|
|
|
|
![]() ![]() |
Sep 9 2007, 08:00 PM
Post
#1
|
|
|
Premium Member Group: [HOSTED] Posts: 286 Joined: 17-June 07 Member No.: 22,702 |
On your computer, tens of hidden processes might run silently in the background. Some consume system resources, radically slowing your PC. Other useless processes contain spyware and Trojans - at least violating your privacy. This process and DLL library is a great free resource for anyone who wants to know the exact purpose of every process.
http://process-dll.com/pd/index.php It's pretty good, but it needs a search feature instead of having to use Ctrl-F. Sure it tells you handy information about processes like svchost.exe but it doesn't tell you why on your Vista you have all of your svchost.exe's taking 200MB of RAM. Also check out: http://www.processlibrary.com/ Article "How to Clean Up a Windows Spyware Infestation": http://www.codinghorror.com/blog/archives/000888.html Edit: I just found one more Internet resource for this. Follow these instructions: 1) Identify the base name of the suspicious file (e.g. mdm.exe or secdrv.sys) - base name is the opposite of a fully qualified name (which means that the base name does not include the full path). 2) Create a link by filling in this base name as follows: www.neuber.com/taskmanager/process/<base-name-of-suspicious-file>.html Examples: http://www.neuber.com/taskmanager/process/mdm.exe.html http://www.neuber.com/taskmanager/process/secdrv.sys.html It's a mix of comments in both English and German, but it's very interesting because even as those comments are filtered and moderated, you still get some useful feedback from people who were burned badly by some of these pieces of malware. I am a little bit cautious about recommending the download of anything from a site that ends in .ru, but today I was in a brave mood and I downloaded the so-called "Hidden Processes Detector - Process Walker" from: http://rkunhooker1.narod.ru/ The site looks like a legit rootkit detection / removal project. I scanned pwalker.exe using my standalone virus scanner and I ran it through http://www.virustotal.com/ - it came out almost clean. I say "almost clean" because out of 31 virus scanning engines, only one thinks it's a suspicious file - Panda. The output of pwalker.exe is a list of processes running on your computer, along with an indication whether it's a visible or hidden process. However, I have to say that this program leaves autorun entries in the registry, which I had to manually go in and remove afterwards. This post has been edited by dserban: Sep 10 2007, 12:56 PM |
|
|
|
Sep 9 2007, 08:42 PM
Post
#2
|
|
|
Way Out Of Control - You need a life :) Group: [HOSTED] Posts: 1,086 Joined: 2-August 05 From: Kapellen (Antwerp, Belgium) Member No.: 7,585 |
|
|
|
|
Sep 9 2007, 08:54 PM
Post
#3
|
|
|
Newbie [ Level 2 ] Group: Members Posts: 28 Joined: 6-September 07 From: San Pedro Sula, Honduras Member No.: 24,649 |
bookmarked^2 ![]() sure, and dserban you can download process explorer of here : http://www.microsoft.com/technet/sysintern...ssexplorer.mspx |
|
|
|
Sep 10 2007, 08:52 PM
Post
#4
|
|
|
Super Member Group: [HOSTED] Posts: 557 Joined: 25-April 05 Member No.: 4,374 myCENTs:17.04 |
The trick about scvhost is it should only run under system credentials. That is when you view the Task Manager and look at the User Name (view > select columns.. if you don’t see it), you should only see SYSTEM, LOCAL SERVICE, or NETWORK SERVICE. If you ever see your logged on user name then you have a problem.
|
|
|
|
![]() ![]() |
Similar Topics
|
Lo-Fi Version | Time is now: 2nd December 2008 - 01:32 AM |