[명령어] tasklist - 명령어로 프로세스 확인하기
아래 /V 옵션은 자세한 내용을 모두 보여 준다. /SVC 옵션은 관련 서비스를 보여준다.
C:\>tasklist /V
이미지 이름 PID 세션 이름 세션# 메모리 사용 상태 사용자 이름 CPU 시간 창 제목
========================= ======== ================ =========== ============ =============== ================================================== ============ ========================================================================
System Idle Process 0 Services 0 24 K Unknown NT AUTHORITY\SYSTEM 33:19:22 N/A
System 4 Services 0 1,024 K Unknown N/A 0:04:40 N/A
smss.exe 316 Services 0 200 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
csrss.exe 444 Services 0 2,164 K Unknown NT AUTHORITY\SYSTEM 0:00:03 N/A
csrss.exe 500 Console 1 28,796 K Running NT AUTHORITY\SYSTEM 0:01:00 N/A
wininit.exe 508 Services 0 644 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
winlogon.exe 568 Console 1 2,336 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
services.exe 620 Services 0 4,420 K Unknown NT AUTHORITY\SYSTEM 0:00:07 N/A
lsass.exe 628 Services 0 5,484 K Unknown NT AUTHORITY\SYSTEM 0:00:11 N/A
lsm.exe 636 Services 0 1,760 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 736 Services 0 3,860 K Unknown NT AUTHORITY\SYSTEM 0:00:39 N/A
svchost.exe 812 Services 0 4,704 K Unknown NT AUTHORITY\NETWORK SERVICE 0:00:04 N/A
svchost.exe 912 Services 0 8,676 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:04 N/A
svchost.exe 956 Services 0 33,012 K Unknown NT AUTHORITY\SYSTEM 0:01:07 N/A
svchost.exe 984 Services 0 23,388 K Unknown NT AUTHORITY\SYSTEM 0:00:50 N/A
svchost.exe 1196 Services 0 6,404 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:04 N/A
svchost.exe 1300 Services 0 8,008 K Unknown NT AUTHORITY\NETWORK SERVICE 0:00:06 N/A
spoolsv.exe 1428 Services 0 5,704 K Unknown NT AUTHORITY\SYSTEM 0:00:01 N/A
svchost.exe 1468 Services 0 5,176 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:03 N/A
armsvc.exe 1568 Services 0 792 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 1592 Services 0 1,776 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 1620 Services 0 40,936 K Unknown NT AUTHORITY\LOCAL SERVICE 0:01:53 N/A
HPLaserJetService.exe 1680 Services 0 4,100 K Unknown NT AUTHORITY\SYSTEM 0:02:01 N/A
svchost.exe 1764 Services 0 3,852 K Unknown NT AUTHORITY\SYSTEM 0:00:01 N/A
inetinfo.exe 1784 Services 0 2,444 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
kcdregsvc.exe 1812 Services 0 752 K Unknown NT AUTHORITY\SYSTEM 0:00:01 N/A
mskcd.exe 1836 Services 0 540 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 1856 Services 0 880 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1876 Console 1 696 K Running NT AUTHORITY\SYSTEM 0:00:00 _zprodady
SMSvcHost.exe 1896 Services 0 4,148 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:02 N/A
kcdsvc.exe 1936 Console 1 9,216 K Running N/A 0:00:18 DelayedWnd
kcdsaclt.exe 1956 Console 1 4,232 K Running N/A 0:00:04 Guard-Z Client
ksuchost.exe 1964 Console 1 856 K Running NT AUTHORITY\SYSTEM 0:00:00 _zpromomy
npkcmsvc.exe 796 Services 0 900 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
npstartersvc.exe 1236 Services 0 1,156 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
PaSvc.exe 1932 Services 0 4,268 K Unknown NT AUTHORITY\SYSTEM 0:00:27 N/A
svchost.exe 2092 Services 0 960 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
RegSrvc.exe 2112 Services 0 876 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
npnj5Agent.exe 2120 Console 1 6,280 K Running NT AUTHORITY\SYSTEM 0:01:13 npnj5Agent
