1. Command line: list all tasks, find the one(s) you want.
NOTE: Acrobat Reader starts 2 processes on my Windows XP 32 bit system. and 1 process on my Windows 7 64 bit system.
wmic process get ProcessId, name, creationdatesample output:
AcroRd32.exe highlighted in red by me
CreationDate Name ProcessId
System Idle Process 0
System 4
20131026103450.468750+060 smss.exe 884
20131026103451.671875+060 csrss.exe 956
20131026103453.531250+060 winlogon.exe 980
20131026103453.687500+060 services.exe 1024
20131026103453.703125+060 lsass.exe 1036
20131026103454.265625+060 svchost.exe 1220
20131026103454.515625+060 svchost.exe 1268
20131026103454.671875+060 MsMpEng.exe 1916
20131026103454.734375+060 svchost.exe 1952
20131026103454.765625+060 S24EvMon.exe 168
20131026103454.875000+060 svchost.exe 644
20131026103455.468750+060 svchost.exe 792
20131026103457.140625+060 spoolsv.exe 1420
20131026103457.312500+060 scardsvr.exe 1476
20131026103515.890625+060 svchost.exe 592
20131026103517.281250+060 mDNSResponder.exe 700
20131026103517.312500+060 EvtEng.exe 776
20131026103517.921875+060 jqs.exe 1332
20131026103517.953125+060 MemeoBackgroundService.exe 232
20131026103527.187500+060 NicConfigSvc.exe 2000
20131026103527.265625+060 RegSrvc.exe 2016
20131026103527.328125+060 SeagateDashboardService.exe 804
20131026103527.375000+060 stacsv.exe 840
20131026103527.656250+060 svchost.exe 1316
20131026103527.687500+060 vmnat.exe 1600
20131026103527.828125+060 WLKEEPER.exe 376
20131026103527.875000+060 vmware-authd.exe 476
20131026103528.140625+060 wmiprvse.exe 1584
20131026103528.265625+060 vmnetdhcp.exe 2092
20131026103528.281250+060 wmiprvse.exe 2112
20131026103528.281250+060 vmware-usbarbitrator.exe 2128
20131026103528.406250+060 wmiprvse.exe 2212
20131026103529.984375+060 alg.exe 2968
20131026103530.031250+060 explorer.exe 2980
20131026103530.921875+060 stsystra.exe 3988
20131026103530.968750+060 hkcmd.exe 4036
20131026103531.000000+060 igfxpers.exe 4044
20131026103531.234375+060 ZCfgSvc.exe 4060
20131026103531.250000+060 igfxsrvc.exe 4076
20131026103531.265625+060 iFrmewrk.exe 4084
20131026103535.375000+060 networx.exe 2664
20131026103535.484375+060 StartupMonitor.exe 2784
20131026103535.531250+060 msseces.exe 2800
20131026103535.890625+060 quickset.exe 3380
20131026103536.000000+060 ctfmon.exe 3408
20131026103536.031250+060 I8kfanGUI.exe 3440
20131026103536.500000+060 svchost.exe 3532
20131026103537.500000+060 MemeoDashboard.exe 3132
20131026103537.640625+060 unsecapp.exe 3340
20131026103542.734375+060 CNAB4RPK.EXE 452
20131026103551.015625+060 DellSystemDetect.exe 3080
20131026103553.562500+060 HipServAgent.exe 2260
20131026104137.062500+060 cmd.exe 3740
20131026104149.531250+060 mmc.exe 3460
20131026111050.281250+060 cmd.exe 2224
20131026115726.703125+060 AcroRd32.exe 3800
20131026115726.828125+060 AcroRd32.exe 2192
20131026115734.218750+060 wmic.exe 16842. Command line where you know the process name
wmic process where name="AcroRd32.exe" get ProcessId, name, creationdateSample output:
CreationDate Name ProcessId
20131026115726.703125+060 AcroRd32.exe 3800
20131026115726.828125+060 AcroRd32.exe 2192Time format is YYYYMMDDhhmmss.uuuuuu+NNN where:
YYYY is year
MM is month
DD is day
hh is hour
mm is minute
ss is second
uuuuuu is microseconds (do not rely on this being accurate!)
+NNN is minutes local time difference from UTC (in my case +060 means 1 hour ahead of UTC (Zulu, GMT)
3. GUI: a Windows add on from Microsoft called Process Explorer
Get it here:
http://technet.microsoft.com/en-gb/sysinternals/bb896653.aspxRight click process name and choose "Properties".