140                0                                   2            156250        9469952      5.1.2600        1679360         29                   1708
omtsreco.exe               E:\oracle\product\11g\db1\bin\omtsreco.exe “OracleMTSRecoveryService”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Win32_Process      20110515124042.312500-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  omtsreco.exe               E:\oracle\product\11g\db1\bin\omtsreco.exe                                                                            1260    136                       5312500         1413120                204800                 omtsreco.exe               Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  617                  7352                6066        21626880       792              21643264           90402816         24813568            8         21626880          1260       7856                    161428               8320                        170196                   46                  61533              0                                   4            625000        89354240     5.1.2600        24801280        42                   3027
VMwareTray.exe             “C:\Program Files\VMware\VMware Tools\VMwareTray.exe”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Win32_Process      20110515124046.953125-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  VMwareTray.exe             C:\Program Files\VMware\VMware Tools\VMwareTray.exe                                                                   1452    102                       10156250        1413120                204800                 VMwareTray.exe             Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  42894                918852              1460        2318336        344              2318336            39337984         5840896             8         2318336           1452       3800                    69556                4480                        77012                    5                   22716              0                                   1            1718750       36569088     5.1.2600        5840896         3                    216
VMwareUser.exe             “C:\Program Files\VMware\VMware Tools\VMwareUser.exe”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Win32_Process      20110515124047.718750-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  VMwareUser.exe             C:\Program Files\VMware\VMware Tools\VMwareUser.exe                                                                   1536    156                       97812500        1413120                204800                 VMwareUser.exe             Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  25091                906686              2940        3256320        344              3260416            52867072         8343552             8         3256320           1536       4920                    85532                5712                        92964                    195                 97041              0                                   4            14843750      49721344     5.1.2600        8343552         8                    576
acrotray.exe               “C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 Win32_Process      20110515124051.000000-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  acrotray.exe               C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe                                                              1668    92                        1250000         1413120                204800                 acrotray.exe               Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  182                  3950                1075        987136         344              1019904            36884480         3960832             8         987136            1668       3160                    61964                4896                        68820                    4                   22716              0                                   2            312500        33370112     5.1.2600        3960832         3                    216
IDMan.exe                  “C:\Program Files\Internet Download Manager\IDMan.exe” /onboot                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             Win32_Process      20110515124051.296875-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  IDMan.exe                  C:\Program Files\Internet Download Manager\IDMan.exe                                                                  1688    353                       32187500        1413120                204800                 IDMan.exe                  Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  6798                 163236              9112        6774784        344              8949760            264110080        16273408            8         6774784           1688       7592                    101028               28264                       498292                   206                 10580719           0                                   4            5000000       60424192     5.1.2600        14131200        3895                 23166335
DTLite.exe                 “C:\Program Files\DAEMON Tools Lite\DTLite.exe” -autorun                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   Win32_Process      20110515124051.859375-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  DTLite.exe                 C:\Program Files\DAEMON Tools Lite\DTLite.exe                                                                         1732    129                       3906250         1413120                204800                 DTLite.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  562                  9428                2583        3096576        344              3932160            42688512         9957376             8         3096576           1732       3840                    78500                5080                        79868                    70                  25988              0                                   2            2656250       41639936     5.1.2600        9957376         36                   1928
GoogleToolbarNotifier.exe  “C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Win32_Process      20110515124052.125000-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  GoogleToolbarNotifier.exe  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe                                               1748    282                       3593750         1413120                204800                 GoogleToolbarNotifier.exe  Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  748                  17304               3759        3420160        344              3497984            56008704         6897664             8         3420160           1748       6808                    89308                9328                        90220                    124                 442156             0                                   5            1093750       51814400     5.1.2600        475136          25                   1964