svchost.exe 2164 Services 0 1,848 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
V3Svc.exe 2200 Services 0 712 K Unknown NT AUTHORITY\SYSTEM 0:00:06 N/A
svchost.exe 2236 Services 0 1,856 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
EvtEng.exe 2340 Services 0 4,244 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2932 Services 0 1,096 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 2976 Services 0 1,060 K Unknown NT AUTHORITY\NETWORK SERVICE 0:00:00 N/A
unsecapp.exe 3712 Services 0 1,268 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
WmiPrvSE.exe 3804 Services 0 4,816 K Unknown NT AUTHORITY\SYSTEM 0:00:07 N/A
tsmclt.exe 3944 Console 1 3,852 K Running NT AUTHORITY\SYSTEM 0:00:00 _tsmclt
taskhost.exe 4080 Console 1 5,812 K Running aaaa\bbbb 0:00:01 MCI command handling window
dwm.exe 3188 Console 1 2,840 K Running aaaa\bbbb 0:00:46 DWM Notification Window
explorer.exe 3256 Console 1 67,736 K Running aaaa\bbbb 0:01:21 N/A
AmIcoSinglun.exe 3928 Console 1 1,788 K Running aaaa\bbbb 0:00:00 AmIcoSinglun
VM331_STI.EXE 3936 Console 1 1,568 K Running aaaa\bbbb 0:00:02 VMStillMnt
RtHDVCpl.exe 4056 Console 1 2,000 K Running aaaa\bbbb 0:00:00 Realtek HD Audio CPL for Vista
SynTPEnh.exe 4060 Console 1 4,844 K Running aaaa\bbbb 0:00:24 TouchPad object helper window
YCMMirage.exe 4036 Console 1 2,640 K Running aaaa\bbbb 0:00:00 {94F11419-869E-47aa-9563-F48591285CAD}
YouCam.exe 2824 Console 1 2,428 K Running aaaa\bbbb 0:00:00 N/A
SynTPHelper.exe 3184 Console 1 976 K Running aaaa\bbbb 0:00:00 N/A
HotKey.exe 3276 Console 1 4,400 K Running aaaa\bbbb 0:00:00 N/A
concentr.exe 3992 Console 1 2,400 K Running aaaa\bbbb 0:00:00 Citrix 연결 센터
kcdsaUI.exe 3652 Console 1 1,660 K Running aaaa\bbbb 0:00:00 Guard-Z UserInterface
hkcmd.exe 3120 Console 1 1,912 K Running aaaa\bbbb 0:00:00 N/A
igfxpers.exe 900 Console 1 4,396 K Running aaaa\bbbb 0:00:00
C:\>tasklist
이미지 이름 PID 세션 이름 세션# 메모리 사용
========================= ======== ================ =========== ============
System Idle Process 0 Services 0 24 K
System 4 Services 0 1,024 K
smss.exe 316 Services 0 200 K
csrss.exe 444 Services 0 2,164 K
csrss.exe 500 Console 1 28,788 K
wininit.exe 508 Services 0 644 K
winlogon.exe 568 Console 1 2,336 K
services.exe 620 Services 0 4,404 K
lsass.exe 628 Services 0 5,484 K
lsm.exe 636 Services 0 1,736 K
svchost.exe 736 Services 0 3,876 K
svchost.exe 812 Services 0 4,708 K
svchost.exe 912 Services 0 8,744 K
svchost.exe 956 Services 0 32,968 K
svchost.exe 984 Services 0 23,244 K
svchost.exe 1196 Services 0 6,384 K
svchost.exe 1300 Services 0 8,012 K
spoolsv.exe 1428 Services 0 5,676 K
svchost.exe 1468 Services 0 5,136 K
armsvc.exe 1568 Services 0 792 K
svchost.exe 1592 Services 0 1,776 K
svchost.exe 1620 Services 0 40,860 K
HPLaserJetService.exe 1680 Services 0 4,948 K
svchost.exe 1764 Services 0 3,852 K
inetinfo.exe 1784 Services 0 2,444 K
kcdregsvc.exe 1812 Services 0 752 K
mskcd.exe 1836 Services 0 540 K
svchost.exe 1856 Services 0 880 K
svchost.exe 1876 Console 1 696 K
SMSvcHost.exe 1896 Services 0 4,148 K
kcdsvc.exe 1936 Console 1 9,216 K
kcdsaclt.exe 1956 Console 1 4,232 K
ksuchost.exe 1964 Console 1 856 K
npkcmsvc.exe 796 Services 0 900 K
npstartersvc.exe 1236 Services 0 1,156 K
PaSvc.exe 1932 Services 0 4,268 K
svchost.exe 2092 Services 0 960 K
RegSrvc.exe 2112 Services 0 876 K
npnj5Agent.exe 2120 Console 1 6,280 K
svchost.exe 2164 Services 0 1,848 K
V3Svc.exe 2200 Services 0 876 K
svchost.exe 2236 Services 0 1,856 K
