TopNet247Independent notes for Windows admins

How-to · Server & Workstation Triage

Find and end a hung process on a domain workstation you administer

Identify and end a frozen process on a remote domain PC with tasklist, CIM, taskkill or PsKill, plus the rights, ports and pitfalls of each route.

A user phones: Outlook is “Not Responding”, the screen is frozen, and they’re on the other side of the building or working from a branch office. Remoting into their desktop means taking over the session they’re stuck in. Ending the one process from your own console is quicker, and the user can keep working in everything else. There are four ways to do this with built-in or free tools, and each needs different network paths. Pick the one your environment already allows.

Use only on systems you administer and with your organisation’s authorization. Ending a process discards anything unsaved in it, so tell the user before you do it.

Rights and paths, up front

Every method below needs local administrator rights on the target. That usually means a workstation-admin group applied by GPO, not Domain Admins. What changes between methods is the network path:

Method Transport Typical firewall need
tasklist / taskkill RPC / WMI Windows Management Instrumentation (WMI) rule group
Get-CimInstance (default) WinRM (WS-Man) TCP 5985, WinRM enabled
Get-CimInstance with DCOM DCOM / RPC TCP 135 + dynamic RPC range
PsList / PsKill SMB admin share, remote registry/perf counters TCP 445

If one method fails with “RPC server unavailable” or “access denied”, the next one may still work. The target isn’t broken, you’ve just hit a firewall rule or UAC restriction that blocks that path.

Step 1 — Find the process and its PID

Start with the built-in command. The first command lists every process on the machine. The second filters to one image name and adds window titles and owners:

tasklist /s PC-0421 /fo table
tasklist /s PC-0421 /v /fi "IMAGENAME eq outlook.exe"

The obvious filter /fi "STATUS eq NOT RESPONDING" doesn’t work against a remote computer. Microsoft’s documentation says so, and WINDOWTITLE has the same restriction. You’ll identify the hung process by name, owner and CPU time instead.

With PowerShell and CIM you get objects you can sort. This helps when the culprit is “the Chrome child using 3 GB”:

Get-CimInstance -ComputerName PC-0421 -ClassName Win32_Process -Filter "Name='outlook.exe'" |
    Select-Object ProcessId, Name, SessionId,
        @{n='WS_MB';e={[math]::Round($_.WorkingSetSize/1MB)}},
        @{n='Owner';e={(Invoke-CimMethod -InputObject $_ -MethodName GetOwner).User}}

If WinRM isn’t enabled on workstations, create a DCOM session instead:

$opt = New-CimSessionOption -Protocol Dcom
$cs  = New-CimSession -ComputerName PC-0421 -SessionOption $opt
Get-CimInstance -CimSession $cs -ClassName Win32_Process -Filter "Name='outlook.exe'"

On a shared machine or RDS host, check SessionId so you end this user’s copy and not someone else’s.

Step 2 — Tell the user, then end it

A quick heads-up avoids “I lost my email draft”. Once they know, pick one of these:

  1. taskkill by PID. /t also takes out child processes. Remote kills are always forceful, so /f makes no difference remotely.
    taskkill /s PC-0421 /pid 7312 /t
  2. CIM Terminate, useful inside scripts. A ReturnValue of 0 means success:
    Get-CimInstance -CimSession $cs -ClassName Win32_Process -Filter "ProcessId=7312" |
        Invoke-CimMethod -MethodName Terminate
  3. PowerShell remoting, if WinRM is your standard path:
    Invoke-Command -ComputerName PC-0421 -ScriptBlock { Stop-Process -Id 7312 -Force }
    Get-Process -ComputerName and Stop-Process have no remote parameter in PowerShell 7, so go through Invoke-Command.
  4. PsKill from Sysinternals, over the admin share. -t kills the process tree:
    pskill -t \\PC-0421 7312

Step 3 — Capture evidence if it keeps happening

If the same app hangs every week, ending it again won’t fix anything. Before you end it next time, capture a full dump the vendor can analyse. On the target, for example in an Invoke-Command block or an elevated remote shell, run ProcDump:

procdump -ma 7312 C:\Temp\outlook-hang.dmp

Windows Admin Center’s Processes tool can also create a dump from the browser, but only on machines you’ve added to it. Dumps can contain mail content and credentials in memory, so treat them as sensitive and delete them once the ticket is closed.

Step 4 — Confirm and note it in the ticket

Run tasklist /s PC-0421 /fi "IMAGENAME eq outlook.exe" again to confirm it’s gone. The user can then restart the app. Note the PID, the time and the method in the ticket. The Security log on the target records your network logon (4624 type 3), which is the audit trail for this action.

Common mistakes

When a GUI helps

If you do this several times a day across many PCs, a console with a live process tree and CPU and memory columns is faster than typing PIDs. LizardSystems Remote Process Explorer works over WMI via DCOM. The vendor lists killing and starting processes, changing priority, and restarting the remote computer. It’s free for personal use and paid per machine for business use. The Sysinternals tools are free and scriptable. Remote Process Explorer vs Sysinternals compares the two approaches. More options are listed in Server & Workstation Triage, with a review of the Sysinternals Suite.

Tool used in this how-to