Solved

how to tell what is launching processes

Posted on 2004-09-29
9
152 Views
Last Modified: 2012-05-05
I am having some problems with some processes that are named "00pxb7.exe" or some such garbage. I am sure it is virus related, but cannot tell what is launching the process. Trendmicro officescan is not picking this one up.  I would like to know if there is a way to find out what application or executable launched this nasty process. The process is never named the same between reboots. thank you
0
Comment
Question by:ironorion
  • 3
  • 2
  • 2
  • +2
9 Comments
 
LVL 95

Expert Comment

by:Lee W, MVP
ID: 12184523
Could be spyware related and not virus related - try running a spyware scanner - I recommend spybot - http://www.safer-networking.org/en/index.html
0
 

Author Comment

by:ironorion
ID: 12184669
Spybot and Ad-aware both came up negative. They both were updated to their latest respecitve patternfiles.
I now believe this to be related to wind32.exe virus issue. I'm still having trouble making the random generated process names go away and stay away.
0
 
LVL 8

Expert Comment

by:Sam Cohen
ID: 12186853
did you check in you registry under run?
0
 
LVL 10

Expert Comment

by:Longbow
ID: 12188044
Run msconfig.exe from Start / Run
Open the Startup tab.
All the startup processes are there.
You can disable suspicious processes and restart.
Maybe you will find wich is the responsible.
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 

Author Comment

by:ironorion
ID: 12189984
I've gone through all the standard virus/malware/spyware manual registry crawls looking for anything suspicious. No luck.
0
 
LVL 6

Accepted Solution

by:
nomi17 earned 125 total points
ID: 12191931
Try this free tool called Process explorer:
(scroll to the bottom of page for download links)

http://www.sysinternals.com/ntw2k/freeware/procexp.shtml

This will list your processes with a description that will most likely help you determine which programs are using it.
0
 
LVL 8

Expert Comment

by:Sam Cohen
ID: 12192081
get this free dowload called Ace Utilities located here:

 http://www.download.com/3000-2086-10145494.html
*******************************************
0
 

Author Comment

by:ironorion
ID: 12199610
Thanks nomi17. While not a direct fix for my problem it is the tool I was looking for! All4artz, I gave the app you pointed to a try as well, not what I was looking for but something I will add to my bag o tricks just the same. Thanks all for your help.

0
 
LVL 6

Expert Comment

by:nomi17
ID: 12202056
glad I could help in some way...
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Suggested Solutions

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
For cloud, the “train has left the station” and in the Microsoft ERP & CRM world, that means the next generation of enterprise software from Microsoft is here: Dynamics 365 is Microsoft’s new integrated business solution that unifies CRM and ERP fun…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now