Dropbox.exe                “C:\Documents and Settings\IBMADMIN\Application Data\Dropbox\bin\Dropbox.exe”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Win32_Process      20110515124053.203125-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  Dropbox.exe                C:\Documents and Settings\IBMADMIN\Application Data\Dropbox\bin\Dropbox.exe                                           1848    413                       93281250        1413120                204800                 Dropbox.exe                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  116474               5131408             89983       39178240       344              39628800           113475584        41054208            8         39178240          1848       34192                   85892                38038                       100596                   9419                44753778           0                                   16           44062500      110329856    5.1.2600        41054208        454                  109916
nmz.exe                    e:\oracle\product\11g\db1\ccr\bin\nmz.exe e:\oracle\product\11g\db1\ccr\hosts\IBMADMIN_HOST-495b58e                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Win32_Process      20110515124103.265625-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  nmz.exe                    e:\oracle\product\11g\db1\ccr\bin\nmz.exe                                                                             268     66                        7500000         1413120                204800                 nmz.exe                    Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  8880                 76010               1203        2949120        792              2949120            20013056         4177920             8         2949120           268        3824                    29188                4144                        32092                    249                 432616             0                                   2            1093750       18669568     5.1.2600        4165632         101                  3095
TNSLSNR.EXE                E:\oracle\product\11g\db1\BIN\TNSLSNR                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Win32_Process      20110515124105.015625-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  TNSLSNR.EXE                E:\oracle\product\11g\db1\BIN\TNSLSNR.exe                                                                             388     138                       26250000        1413120                204800                 TNSLSNR.EXE                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  8438                 488264              6487        23846912       792              26116096           89788416         25899008            8         23846912          388        38152                   153636               39792                       162100                   40                  98766              0                                   3            5000000       87490560     5.1.2600        25858048        2365                 259862
oracle.exe                 e:\oracle\product\11g\db1\bin\ORACLE.EXE IBMADMIN11G                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       Win32_Process      20110515124106.046875-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  oracle.exe                 e:\oracle\product\11g\db1\bin\ORACLE.EXE                                                                              488     592                       787031250       1413120                204800                 oracle.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  138191               1279160             672820      848347136      792              917495808          1145769984       487002112           8         848347136         488        56888                   409556               279056                      410140                   57377               692398492          0                                   30           994062500     1075187712   5.1.2600        464633856       28948                333704042
cmd.exe                    cmd /c “”E:\oracle\product\11g\db1\bin\emctl.bat” istart dbconsole”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Win32_Process      20110515124106.812500-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  cmd.exe                    C:\WINDOWS\system32\cmd.exe                                                                                           592     20                        625000          1413120                204800                 cmd.exe                    Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  409                  8576                437         1593344        648              1597440            12845056         1753088             8         1593344           592        1520                    22884                2072                        25524                    134                 471971             0                                   1            312500        11640832     5.1.2600        1748992         0                    0
perl.exe                   E:\oracle\product\11g\db1\\perl\bin\perl.exe E:\oracle\product\11g\db1\bin\emwd.pl dbconsole                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               Win32_Process      20110515124106.968750-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  perl.exe                   E:\oracle\product\11g\db1\perl\bin\perl.exe                                                                           612     39                        45625000        1413120                204800                 perl.exe                   Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  80258                1074152             35015       9789440        592              9801728            47575040         12550144            8         9789440           612        2704                    27996                3224                        31116                    383                 1037182            0                                   1            24218750      45969408     5.1.2600        12484608        7                    588
vmtoolsd.exe               “C:\Program Files\VMware\VMware Tools\vmtoolsd.exe”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Win32_Process      20110515124108.078125-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  vmtoolsd.exe               C:\Program Files\VMware\VMware Tools\vmtoolsd.exe                                                                     1296    289                       558593750       1413120                204800                 vmtoolsd.exe               Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  132994               7927324             45008       7852032        792              14102528           86188032         17940480            8         7852032           1296       8080                    118964               12368                       125564                   183                 119596             0                                   5            28437500      77471744     5.1.2600        10252288        181                  12580