EvtEng.exe 2340 Services 0 4,244 K
svchost.exe 2932 Services 0 1,096 K
svchost.exe 2976 Services 0 1,060 K
unsecapp.exe 3712 Services 0 1,268 K
WmiPrvSE.exe 3804 Services 0 4,816 K
tsmclt.exe 3944 Console 1 3,848 K
taskhost.exe 4080 Console 1 5,804 K
dwm.exe 3188 Console 1 2,840 K
explorer.exe 3256 Console 1 67,404 K
AmIcoSinglun.exe 3928 Console 1 1,788 K
VM331_STI.EXE 3936 Console 1 1,568 K
RtHDVCpl.exe 4056 Console 1 2,000 K
SynTPEnh.exe 4060 Console 1 4,844 K
YCMMirage.exe 4036 Console 1 2,640 K
YouCam.exe 2824 Console 1 2,428 K
SynTPHelper.exe 3184 Console 1 976 K
HotKey.exe 3276 Console 1 4,400 K
concentr.exe 3992 Console 1 2,400 K
kcdsaUI.exe 3652 Console 1 1,660 K
hkcmd.exe 3120 Console 1 1,912 K
igfxpers.exe 900 Console 1 4,396 K
wfcrun32.exe 4232 Console 1 4,932 K
HPTLBXFX.exe 4348 Console 1 6,940 K
hppfaxprintersrv.exe 4436 Console 1 1,816 K
iMessengerUC.exe 4588 Console 1 38,644 K
V3SP.exe 4628 Console 1 980 K
SearchIndexer.exe 4644 Services 0 41,368 K
sidebar.exe 4656 Console 1 29,032 K
wmpnetwk.exe 4912 Services 0 9,008 K
PresentationFontCache.exe 5276 Services 0 2,964 K
iexplore.exe 5284 Console 1 37,576 K
eXtremeSMS.exe 5076 Console 1 8,172 K
LMS.exe 5752 Services 0 1,644 K
svchost.exe 3516 Services 0 22,068 K
UNS.exe 2988 Services 0 2,684 K
LGCNS.SBC.UI.MAIN.exe 6100 Console 1 29,996 K
OUTLOOK.EXE 832 Console 1 110,656 K
CDViewer.exe 1868 Console 1 25,412 K
wfica32.exe 4840 Console 1 41,252 K
netterm.exe 2004 Console 1 7,048 K
cmd.exe 5388 Console 1 824 K
conhost.exe 4372 Console 1 4,380 K
javaw.exe 3828 Console 1 34,348 K
RDCMan.exe 5040 Console 1 54,544 K
notepad.exe 6844 Console 1 4,316 K
iexplore.exe 2744 Console 1 304,312 K
WUDFHost.exe 7024 Services 0 5,208 K
iexplore.exe 7892 Console 1 206,264 K
EXCEL.EXE 5028 Console 1 57,428 K
iexplore.exe 7236 Console 1 125,044 K
cmd.exe 7484 Console 1 2,764 K
conhost.exe 6596 Console 1 7,652 K
audiodg.exe 6456 Services 0 13,640 K
SearchProtocolHost.exe 7664 Console 1 6,232 K
SearchFilterHost.exe 8120 Services 0 3,812 K
tasklist.exe 4284 Console 1 4,736 K
WmiPrvSE.exe 2016 Services 0 5,188 K
C:\>tasklist /?
TASKLIST [/S 시스템 [/U 사용자 이름 [/P [암호]]]]
[/M [모듈] | /SVC | /V] [/FI 필터] [/FO 형식] [/NH]
설명:
이 도구는 로컬 또는 원격 시스템에서 현재
실행되고 있는 프로세스 목록을 표시합니다.
매개 변수 목록:
/S 시스템 연결할 원격 시스템을 지정합니다.
/U [도메인\]사용자 명령을 실행해야 하는 사용자 컨텍스트를
지정합니다.
/P [암호] 해당 사용자 컨텍스트의 암호를 지정합니다.
생략한 경우에는 물어봅니다.
/M [모듈] 해당 exe/dll 이름을 사용하는 모든 작업을
나열합니다. 모듈 이름을 지정하지 않으면
로드된 모든 작업을 나열합니다.
/SVC 각 프로세스에 호스트된 서비스를 표시합니다.
/V 자세한 작업 정보를 표시합니다.
/FI 필터 필터에서 지정한 조건과 일치하는
작업 집합을 표시합니다.
/FO 형식 출력 형식을 지정합니다.
사용할 수 있는 값: "TABLE", "LIST", "CSV".
/NH 출력에 표시하지 않을 "열 머리글"을
지정합니다.
"TABLE"과 "CSV" 형식에서만 사용할 수 있습니다.
/? 이 도움말 메시지를 표시합니다.
필터:
필터 이름 유효한 연산자 유효한 값
----------- --------------- --------------------------
STATUS eq, ne RUNNING |
NOT RESPONDING | UNKNOWN
IMAGENAME eq, ne 이미지 이름
PID eq, ne, gt, lt, ge, le PID 값
SESSION eq, ne, gt, lt, ge, le 세션 번호
SESSIONNAME eq, ne 세션 이름
CPUTIME eq, ne, gt, lt, ge, le CPU 시간
(hh:mm:ss 형식)
hh - 시간,
mm - 분, ss - 초
MEMUSAGE eq, ne, gt, lt, ge, le 메모리 사용(KB)
USERNAME eq, ne 사용자 이름([domain\]user
형식)
SERVICES eq, ne 서비스 이름
WINDOWTITLE eq, ne 창 제목
MODULES eq, ne DLL 이름
참고: 원격 컴퓨터를 쿼리할 때 "WINDOWTITLE" 및 "STATUS" 필터는
지원되지 않습니다.
예:
TASKLIST
TASKLIST /M
TASKLIST /V /FO CSV
TASKLIST /SVC /FO LIST
TASKLIST /M wbem*
TASKLIST /S 시스템 /FO LIST
TASKLIST /S 시스템 /U domain\username /FO CSV /NH
TASKLIST /S 시스템 /U 사용자 이름 /P 암호 /FO TABLE /NH
TASKLIST /FI "USERNAME ne NT AUTHORITY\SYSTEM" /FI "STATUS eq running"