Solved

outlook.exe runs at 100% in strange context (services.exe > svchost.exe > outlook.exe)

Posted on 2008-10-22
2
479 Views
Last Modified: 2012-05-05
got a very strange effect on a large number of clients.

a separate outlook.exe process is running in the context of services.exe > svchost.exe. the process is completely independent of any other "regular" outlook instances.

killing the process will (of course) help but the problem will reoccur the next day.

does anyone have an idea what's spawning the process and how this might be prevented?

thanks alot
- Boris
procexp.gif
0
Comment
Question by:vischer-it
2 Comments
 
LVL 23

Accepted Solution

by:
Admin3k earned 250 total points
ID: 22775064
try using Procmon , also from Sysinternals, to check what File system access, registry entries , network traffic and process activity , this Outlook instance is related to.

http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx

This could be a bad add-on for outlook, I doubt this is malware related, since KAV seems up & running, however please post a Hijack this log

http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php?page=download
0
 

Author Comment

by:vischer-it
ID: 22776821
procmon led me to the "bad add-on for outlook". which in our case was the symantec enterprise vault outlook add-in. it's been communicating with the server as often and fast as possible and writing tons of data to the local log files. have opened a case with symantec and am waiting for their response.
0

Featured Post

Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

There are 2 things you must have in order to connect to the internet behind a router, The "Gateway IP" of the router, which is usually something like 192.168.xxx.1, I've seen routers with default values of: 192.168.0.1, 192.168.1.1, 192.168.11.1, …
Today, still in the boom of Apple, PC's and products, nearly 50% of the computer users use Windows as graphical operating systems. If you are among those users who love windows, but are grappling to keep the system's hard drive optimized, then you s…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question