PDA

View Full Version : Windows Smells Fishy



trajillo
12-12-2004, 06:57 AM
Hey i have a screenshot of my processes .. and i;ve noticed my system running slower than usuall, now can someone tell me if any of these processes are viruses or resource hogs..

http://img55.exs.cx/my.php?loc=img55&image=screen03pu.jpg

Xilo
12-12-2004, 07:05 AM
That's just Norton auto-protect (the one you highlighted). A lot of the others are for Norton, too. Dunno bout some of those. Try googling any non-CC... and non-NV... process that you don't know about (those are Norton)

Ariel_001
12-12-2004, 07:18 AM
process explorer (http://www.sysinternals.com/ntw2k/freeware/procexp.shtml) will give you more insight on what is running..

http://img79.exs.cx/img79/7830/pe9ne.th.jpg (http://img79.exs.cx/my.php?loc=img79&image=pe9ne.jpg)

100%
12-12-2004, 11:24 AM
The ones i would find Questionable are
wdfmgr.exe
rundll32.exe
istsvc.exe
usrprmpt.exe
sapisvvr.exe
lucoms.exe
symlcsvc.exe
mdm.exe
scsiaccess.exe
wuauclt.exe
+ you have 3 versions of messenger running wtf?

The CORE system processes(+ internet access) that need to be running for Windows to function are the following - anything else is too much.
csrss.exe
ctfmon.exe (disable this if DONT need different languages)
explorer.exe
Isass.exe (x2?)
services.exe
smss.exe
svchost.exe (x4)
spoolsv.exe (printer...)
System
System Idle Process
Winlogon.exe
(+your firewall and antivirus programs...)
if any of the above .exes are named slightly different or are located outside of the system32 folder there is a big likelihood they are viruses.

trajillo
12-12-2004, 11:32 AM
wdfmgr.exe
rundll32.exe
istsvc.exe
usrprmpt.exe
sapisvvr.exe
lucoms.exe
symlcsvc.exe
mdm.exe
scsiaccess.exe
wuauclt.exe


should i deleted those from system32?

100%
12-12-2004, 11:46 AM
NO
first look on goggle and find out exactly what they are eg "istsvc.exe process"
and find proper ways to disable them running at startup.
in some cases it is simply possible to disable them via the program(in options) they are refering to - eg in program options disable running at startup
there is plenty of topics on wdfmgr.exe
the rundll32.exe process is essential for windows but is an annoying one and cant remember why it sometimes popsup in processes so look on google first

100%
12-12-2004, 11:50 AM
or you could simply use a startup controller utility - and simply disable them from running at startup
try this program Mike Lin's Startup Control Panel http://www.mlin.net/StartupCPL.shtml

http://www.mlin.net/media/StartupCPL.png

Smurfette
12-12-2004, 09:29 PM
You certainly don't want to delete rundll32.exe because it's a system file that allows a 32bit dll to be run as an application.