Edit C:\Windows\SysWOW64\tasklist.exe
MZ? ÿÿ ¸ @ ð º ´ Í!¸LÍ!This program cannot be run in DOS mode. $ uû^W1?01?01?0ìeÿ3?0ìeý2?0ìeþ&?0ìeû.?01?1÷?0ìeã!?0ìeù0?0ìeü0?0Rich1?0 PE L ÌBPT à 6 `ð @ p p× @Á 3 @ P ` à p 8 \ 0 .text ø `.data Ô @ À.idata 0 @ @.rsrc P " @ @.reloc à ` , @ B `î@ ?í@ 0ó@ ?5 @6 ðP `c 0d pe @? p? Ð? ?í `î `ð pð ?ð ñ àò 0ó ô ö Ðö P÷ ÌBPT % ? ? ?ð@ p A À A = À F À F\ / @?@ : W i n s t a . d l l WinStationFreeMemory WinStationCloseServer WinStationOpenServerW WinStationFreeGAPMemory WinStationGetAllProcesses WinStationNameFromLogonIdW WinStationEnumerateProcesses S e D e b u g P r i v i l e g e PARSER2 ? s u p f i f o n h v s v c m a p p s * S E L E C T _ _ P A T H , P r o c e s s I d , C S N a m e , C a p t i o n , S e s s i o n I d , T h r e a d C o u n t , W o r k i n g S e t S i z e , K e r n e l M o d e T i m e , U s e r M o d e T i m e F R O M W i n 3 2 _ P r o c e s s W H E R E P r o c e s s I d % s % s % s % d S e s s i o n I d C a p t i o n % s % s % s ' % s ' W o r k i n g S e t S i z e % s % s % s % l u A N D _ _ P A T H C S N a m e ( ) % s \ % s G e t O w n e r D o m a i n U s e r @ K e r n e l M o d e T i m e U s e r M o d e T i m e % d % s % 0 2 d % s % 0 2 d % d S E L E C T N a m e F R O M W i n 3 2 _ S e r v i c e W H E R E P r o c e s s I d = % d a n d S t a t e = "