cmd.exe                    cmd /c “E:\oracle\product\11g\db1/bin/execjavatemp.bat”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Win32_Process      20110515124108.234375-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  cmd.exe                    C:\WINDOWS\system32\cmd.exe                                                                                           1552    30                        312500          1413120                204800                 cmd.exe                    Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  167                  3650                415         1556480        612              1568768            12873728         1675264             8         1556480           1552       1440                    22940                1912                        25412                    1                   1340               0                                   1            156250        11608064     5.1.2600        1638400         5                    1405
java.exe                   E:\oracle\product\11g\db1\jdk/bin/java -server -Xmx192M -XX:MaxPermSize=200M -XX:MinHeapFreeRatio=20 -XX:MaxHeapFreeRatio=40    -DORACLE_HOME=E:\oracle\product\11g\db1 -Doracle.home=E:\oracle\product\11g\db1/oc4j -Doracle.oc4j.localhome=E:\oracle\product\11g\db1\IBMADMIN_HOST-495b58e_IBMADMIN11G/sysman -DEMSTATE=E:\oracle\product\11g\db1\IBMADMIN_HOST-495b58e_IBMADMIN11G -Doracle.j2ee.dont.use.memory.archive=true -Djava.protocol.handler.pkgs=HTTPClient -Doracle.security.jazn.config=E:\oracle\product\11g\db1/oc4j/j2ee/OC4J_DBConsole_IBMADMIN_HOST-495b58e_IBMADMIN11G/config/jazn.xml -Djava.security.policy=E:\oracle\product\11g\db1/oc4j/j2ee/OC4J_DBConsole_IBMADMIN_HOST-495b58e_IBMADMIN11G/config/java2.policy -Djavax.net.ssl.KeyStore=E:\oracle\product\11g\db1/sysman/config/OCMTrustedCerts.txt-Djava.security.properties=E:\oracle\product\11g\db1/oc4j/j2ee/home/config/jazn.security.props -DEMDROOT=E:\oracle\product\11g\db1\IBMADMIN_HOST-495b58e_IBMADMIN11G -Dsysman.md5password=true -Drepapi.oracle.home=E:\oracle\product\11g\db1 -Ddisable.checkForUpdate=true -Doracle.sysman.ccr.ocmSDK.websvc.keystore=E:\oracle\product\11g\db1/jlib/emocmclnt.ks -Dice.pilots.html4.ignoreNonGenericFonts=true -Djava.awt.headless=true -jar E:\oracle\product\11g\db1/oc4j/j2ee/home/oc4j.jar -config E:\oracle\product\11g\db1/oc4j/j2ee/OC4J_DBConsole_IBMADMIN_HOST-495b58e_IBMADMIN11G/config/server.xml  Win32_Process      20110515124108.281250-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  java.exe                   E:\oracle\product\11g\db1\jdk\bin\java.exe                      1564    1030                      467812500       1413120                204800                 java.exe                   Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  172457               17347473            136350      121335808      1552             197951488          632545280        159375360           8         121335808         1564       22088                   182644               40624                       185324                   69191               140289067          0                                   46           979687500     630493184    5.1.2600        122241024       22975                42208781
VMUpgradeHelper.exe        “C:\Program Files\VMware\VMware Tools\VMUpgradeHelper.exe” /service                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Win32_Process      20110515124109.187500-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  VMUpgradeHelper.exe        C:\Program Files\VMware\VMware Tools\VMUpgradeHelper.exe                                                              1896    105                       1250000         1413120                204800                 VMUpgradeHelper.exe        Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  158                  3406                1970        1064960        792              2224128            29126656         5378048             8         1064960           1896       3200                    45964                3760                        46372                    7                   22840              0                                   3            156250        27029504     5.1.2600        4259840         6                    300
emagent.exe                E:\oracle\product\11g\db1/bin/emagent                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Win32_Process      20110515124109.546875-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  emagent.exe                E:\oracle\product\11g\db1\bin\emagent.exe                                                                             1936    370                       265937500       1413120                204800                 emagent.exe                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  115625               6388066             37316       31272960       612              32755712           121987072        38764544            8         31272960          1936       11944                   160300               22072                       168596                   20432               579386479          0                                   7            128125000     113598464    5.1.2600        37457920        16685                5550141
alg.exe                    C:\WINDOWS\System32\alg.exe                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Win32_Process      20110515124223.051050-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  alg.exe                    C:\WINDOWS\System32\alg.exe                                                                                           1828    111                       156250          1413120                204800                 alg.exe                    Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  157                  3184                953         1232896        792              1241088            34816000         3756032             8         1232896           1828       5408                    65164                6144                        66900                    5                   22680              0                                   6            312500        34123776     5.1.2600        3756032         4                    156
IEMonitor.exe              “C:\Program Files\Internet Download Manager\IEMonitor.exe”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 Win32_Process      20110515124225.472739-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  IEMonitor.exe              C:\Program Files\Internet Download Manager\IEMonitor.exe                                                              236     104                       16406250        1413120                204800                 IEMonitor.exe              Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  185                  4496                1130        1261568        1688             1277952            39215104         4407296             8         1261568           236        3200                    69260                4760                        76892                    7                   22920              0                                   1            156250        36352000     5.1.2600        4407296         6                    432
