wmic process where Caption="DingTalk.exe" get Caption,ParentProcessId,ProcessId
Caption ParentProcessId ProcessId
DingTalk.exe 18452 16408
DingTalk.exe 16408 20460
DingTalk.exe 16408 21056
DingTalk.exe 16408 22084
DingTalk.exe 16408 22136
DingTalk.exe 16408 21788
DingTalk.exe 16408 14292
DingTalk.exe 16408 16652
wmic process where "COMMANDLINE LIKE '%DingTalk.exe%'" get Caption,ParentProcessId,ProcessId
wmic process where "ProcessID=44108" get CommandLine, ExecutablePath
kill 隐藏的子进程
WMIC PROCESS WHERE "COMMANDLINE LIKE '%DingTalk.exe%'" CALL TERMINATE