Solved

outlook.exe runs at 100% in strange context (services.exe > svchost.exe > outlook.exe)

Posted on 2008-10-22
2
476 Views
Last Modified: 2012-05-05
got a very strange effect on a large number of clients.

a separate outlook.exe process is running in the context of services.exe > svchost.exe. the process is completely independent of any other "regular" outlook instances.

killing the process will (of course) help but the problem will reoccur the next day.

does anyone have an idea what's spawning the process and how this might be prevented?

thanks alot
- Boris
procexp.gif
0
Comment
Question by:vischer-it
2 Comments
 
LVL 23

Accepted Solution

by:
Admin3k earned 250 total points
ID: 22775064
try using Procmon , also from Sysinternals, to check what File system access, registry entries , network traffic and process activity , this Outlook instance is related to.

http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx

This could be a bad add-on for outlook, I doubt this is malware related, since KAV seems up & running, however please post a Hijack this log

http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php?page=download
0
 

Author Comment

by:vischer-it
ID: 22776821
procmon led me to the "bad add-on for outlook". which in our case was the symantec enterprise vault outlook add-in. it's been communicating with the server as often and fast as possible and writing tons of data to the local log files. have opened a case with symantec and am waiting for their response.
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Most of the time we are in fix when all of sudden our systems behave weirdly.  Such problems cost time and effort... so it's best to take some preventive actions so that we can avoid such issues or overcome such problems more easily. Preventive M…
Are you unable to synchronize your OST (Offline Storage Table) file with Microsoft Exchange Server? Is your OST file exceeding 2 GB size limit? In Microsoft Outlook 2002 and earlier versions, there is a 2 GB size limit for the OST file. If the file …
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now