Page 1 of 1
Interesting Windows 2000 Tip
Posted: 2003-05-15 11:09am
by TrailerParkJawa
I was helping someone ferret out a mIRC Trojan on their laptop when I discovered this while troubleshooting.
Ever want to match a running application to it's process in Task Manager?
1. Open several applications. ( IE, Winzip, Paint, etc )
2. Open the Task Manager
3. Go to the Applications Tab
4. Highlight the Application you want to match with a process.
5. Right click and select ' Go to process'
This should work on XP as well, not so sure on NT. Have not tested that yet.
Posted: 2003-05-15 11:25am
by Einhander Sn0m4n
Excellent tip, TPJ!
Posted: 2003-05-15 11:26am
by phongn
IIRC, that worked under NT4 as well.
Posted: 2003-05-15 11:32am
by Shinova
I believe it does work with XP also.
And don't forget that besides the "End process" option, you also have the option of ending an entire tree of processes, which I think is used to close, say, all currently open IE windows, if you're hit by a mass popup attack or something.
Posted: 2003-05-15 11:42am
by Admiral Valdemar
Always use that if a proggie is acting up and won't die properly.
Posted: 2003-05-15 11:44am
by TrailerParkJawa
Shinova wrote:I believe it does work with XP also.
And don't forget that besides the "End process" option, you also have the option of ending an entire tree of processes, which I think is used to close, say, all currently open IE windows, if you're hit by a mass popup attack or something.
I just tried that, it stops related processes but not all of the same name.
I opened 3 instances of MS Paint and chose to end the entire tree. It only closed 1 MS Paint.
Posted: 2003-05-15 12:32pm
by phongn
That's because the three instances of Microsoft Paint are seperate from each other. End Tree only works with child processes.
Posted: 2003-05-15 01:04pm
by Superman
I don't get it.
Posted: 2003-05-15 01:10pm
by Faram
Superman wrote:I don't get it.
Here you go:
Posted: 2003-05-15 01:51pm
by Einhander Sn0m4n
Eh Faram d00d, you have BackWeb.
I see a Backweb-7681197.exe in your tasklist.
Posted: 2003-05-15 01:57pm
by Faram
Einhander Sn0m4n wrote:Eh Faram d00d, you have BackWeb.
I see a Backweb-7681197.exe in your tasklist.
Yeap I know...
F-Secure uses it to automaticaly dload AV updates.
But don't worry I have it locked down
Btw Kerio 2.1.5 is out
Thought you had me there did't you
Posted: 2003-05-15 02:02pm
by TrailerParkJawa
phongn wrote:That's because the three instances of Microsoft Paint are seperate from each other. End Tree only works with child processes.
Yeah, thats what I figured.
This came in real handy when I used it. The laptop I was working would launch mIRC everytime at boot up. But mIRC was not installed in the Programs sections, not in the registry, and not in the usual places like Start Up Folder.
When I matched the application to the process, the trojan was renamed at TaskMngr.exe . Pretty clever, because I did not catch it in the processes that were running because they were sorted by CPU % and not name.
Posted: 2003-05-15 03:46pm
by Pu-239
Not very useful, since I seemed to have memorized the names of most of the EXEs that I run, and I don't run multiple instances of stuff thanks to tabbed interfaces, except for OO.
Posted: 2003-05-15 03:48pm
by TrailerParkJawa
Pu-239 wrote:Not very useful, since I seemed to have memorized the names of most of the EXEs that I run, and I don't run multiple instances of stuff thanks to tabbed interfaces, except for OO.
Thats great for your OWN computer. When you are supporting other computers that people walk up and bring to your desk it can be quite useful.
Posted: 2003-05-15 03:56pm
by Superman
I still don't get it.
Posted: 2003-05-15 04:40pm
by Dalton
Good tip Jawa. Works with XP.
Posted: 2003-05-16 01:20am
by Vertigo1
Yeah, thats a really useful one.