Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

outlook.exe runs at 100% in strange context (services.exe > svchost.exe > outlook.exe)

Posted on 2008-10-22
2
Medium Priority
?
489 Views
Last Modified: 2012-05-05
got a very strange effect on a large number of clients.

a separate outlook.exe process is running in the context of services.exe > svchost.exe. the process is completely independent of any other "regular" outlook instances.

killing the process will (of course) help but the problem will reoccur the next day.

does anyone have an idea what's spawning the process and how this might be prevented?

thanks alot
- Boris
procexp.gif
0
Comment
Question by:vischer-it
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 23

Accepted Solution

by:
Mohamed Osama earned 750 total points
ID: 22775064
try using Procmon , also from Sysinternals, to check what File system access, registry entries , network traffic and process activity , this Outlook instance is related to.

http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx

This could be a bad add-on for outlook, I doubt this is malware related, since KAV seems up & running, however please post a Hijack this log

http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php?page=download
0
 

Author Comment

by:vischer-it
ID: 22776821
procmon led me to the "bad add-on for outlook". which in our case was the symantec enterprise vault outlook add-in. it's been communicating with the server as often and fast as possible and writing tons of data to the local log files. have opened a case with symantec and am waiting for their response.
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are 2 things you must have in order to connect to the internet behind a router, The "Gateway IP" of the router, which is usually something like 192.168.xxx.1, I've seen routers with default values of: 192.168.0.1, 192.168.1.1, 192.168.11.1, …
Can you find a fax from a vendor you saved a decade ago in seconds? Have you ever cursed your PC under your breath during an audit because you couldn’t find the requested statement or driver history?  If you answered no to the first question or yes …
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question