Solved

how to tell what is launching processes

Posted on 2004-09-29
9
156 Views
Last Modified: 2012-05-05
I am having some problems with some processes that are named "00pxb7.exe" or some such garbage. I am sure it is virus related, but cannot tell what is launching the process. Trendmicro officescan is not picking this one up.  I would like to know if there is a way to find out what application or executable launched this nasty process. The process is never named the same between reboots. thank you
0
Comment
Question by:ironorion
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +2
9 Comments
 
LVL 95

Expert Comment

by:Lee W, MVP
ID: 12184523
Could be spyware related and not virus related - try running a spyware scanner - I recommend spybot - http://www.safer-networking.org/en/index.html
0
 

Author Comment

by:ironorion
ID: 12184669
Spybot and Ad-aware both came up negative. They both were updated to their latest respecitve patternfiles.
I now believe this to be related to wind32.exe virus issue. I'm still having trouble making the random generated process names go away and stay away.
0
 
LVL 8

Expert Comment

by:Sam Cohen
ID: 12186853
did you check in you registry under run?
0
Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

 
LVL 10

Expert Comment

by:Longbow
ID: 12188044
Run msconfig.exe from Start / Run
Open the Startup tab.
All the startup processes are there.
You can disable suspicious processes and restart.
Maybe you will find wich is the responsible.
0
 

Author Comment

by:ironorion
ID: 12189984
I've gone through all the standard virus/malware/spyware manual registry crawls looking for anything suspicious. No luck.
0
 
LVL 6

Accepted Solution

by:
nomi17 earned 125 total points
ID: 12191931
Try this free tool called Process explorer:
(scroll to the bottom of page for download links)

http://www.sysinternals.com/ntw2k/freeware/procexp.shtml

This will list your processes with a description that will most likely help you determine which programs are using it.
0
 
LVL 8

Expert Comment

by:Sam Cohen
ID: 12192081
get this free dowload called Ace Utilities located here:

 http://www.download.com/3000-2086-10145494.html
*******************************************
0
 

Author Comment

by:ironorion
ID: 12199610
Thanks nomi17. While not a direct fix for my problem it is the tool I was looking for! All4artz, I gave the app you pointed to a try as well, not what I was looking for but something I will add to my bag o tricks just the same. Thanks all for your help.

0
 
LVL 6

Expert Comment

by:nomi17
ID: 12202056
glad I could help in some way...
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
The Windows functions GetTickCount and timeGetTime retrieve the number of milliseconds since the system was started. However, the value is stored in a DWORD, which means that it wraps around to zero every 49.7 days. This article shows how to solve t…
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question