Interesting Windows 2000 Tip

OT: anything goes!

Moderator: Edi

Post Reply
User avatar
TrailerParkJawa
Sith Acolyte
Posts: 5850
Joined: 2002-07-04 11:49pm
Location: San Jose, California

Interesting Windows 2000 Tip

Post by TrailerParkJawa »

I was helping someone ferret out a mIRC Trojan on their laptop when I discovered this while troubleshooting.

Ever want to match a running application to it's process in Task Manager?

1. Open several applications. ( IE, Winzip, Paint, etc )
2. Open the Task Manager
3. Go to the Applications Tab
4. Highlight the Application you want to match with a process.
5. Right click and select ' Go to process'

This should work on XP as well, not so sure on NT. Have not tested that yet.
MEMBER of the Anti-PETA Anti-Facist LEAGUE
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

Excellent tip, TPJ!
Image Image
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

IIRC, that worked under NT4 as well.
User avatar
Shinova
Emperor's Hand
Posts: 10193
Joined: 2002-10-03 08:53pm
Location: LOLOLOLOLOLOLOLOLOL

Post by Shinova »

I believe it does work with XP also.


And don't forget that besides the "End process" option, you also have the option of ending an entire tree of processes, which I think is used to close, say, all currently open IE windows, if you're hit by a mass popup attack or something.
What's her bust size!?

It's over NINE THOUSAAAAAAAAAAND!!!!!!!!!
User avatar
Admiral Valdemar
Outside Context Problem
Posts: 31572
Joined: 2002-07-04 07:17pm
Location: UK

Post by Admiral Valdemar »

Always use that if a proggie is acting up and won't die properly.
User avatar
TrailerParkJawa
Sith Acolyte
Posts: 5850
Joined: 2002-07-04 11:49pm
Location: San Jose, California

Post by TrailerParkJawa »

Shinova wrote:I believe it does work with XP also.


And don't forget that besides the "End process" option, you also have the option of ending an entire tree of processes, which I think is used to close, say, all currently open IE windows, if you're hit by a mass popup attack or something.
I just tried that, it stops related processes but not all of the same name.

I opened 3 instances of MS Paint and chose to end the entire tree. It only closed 1 MS Paint.
MEMBER of the Anti-PETA Anti-Facist LEAGUE
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

That's because the three instances of Microsoft Paint are seperate from each other. End Tree only works with child processes.
User avatar
Superman
Pink Foamin' at the Mouth
Posts: 9690
Joined: 2002-12-16 12:29am
Location: Metropolis

Post by Superman »

I don't get it.
Image
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Superman wrote:I don't get it.
Here you go:
Image

Image
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

Eh Faram d00d, you have BackWeb.

I see a Backweb-7681197.exe in your tasklist. :P
Image Image
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Einhander Sn0m4n wrote:Eh Faram d00d, you have BackWeb.

I see a Backweb-7681197.exe in your tasklist. :P
Yeap I know...

F-Secure uses it to automaticaly dload AV updates.

But don't worry I have it locked down

Image

Image

Btw Kerio 2.1.5 is out :D

Thought you had me there did't you ;)
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
TrailerParkJawa
Sith Acolyte
Posts: 5850
Joined: 2002-07-04 11:49pm
Location: San Jose, California

Post by TrailerParkJawa »

phongn wrote:That's because the three instances of Microsoft Paint are seperate from each other. End Tree only works with child processes.
Yeah, thats what I figured.

This came in real handy when I used it. The laptop I was working would launch mIRC everytime at boot up. But mIRC was not installed in the Programs sections, not in the registry, and not in the usual places like Start Up Folder.

When I matched the application to the process, the trojan was renamed at TaskMngr.exe . Pretty clever, because I did not catch it in the processes that were running because they were sorted by CPU % and not name.
MEMBER of the Anti-PETA Anti-Facist LEAGUE
User avatar
Pu-239
Sith Marauder
Posts: 4727
Joined: 2002-10-21 08:44am
Location: Fake Virginia

Post by Pu-239 »

Not very useful, since I seemed to have memorized the names of most of the EXEs that I run, and I don't run multiple instances of stuff thanks to tabbed interfaces, except for OO.

ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer


George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
User avatar
TrailerParkJawa
Sith Acolyte
Posts: 5850
Joined: 2002-07-04 11:49pm
Location: San Jose, California

Post by TrailerParkJawa »

Pu-239 wrote:Not very useful, since I seemed to have memorized the names of most of the EXEs that I run, and I don't run multiple instances of stuff thanks to tabbed interfaces, except for OO.
Thats great for your OWN computer. When you are supporting other computers that people walk up and bring to your desk it can be quite useful. :P
MEMBER of the Anti-PETA Anti-Facist LEAGUE
User avatar
Superman
Pink Foamin' at the Mouth
Posts: 9690
Joined: 2002-12-16 12:29am
Location: Metropolis

Post by Superman »

I still don't get it.
Image
User avatar
Dalton
For Those About to Rock We Salute You
For Those About to Rock We Salute You
Posts: 22640
Joined: 2002-07-03 06:16pm
Location: New York, the Fuck You State
Contact:

Post by Dalton »

Good tip Jawa. Works with XP.
Image
Image
To Absent Friends
Dalton | Admin Smash | Knight of the Order of SDN

"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster

May the way of the Hero lead to the Triforce.
User avatar
Vertigo1
Defender of the Night
Posts: 4720
Joined: 2002-08-12 12:47am
Location: Tennessee, USA
Contact:

Post by Vertigo1 »

Yeah, thats a really useful one.
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong

Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
Post Reply