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Win32_Process      20110515124240.627825-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               4044    1149                      839218750       1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  23685                4277530             1095751     51527680       344              83038208           231989248        117047296           8         51527680          4044       16896                   198212               49184                       255556                   110864              104268964          0                                   19           406093750     191320064    5.1.2600        69808128        84260                132676204
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=extension –lang=en-US –force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.01150D80.342774234 /prefetch:3 –ignored=” –type=renderer ”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Win32_Process      20110515124241.440263-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               3064    95                        17031250        1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  216                  6808                45738       17960960       4044             39370752           139206656        47210496            8         17960960          3064       7160                    139820               9840                        143260                   5196                6465381            0                                   4            52812500      132538368    5.1.2600        25702400        2954                 19858871
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.03D4AD80.1140885497 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Win32_Process      20110515124242.127710-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               544     93                        20625000        1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  219                  6964                118023      13557760       4044             23281664           135106560        32886784            6         13557760          544        5400                    139820               6520                        155524                   1557                494861             0                                   4            13125000      126001152    5.1.2600        23330816        2636                 231531
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.03D4A180.135252000 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Win32_Process      20110515124243.736962-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               1568    93                        34531250        1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  217                  6756                121427      14581760       4044             18034688           135135232        32063488            8         14581760          1568       5760                    139820               6840                        154676                   4621                898384             0                                   4            23125000      126623744    5.1.2600        24440832        8575                 421083
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.03D4A000.2125751902 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               Win32_Process      20110515124244.096309-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               2060    95                        136562500       1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  216                  6782                22225       16101376       4044             20574208           137326592        33529856            6         16101376          2060       6560                    139820               7680                        154660                   1676                680688             0                                   4            35937500      129728512    5.1.2600        26103808        2696                 234281
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.03E49D80.1512159009 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               Win32_Process      20110515124245.111856-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               2164    95                        10156250        1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  216                  6782                27710       19111936       4044             26902528           138317824        36651008            6         19111936          2164       7120                    139820               8200                        154660                   2193                1909800            0                                   4            14687500      130719744    5.1.2600        29093888        3281                 277394
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.03E49C00.1078948469 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               Win32_Process      20110515124245.705560-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               2408    94                        27187500        1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  219                  6938                108406      13877248       4044             18038784           133959680        32346112            6         13877248          2408       5120                    139820               6200                        154676                   3559                829187             0                                   4            20156250      125804544    5.1.2600        22740992        6615                 379340
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.03E49A80.764067024 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Win32_Process      20110515124245.830551-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               2344    94                        6250000         1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  216                  6522                22164       9547776        4044             20664320           131727360        28614656            6         9547776           2344       4840                    139820               5960                        154836                   781                 342900             0                                   4            3437500       123052032    5.1.2600        17608704        1136                 144554
cmd.exe                    “C:\WINDOWS\system32\cmd.exe”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Win32_Process      20110515124448.638878-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  cmd.exe                    C:\WINDOWS\system32\cmd.exe                                                                                           948     58                        5000000         1413120                204800                 cmd.exe                    Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  2613                 41736               1753        2289664        344              2322432            37552128         4845568             8         2289664           948        2640                    63796                4384                        71732                    7                   22920              0                                   1            937500        33579008     5.1.2600        172032          6                    432
