排查监听进程及父进程命令记录
netstat -ano |findstr ESTABLISHED

wmic process where processid=XXXX get parentprocessid,name,executablepath,commandline

netstat -ano |findstr ESTABLISHED

wmic process where processid=XXXX get parentprocessid,name,executablepath,commandline
