There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash driver drivers error ethernet excel freeze gaming gpu hard drive hardware hdmi internet laptop malware memory monitor motherboard music network obp operating system printer problem ram registry router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
What processes will not be shown in Task Manager?

Reply  
Thread Tools
GeoRanger's Avatar
Computer Specs
Junior Member with 16 posts.
 
Join Date: Mar 2009
05-Jul-2009, 11:09 PM #1
What processes will not be shown in Task Manager?
Hello:

Concerning Windows XP... In working on a MalWare infection, I found references (some in advertising) to the notion that Task Manager will not show all of the processes running on your system.

1. Are there any processes other than rootkit-type MalWare which would not be shown in Task Manager? Or to put it another way, would any legitimate process not be shown in Task Manager? If so, is there some common name for such processes?

2. If legitimate processes wouldn't show, why not?

3. Would a legitimitate process like this (assuming there are any) show up in a program that finds rootkits? If not, are there any programs which will show them?

I no longer trust my Windows installation and am going to rebuild it from the ground up. I want to keep track of each and every process that runs on the rebuild so I'll have a leg up if/when something goes wrong next time.

Thanks for any info
lunarlander's Avatar
Computer Specs
Senior Member with 3,484 posts.
 
Join Date: Sep 2007
05-Jul-2009, 11:48 PM #2
Sysinternals has 2 free programs which may interest you, Process Explorer and RootKitRevealer. Google for them. The company is so good that MS bought them.
Elvandil's Avatar
Computer Specs
Moderator with 48,924 posts.
 
Join Date: Aug 2003
Location: Vermont
Experience: "Been through the mill."
06-Jul-2009, 01:08 AM #3
Rootkits use drivers to take control of the kernel at boot. They can hide anything that you can see in Windows. There are also ways of hiding legitimate programs.

Offline scans can see and detect these infections.

Process Hacker (Allows editing memory, shows hidden processes, similar to Sysinternals Process Explorer with more features - can replace normal Task Manager) can also find hidden processes by checking each PID and comparing it to the Task Manager list. Look under "Tools".
__________________
Microsoft MVP
異驚の界世 ˇpןɹoʍ ǝɥʇ ɟo sɹǝpuoʍ ǝɥʇ ɟo ǝuo sı ǝpoɔıun ʞuıɥʇ ı
Sevvie's Avatar
Computer Specs
Junior Member with 18 posts.
 
Join Date: Dec 2008
Experience: Intermediate
06-Jul-2009, 02:19 AM #4
Use Sysinternals tools and also check out www.fileinspect.com for references.

Last edited by Cookiegal; 06-Jul-2009 at 01:41 PM.. Reason: To fix link
Elvandil's Avatar
Computer Specs
Moderator with 48,924 posts.
 
Join Date: Aug 2003
Location: Vermont
Experience: "Been through the mill."
06-Jul-2009, 02:26 AM #5
Quote:
Originally Posted by Sevvie View Post
Use Sysinternals tools and also check out www.fileinspect.com for references.
Your link does not exist as a web site.

Last edited by Cookiegal; 06-Jul-2009 at 01:42 PM.. Reason: To fix quoted link
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,000 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
06-Jul-2009, 10:44 AM #6
perfume's Avatar
perfume has a Photo Album
Computer Specs
Account Disabled with 2,011 posts.
 
Join Date: Sep 2008
Location: A DUDE WITH ATTITUDE! ALIEN.
Experience: Intermediate++
06-Jul-2009, 12:58 PM #7
Dear Elvandil,
Thanks for the Process Hacker!
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,272 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
06-Jul-2009, 01:42 PM #8
Quote:
Originally Posted by Elvandil View Post
Your link does not exist as a web site.
There was a typo in the actual link and I've fixed it.
Elvandil's Avatar
Computer Specs
Moderator with 48,924 posts.
 
Join Date: Aug 2003
Location: Vermont
Experience: "Been through the mill."
11-Jul-2009, 11:27 PM #9
Quote:
Originally Posted by Cookiegal View Post
There was a typo in the actual link and I've fixed it.
Thanks. I missed that "s" when I first glanced at it.

Quote:
Originally Posted by perfume View Post
Dear Elvandil,
Thanks for the Process Hacker!
You're welcome. It is a great tool. Keep up to date since it is getting better all the time.

Download and install all (or your chosen) Sysinternals tools automatically with the Sysinternals Installer.
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 12:46 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.