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.03E49600.279947849 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Win32_Process      20110515125859.489493-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               3060    93                        72187500        1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  218                  6756                50996       24600576       4044             37511168           145731584        47255552            6         24600576          3060       6520                    139820               7680                        154676                   2185                478640             0                                   4            43281250      136572928    5.1.2600        35229696        3336                 353417
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.038DA900.505266925 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Win32_Process      20110515130202.115984-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               2748    97                        161250000       1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  218                  6860                263554      35753984       4044             57389056           160116736        64704512            8         35753984          2748       10320                   139820               12760                       157140                   7930                4398035            0                                   4            94843750      147812352    5.1.2600        46559232        12901                2047015
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.0649F480.281779159 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Win32_Process      20110515130321.707366-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               1768    94                        5312500         1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  216                  6730                20035       9551872        4044             20283392           131727360        27856896            6         9551872           1768       4840                    139820               5960                        154676                   564                 331624             0                                   4            2656250       123052032    5.1.2600        17829888        856                  141538
wordpad.exe                “C:\Program Files\Windows NT\Accessories\WORDPAD.EXE”  “C:\WindowsScripts\Scriptomatic\Write WMI Scripts Like the Pros.doc”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Win32_Process      20110515130458.944606-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  wordpad.exe                C:\Program Files\Windows NT\Accessories\WORDPAD.EXE                                                                   684     129                       90000000        1413120                204800                 wordpad.exe                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  984                  11030               4176        2744320        344              3051520            52625408         8204288             8         2744320           684        3960                    92948                5280                        94316                    25                  23549              0                                   2            18906250      51646464     5.1.2600        1597440         20                   47752
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.01150A80.1218345854 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               Win32_Process      20110515130642.109698-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               1716    96                        92656250        1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  221                  7016                376109      35373056       4044             63049728           159739904        71397376            8         35373056          1716       9520                    140900               11640                       155756                   11305               4155762            0                                   4            189375000     148287488    5.1.2600        46297088        18966                2430416
cmd.exe                    “C:\WINDOWS\system32\cmd.exe” /k cscript.exe temp_script.vbs                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               Win32_Process      20110515131214.583881-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  cmd.exe                    C:\WINDOWS\system32\cmd.exe                                                                                           1772    59                        2968750         1413120                204800                 cmd.exe                    Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  418                  7470                1675        2293760        312              2326528            37552128         3739648             8         2293760           1772       2640                    63796                4384                        71732                    7                   22920              0                                   1            1250000       33579008     5.1.2600        3653632         6                    432
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.06E73A80.2062994182 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               Win32_Process      20110515131627.659801-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               3584    93                        13125000        1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  216                  6730                58956       17326080       4044             30453760           139149312        38465536            6         17326080          3584       6480                    139820               7840                        154676                   2229                1116756            0                                   4            16562500      129667072    5.1.2600        27271168        3700                 280054
firefox.exe                “C:\Program Files\Mozilla Firefox\firefox.exe”                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             Win32_Process      20110515141445.544836-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  firefox.exe                C:\Program Files\Mozilla Firefox\firefox.exe                                                                          2896    412                       1342500000      1413120                204800                 firefox.exe                Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  31595                2114466             1407800     155848704      3528             185180160          319811584        200921088           8         155848704         2896       31904                   158412               50664                       194468                   5586                53750752           0                                   35           2266875000    292749312    5.1.2600        171573248       20002                316620109
