Solved

outlook.exe runs at 100% in strange context (services.exe > svchost.exe > outlook.exe)

Posted on 2008-10-22
2
483 Views
Last Modified: 2012-05-05
got a very strange effect on a large number of clients.

a separate outlook.exe process is running in the context of services.exe > svchost.exe. the process is completely independent of any other "regular" outlook instances.

killing the process will (of course) help but the problem will reoccur the next day.

does anyone have an idea what's spawning the process and how this might be prevented?

thanks alot
- Boris
procexp.gif
0
Comment
Question by:vischer-it
2 Comments
 
LVL 23

Accepted Solution

by:
Admin3k earned 250 total points
ID: 22775064
try using Procmon , also from Sysinternals, to check what File system access, registry entries , network traffic and process activity , this Outlook instance is related to.

http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx

This could be a bad add-on for outlook, I doubt this is malware related, since KAV seems up & running, however please post a Hijack this log

http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php?page=download
0
 

Author Comment

by:vischer-it
ID: 22776821
procmon led me to the "bad add-on for outlook". which in our case was the symantec enterprise vault outlook add-in. it's been communicating with the server as often and fast as possible and writing tons of data to the local log files. have opened a case with symantec and am waiting for their response.
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If your system is showing symptoms of browser hijacks or 'google search redirects' check out my other article (http://rdsrc.us/u3GP7A) first and run the tool TDSSKiller (http://rdsrc.us/GDBBs4) to get rid of the infection. Once done, and if the …
Sometimes people don't understand why download speed shows differently for Windows than Linux.Specially, this article covers and shows the solution for throughput difference for Windows than a Linux machine. For this, I arranged a test scenario.I…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question