呵呵,最近看了一个很牛逼的命令wmic,希望这些命令对你有帮助======对进程的管理========== 结束一个进程(可根据进程对应的PID) wmic process where name="notepad.exe" delete wmic process where name="notepad.exe" terminate wmic process where pid="123" delete wmic path win32_process where "name='notepad.exe'" delete创建一个进程 wmic process call create "c:\windows\system32\calc.exe"查询进程的启动路径(将得到的信息输出) wmic process get name,executablepath,processid wmic /output:c:\process.html process get processid,name,executablepath /format:htable.xsl查询指定进程的信息 wmic process where name="notepad.exe" get name,executablepath,processid在远程计算上创建进程 wmic /node:192.168.8.10 /user:administrator /password:xiongyefeng process call create "c:\windows\notepad.exe"查询远程计算机上的进程列表 wmic /node:192.168.8.10 /user:administrator /password:xiongyefeng process get name,executablepath,processid将获得到的远程计算机进程列表保存到本地wmic /output:c:\process.html /node:192.168.8.10 /user:administrator /password:xiongyefeng process get processid,name,executablepath /format:htable.xsl结束远程计算上的指定进程 wmic /node:192.168.8.10 /user:administrator /password:xiongyefeng process where name="notepad.exe" delete重启远程计算机 wmic /node:192.168.8.10 /user:administrator /password:xiongyefeng process call create "shutdown -r -f"关闭远程计算机 wmic /node:192.168.8.10 /user:administrator /password:xiongyefeng process call create "shutdown -s -f"高级应用:结束可疑的进程 wmic process where "name='explorer.exe' and executablepath <> '%systemdrive%\\windows\\explorer.exe'" delete wmic process where "name='svchost.exe' and executablepath <> '%systemdrive%\\windows\\system32\\svchost.exe'" call terminate======对磁盘的管理======== 查看磁盘的属性 wmic logicaldisk list brief根据磁盘的类型查看相关属性 wmic logicaldisk where drivetype=3 list brief使用get参数来获得自己想要参看的属性 wmic logicaldisk where drivetype=3 get deviceid,size,freespace,description,filesystem只显示c盘的相关信息 wmic logicaldisk where name="c:" get deviceid,size,freespace,description,filesystem更改卷标的名称 wmic logicaldisk where name="c:" set volumename=lsxq获得U盘的盘符号 wmic logicaldisk where drivetype='2' get deviceid,description
不过获取磁盘利用率一般需要私有mib.2、开通telnet,通过远程登录后,执行script来获取
否则没法获得,自己写个服务接口,随时提供这几个参数的值。
SNMP对UNIX主机往往是有的,而windows一般是默认没有的。
结束一个进程(可根据进程对应的PID)
wmic process where name="notepad.exe" delete
wmic process where name="notepad.exe" terminate
wmic process where pid="123" delete
wmic path win32_process where "name='notepad.exe'" delete创建一个进程
wmic process call create "c:\windows\system32\calc.exe"查询进程的启动路径(将得到的信息输出)
wmic process get name,executablepath,processid
wmic /output:c:\process.html process get processid,name,executablepath /format:htable.xsl查询指定进程的信息
wmic process where name="notepad.exe" get name,executablepath,processid在远程计算上创建进程
wmic /node:192.168.8.10 /user:administrator /password:xiongyefeng process call create "c:\windows\notepad.exe"查询远程计算机上的进程列表
wmic /node:192.168.8.10 /user:administrator /password:xiongyefeng process get name,executablepath,processid将获得到的远程计算机进程列表保存到本地wmic /output:c:\process.html /node:192.168.8.10 /user:administrator /password:xiongyefeng process get processid,name,executablepath /format:htable.xsl结束远程计算上的指定进程
wmic /node:192.168.8.10 /user:administrator /password:xiongyefeng process where name="notepad.exe" delete重启远程计算机
wmic /node:192.168.8.10 /user:administrator /password:xiongyefeng process call create "shutdown -r -f"关闭远程计算机
wmic /node:192.168.8.10 /user:administrator /password:xiongyefeng process call create "shutdown -s -f"高级应用:结束可疑的进程
wmic process where "name='explorer.exe' and executablepath <> '%systemdrive%\\windows\\explorer.exe'" delete
wmic process where "name='svchost.exe' and executablepath <> '%systemdrive%\\windows\\system32\\svchost.exe'" call terminate======对磁盘的管理========
查看磁盘的属性
wmic logicaldisk list brief根据磁盘的类型查看相关属性
wmic logicaldisk where drivetype=3 list brief使用get参数来获得自己想要参看的属性
wmic logicaldisk where drivetype=3 get deviceid,size,freespace,description,filesystem只显示c盘的相关信息
wmic logicaldisk where name="c:" get deviceid,size,freespace,description,filesystem更改卷标的名称
wmic logicaldisk where name="c:" set volumename=lsxq获得U盘的盘符号
wmic logicaldisk where drivetype='2' get deviceid,description
r.exec("cmd /c "+上面的命令即可);