plugin-container.exe       “C:\Program Files\Mozilla Firefox\plugin-container.exe” –channel=2896.70ed400.2786316 “C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll” – -omnijar C:\Program Files\Mozilla Firefox\omni.jar 2896 \\.\pipe\gecko-crash-server-pipe.2896 plugin                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             Win32_Process      20110515141447.013558-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  plugin-container.exe       C:\Program Files\Mozilla Firefox\plugin-container.exe                                                                 496     194                       1445000000      1413120                204800                 plugin-container.exe       Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  1209                 67292               41196       25272320       2896             57888768           134103040        71671808            8         25272320          496        6880                    126580               8096                        156844                   793                 488212             0                                   9            294375000     116965376    5.1.2600        30142464        578                  287524
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.063BCC00.446176632 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Win32_Process      20110515141858.581513-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               2880    93                        7968750         1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  218                  6730                63727       13643776       4044             24670208           134950912        34131968            6         13643776          2880       5480                    139820               6600                        154676                   568                 415464             0                                   4            5156250       126177280    5.1.2600        23617536        865                  176683
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.064A1A80.486614871 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Win32_Process      20110515141910.753232-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               4016    92                        17343750        1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  218                  6730                109261      10301440       4044             21827584           132268032        31363072            6         10301440          4016       4880                    139820               6000                        154676                   892                 351856             0                                   4            5000000       123183104    5.1.2600        19791872        1504                 183847
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.064A1780.1622902321 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               Win32_Process      20110515142251.997464-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               1548    93                        5312500         1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  218                  6730                25351       13144064       4044             24645632           134905856        33804288            6         13144064          1548       5400                    139820               6520                        154676                   640                 421292             0                                   4            6250000       126001152    5.1.2600        22773760        985                  179309
chrome.exe                 “C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe” –type=renderer –lang=en-US –force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ –channel=4044.064A1300.249827419 /prefetch:3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Win32_Process      20110515142254.903714-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  chrome.exe                 C:\Documents and Settings\IBMADMIN\Local Settings\Application Data\Google\Chrome\Application\chrome.exe               3276    97                        54062500        1413120                204800                 chrome.exe                 Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  216                  6730                138856      16830464       4044             27385856           137773056        36712448            6         16830464          3276       5920                    139820               7040                        154676                   7284                1074436            0                                   4            69062500      129245184    5.1.2600        27324416        13241                650423
wmic.exe                   wmic                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       Win32_Process      20110515175703.175901-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  wmic.exe                   C:\WINDOWS\System32\Wbem\wmic.exe                                                                                     3620    191                       3125000         1413120                204800                 wmic.exe                   Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  335                  4250                25930       12476416       1772             26501120           97402880         31776768            8         12476416          3620       6160                    88948                6720                        89228                    47                  32484              0                                   4            5625000       90390528     5.1.2600        17784832        7                    532
wmiprvse.exe               C:\WINDOWS\system32\wbem\wmiprvse.exe                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Win32_Process      20110515180238.720817-240  Win32_ComputerSystem  IBMADMIN_HOST-495B58E  wmiprvse.exe               C:\WINDOWS\system32\wbem\wmiprvse.exe                                                                                 308     150                       1093750         1413120                204800                 wmiprvse.exe               Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  322                  5788                2030        2293760        980              3244032            42696704         7159808             8         2293760           308        5144                    75156                8488                        75684                    25                  272865             0                                   6            468750        41099264     5.1.2600        6602752         23                   1644

