Solved

How to Identify the Process a Service is Using

Posted on 2014-12-10
7
109 Views
Last Modified: 2014-12-15
I needed to change permissions on some processes.  The process name for most services nicely matches the service names.  However, I can't locate the name of the process the Messenger spawns in process explorer by name.  Is there a better way to link a service to a process in memory?  (Yes, Messenger is disabled, but the permissions are insecure so picked up on a scan.  I'm just temporarily starting the service to try to see it).

Thanks.
0
Comment
Question by:whoam
7 Comments
 
LVL 32

Assisted Solution

by:it_saige
it_saige earned 167 total points
ID: 40492716
You can look at the service properties:

Start -> Run --> services.msc

Choose a service, right-click on it and choose properties.  There is a line under the description that reads 'Path to executable' -Capture.JPG
Although, don't be surprised if you find many Microsoft services use svchost.exe.

-saige-
0
 
LVL 68

Assisted Solution

by:Qlemo
Qlemo earned 167 total points
ID: 40492720
In Process Explorer you can view the hosted services in the service exe. Indirect, but feasible.
With newer OS TaskManager has own tab displaying service names and their corresponding host file.
You can also search in registry,  if you know the internal name.
0
 
LVL 4

Assisted Solution

by:Zsolt Pribusz
Zsolt Pribusz earned 166 total points
ID: 40492721
in powershell you can run this:

Get-WmiObject win32_service | select Name, DisplayName, PathName

PathName points to executable what service is using.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:whoam
ID: 40492752
Thanks guys, I left out some details.  Messenger's executable is
"C:\Windows\System32\svchost.exe -k netsnvs"
So, yep it spawns the dreaded "Svchost.exe" in process explorer.  So that's no help.

I need a way to find which svchost.exe is being used by Messenger.

One of the running svchost.exe has the same executable string, but mousing over shows only other services.
0
 

Accepted Solution

by:
whoam earned 0 total points
ID: 40492755
Found it!

So, if you take that process "SVCHOST.EXE" that I spoke of and open it's properties in process explorer(Sysinternals), then go to the SERVICES tab, there you find the Messenger process/servcie listed with the other services.  From there you can choose permissions, modify them as needed.

Thanks all!
0
 
LVL 68

Expert Comment

by:Qlemo
ID: 40492756
That's what I tried to tell in http:#a40492720.
You can also use   tasklist /svc   to view the service/exe relation.
0
 

Author Closing Comment

by:whoam
ID: 40499978
The expert comment did not provide the answer I needed, but felt they deserved points for effort and helping me get there.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Learn about cloud computing and its benefits for small business owners.
When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup". After a while, you have entered a loop for Auto repair which does not fix anything and you will be in a  panic as all your work w…
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now