Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> A Very Comprehensive Windows (vista And Xp) Process And Dll Library
dserban
post Sep 9 2007, 08:00 PM
Post #1


Premium Member
Group Icon

Group: [HOSTED]
Posts: 286
Joined: 17-June 07
Member No.: 22,702



On your computer, tens of hidden processes might run silently in the background. Some consume system resources, radically slowing your PC. Other useless processes contain spyware and Trojans - at least violating your privacy. This process and DLL library is a great free resource for anyone who wants to know the exact purpose of every process.

http://process-dll.com/pd/index.php

It's pretty good, but it needs a search feature instead of having to use Ctrl-F.
Sure it tells you handy information about processes like svchost.exe but it doesn't tell you why on your Vista you have all of your svchost.exe's taking 200MB of RAM.

Also check out:

http://www.processlibrary.com/

Article "How to Clean Up a Windows Spyware Infestation":
http://www.codinghorror.com/blog/archives/000888.html

Edit:
I just found one more Internet resource for this. Follow these instructions:
1) Identify the base name of the suspicious file (e.g. mdm.exe or secdrv.sys) - base name is the opposite of a fully qualified name (which means that the base name does not include the full path).
2) Create a link by filling in this base name as follows:
www.neuber.com/taskmanager/process/<base-name-of-suspicious-file>.html

Examples:
http://www.neuber.com/taskmanager/process/mdm.exe.html
http://www.neuber.com/taskmanager/process/secdrv.sys.html

It's a mix of comments in both English and German, but it's very interesting because even as those comments are filtered and moderated, you still get some useful feedback from people who were burned badly by some of these pieces of malware.

I am a little bit cautious about recommending the download of anything from a site that ends in .ru, but today I was in a brave mood and I downloaded the so-called "Hidden Processes Detector - Process Walker" from:
http://rkunhooker1.narod.ru/
The site looks like a legit rootkit detection / removal project.
I scanned pwalker.exe using my standalone virus scanner and I ran it through http://www.virustotal.com/ - it came out almost clean. I say "almost clean" because out of 31 virus scanning engines, only one thinks it's a suspicious file - Panda.

The output of pwalker.exe is a list of processes running on your computer, along with an indication whether it's a visible or hidden process.

However, I have to say that this program leaves autorun entries in the registry, which I had to manually go in and remove afterwards.

This post has been edited by dserban: Sep 10 2007, 12:56 PM
Go to the top of the page
 
+Quote Post
wutske
post Sep 9 2007, 08:42 PM
Post #2


Way Out Of Control - You need a life :)
Group Icon

Group: [HOSTED]
Posts: 1,086
Joined: 2-August 05
From: Kapellen (Antwerp, Belgium)
Member No.: 7,585



bookmarked^2 smile.gif . About the svchost process, try Process Explorer, if you hover over one of the many svchost.exe processes, then it'll show you which service it's hosting:


This post has been edited by wutske: Sep 9 2007, 08:42 PM
Go to the top of the page
 
+Quote Post
WaLhEZ
post Sep 9 2007, 08:54 PM
Post #3


Newbie [ Level 2 ]
Group Icon

Group: Members
Posts: 28
Joined: 6-September 07
From: San Pedro Sula, Honduras
Member No.: 24,649



QUOTE(wutske @ Sep 9 2007, 08:42 PM) *
bookmarked^2 smile.gif . About the svchost process, try Process Explorer, if you hover over one of the many svchost.exe processes, then it'll show you which service it's hosting:

sure, and dserban you can download process explorer of here : http://www.microsoft.com/technet/sysintern...ssexplorer.mspx
Go to the top of the page
 
+Quote Post
tansqrx
post Sep 10 2007, 08:52 PM
Post #4


Super Member
Group Icon

Group: [HOSTED]
Posts: 557
Joined: 25-April 05
Member No.: 4,374
myCENTs:17.04



The trick about scvhost is it should only run under system credentials. That is when you view the Task Manager and look at the User Name (view > select columns.. if you don’t see it), you should only see SYSTEM, LOCAL SERVICE, or NETWORK SERVICE. If you ever see your logged on user name then you have a problem.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. What Is The Use Of Service Packs For Windows?(18)
  2. Anyone Know Of Any Good Image Editing Software?(24)
  3. How To Make Your Windows Look Like A Mac(24)
  4. A Note To All Illegal Windows Xp Owners(48)
  5. How Can I Delete Old Files In Windows Xp ?(22)
  6. Using Same Serial # On Multiple Copies Of Windows(18)
  7. Problems Installing Vista(14)
  8. Blue Screen - irql_not_less_or_equal(35)
  9. 100 Reasons To Use Windows Vista(13)
  10. Review About Vista(11)
  11. Windows Or Mac?(31)
  12. Help! Usb Flash Drive(12)
  13. How To Install Ubuntu On Windows(3)
  14. Extremely Slow Hdd Operations On Windows Xp(9)
  15. Image Problems With Windows 2000(10)
  1. Windows 7(12)
  2. Windows Black Edition(11)
  3. Windows Mobile 6.1 Games Folder(0)
  4. String Library Functions(4)
  5. How To Make Both Windows Look Like Active At Same Time(9)
  6. Windows Xp, How To Re-enable Show All Possible Color(6)
  7. The Run Command(5)
  8. How To Change Your Windows User Environment Variables(5)
  9. Repairing Your Windows Environment(0)
  10. How To Enable User Login Security On Windows Vista(0)
  11. What Do You Guys Think Of Windows 7?(10)
  12. How To Improve Windows.(7)
  13. Why Still Windows But Ubuntu Linux(3)


 



- Lo-Fi Version Time is now: 2nd December 2008 - 01:32 AM