wmic:root\cli>

wmic:root\cli>cpu
AddressWidth  Architecture  Availability  Caption                             ConfigManagerErrorCode  ConfigManagerUserConfig  CpuStatus  CreationClassName  CurrentClockSpeed  CurrentVoltage  DataWidth  Description                         DeviceID  ErrorCleared  ErrorDescription  ExtClock  Family  InstallDate  L2CacheSize  L2CacheSpeed  L3CacheSize  L3CacheSpeed  LastErrorCode  Level  LoadPercentage  Manufacturer  MaxClockSpeed  Name                                NumberOfCores  NumberOfLogicalProcessors  OtherFamilyDescription  PNPDeviceID  PowerManagementCapabilities  PowerManagementSupported  ProcessorId       ProcessorType  Revision  Role  SocketDesignation  Status  StatusInfo  Stepping  SystemCreationClassName  SystemName  UniqueId  UpgradeMethod  Version              VoltageCaps
64            9             3             AMD64 Family 16 Model 4 Stepping 3                                                   1          Win32_Processor    2800               15              64         AMD64 Family 16 Model 4 Stepping 3  CPU0                                      200       236                  2048                       6144         0                            16     4               AuthenticAMD  2800           AMD Phenom(tm) II X4 830 Processor  4              4                                                                                            FALSE                     178BFBFF00100F43  3              1027      CPU   CPU 1              OK      3           3         Win32_ComputerSystem     IBMADMIN-PC              1            Model 4, Stepping 3

wmic:root\cli>
wmic:root\cli>memphysical
Caption                CreationClassName          Depth  Description            Height  HotSwappable  InstallDate  Location  Manufacturer  MaxCapacity  MemoryDevices  MemoryErrorCorrection  Model  Name                   OtherIdentifyingInfo  PartNumber  PoweredOn  Removable  Replaceable  SerialNumber  SKU  Status  Tag                      Use  Version  Weight  Width
Physical Memory Array  Win32_PhysicalMemoryArray         Physical Memory Array                                     3                       16777216     4              3                             Physical Memory Array                                                                                                  Physical Memory Array 0  3

wmic:root\cli>memphysical
Caption                CreationClassName          Depth  Description            Height  HotSwappable  InstallDate  Location  Manufacturer  MaxCapacity  MemoryDevices  MemoryErrorCorrection  Model  Name                   OtherIdentifyingInfo  PartNumber  PoweredOn  Removable  Replaceable  SerialNumber  SKU  Status  Tag                      Use  Version  Weight  Width
Physical Memory Array  Win32_PhysicalMemoryArray         Physical Memory Array                                     3                       268435456    15             3                             Physical Memory Array                                                                                                  Physical Memory Array 0  3
wmic:root\cli>memlogical
AvailableVirtualMemory  Caption                       Description                   Name                        SettingID                   TotalPageFileSpace  TotalPhysicalMemory  TotalVirtualMemory
425268                  Logical Memory Configuration  Logical Memory Configuration  LogicalMemoryConfiguration  LogicalMemoryConfiguration  5075724             3145192              4026612

The above WMIC command help us to understand the Windows current process and the memory details about the system.

Utility Command

If you want to run the WMIC command in the scripts or run it as a single command, then we can use the following methods.

To extract the running process details, we need to use the following command

WMIC SERVICE where state=”Running” GET > services.tsv

To know about the running chrome browser details, then we need to run the following commands.

WMIC PROCESS where name=’chrome.exe’ GET > chrome_process.tsv

In many times middleware administrators need to know about the running application server java process id. This is the tricky part in our administration in the Windows servers. The following command gives the process id and other details about the java process from that we can identify which process we need to kill.

C:\Documents and Settings\IBMADMIN>WMIC PROCESS where name=”java.exe”

Caption   CommandLine                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                CreationClassName  CreationDate               CSCreationClassName   CSName           Description  ExecutablePath                              ExecutionState  Handle  HandleCount  InstallDate  KernelModeTime  MaximumWorkingSetSize  MinimumWorkingSetSize  Name      OSCreationClassName    OSName                                                                     OtherOperationCount  OtherTransferCount  PageFaults  PageFileUsage  ParentProcessId  PeakPageFileUsage  PeakVirtualSize  PeakWorkingSetSize  Priority  PrivatePageCount  ProcessId  QuotaNonPagedPoolUsage  QuotaPagedPoolUsage  QuotaPeakNonPagedPoolUsage  QuotaPeakPagedPoolUsage  ReadOperationCount  ReadTransferCount  SessionId  Status  TerminationDate  ThreadCount  UserModeTime  VirtualSize  WindowsVersion  WorkingSetSize  WriteOperationCount  WriteTransferCount
java.exe  E:\oracle\product\11g\db1\jdk/bin/java -server -Xmx192M -XX:MaxPermSize=200M -XX:MinHeapFreeRatio=20 -XX:MaxHeapFreeRatio=40    -DORACLE_HOME=E:\oracle\product\11g\db1 -Doracle.home=E:\oracle\product\11g\db1/oc4j -Doracle.oc4j.localhome=E:\oracle\product\11g\db1\IBMADMIN-PC-495b58e_IBMADMIN11G/sysman -DEMSTATE=E:\oracle\product\11g\db1\IBMADMIN-PC-495b58e_IBMADMIN11G -Doracle.j2ee.dont.use.memory.archive=true -Djava.protocol.handler.pkgs=HTTPClient -Doracle.security.jazn.config=E:\oracle\product\11g\db1/oc4j/j2ee/OC4J_DBConsole_IBMADMIN-PC-495b58e_IBMADMIN11G/config/jazn.xml -Djava.security.policy=E:\oracle\product\11g\db1/oc4j/j2ee/OC4J_DBConsole_IBMADMIN-PC-495b58e_IBMADMIN11G/config/java2.policy -Djavax.net.ssl.KeyStore=E:\oracle\product\11g\db1/sysman/config/OCMTrustedCerts.txt-Djava.security.properties=E:\oracle\product\11g\db1/oc4j/j2ee/home/config/jazn.security.props -DEMDROOT=E:\oracle\product\11g\db1\IBMADMIN-PC-495b58e_IBMADMIN11G -Dsysman.md5password=true -Drepapi.oracle.home=E:\oracle\product\11g\db1 -Ddisable.checkForUpdate=true -Doracle.sysman.ccr.ocmSDK.websvc.keystore=E:\oracle\product\11g\db1/jlib/emocmclnt.ks -Dice.pilots.html4.ignoreNonGenericFonts=true -Djava.awt.headless=true -jar E:\oracle\product\11g\db1/oc4j/j2ee/home/oc4j.jar -config E:\oracle\product\11g\db1/oc4j/j2ee/OC4J_DBConsole_IBMADMIN-PC-495b58e_IBMADMIN11G/config/server.xml  Win32_Process      20110515124108.281250-240  Win32_ComputerSystem  IBMADMIN-PC-495B58E  java.exe     E:\oracle\product\11g\db1\jdk\bin\java.exe                  1564    1035                      526093750       1413120                204800                 java.exe  Win32_OperatingSystem  Microsoft Windows XP Professional|C:\WINDOWS|\Device\Harddisk0\Partition1  190751               19407207            138565      120147968      1552             197951488          632545280        159375360           8         120147968         1564       23152                   183140               40624                       185324                   71804               152462176          0                                   45           1084531250    630231040    5.1.2600        123162624       25798                47438207

We can redirect the outputs to the file from where we can read the file output.

WMIC SERVICE where state=”Running” GET > services.tsv

WMIC PROCESS where name=’chrome.exe’ GET > chrome_process.tsv

WMIC PROCESS where name=”java.exe” GET > java_process.tsv

Note:  Copy and paste the following output into Notepad++ for the clear formatting as it shown here as wrapped format.

There is an excellent utility which will help us to understand the WMIC scripting and to extract the details about the WMIC commands. That is

Scriptomatic Utility

We can find the scriptomatic utility from the following link

http://www.microsoft.com/downloads/en/details.aspx?familyid=9ef05cbd-c1c5-41e7-9da8-212c414a7ab0&displaylang=en

Ref Link:

http://technet.microsoft.com/en-us/library/bb742610.aspx

http://msdn.microsoft.com/en-us/library/aa394531(v=vs.85).aspx

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

Categories

%d bloggers like this: