1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Invisible process wants to run

Discussion in 'Security and Privacy' started by alpwazungy, 2006/03/15.

  1. 2006/03/15
    alpwazungy

    alpwazungy Inactive Thread Starter

    Joined:
    2006/03/15
    Messages:
    3
    Likes Received:
    0
    Hi gang,.

    I noticed an invisivble process running shortly after I set up my Win XP home on my system.
    I have current service packs and upgrades installed (up until about a week ago I guess).
    The invisible process is listed in the system configuration utility (run msconfig) under the startup tab.
    A line and check box apears in the middle of the list with no startup item name or command listed what so ever.
    The Location is listed as SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    Most of the other entries in the list are at (HLM or HKCU)\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    Only one other entry shares the exact same location, this is apparently for a gigabyte VGA utility called G-VGA.

    I have unchecked the box so it will not run when I start up.
    How do I determine what it is and why it is on my system???
    Unmamed processes are suspicious.

    Thanks,

    Waz
     
  2. 2006/03/15
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0

  3. to hide this advert.

  4. 2006/04/12
    alpwazungy

    alpwazungy Inactive Thread Starter

    Joined:
    2006/03/15
    Messages:
    3
    Likes Received:
    0
    lost something in the explanation

    Thanks for your reply.
    I do not know how it sat in my inbox for 4 weeks without notice or if somehow I just got it today (email notification).

    Anyway, yes, I know G-VGA is a gigabyte process and is safe.
    The suspect file is not named anything. If you re-read my origional message you'll note that I only mention the location or what I think of as the location for this invisible process is the same as the g-vga.exe process. I listed what looks like a registry entry to me but I don't know any better.

    I don't trust processes that have a null entry for a name. Seems sneaky.

    What say you?
     
  5. 2006/04/13
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hello alpwazungy,

    A similiar example http://www.windowsbbs.com/showthread.php?t=50611&highlight=blank I've seen this a number times. In this case, the sysem32 folder was displayed.

    An excellent tool for finding and stopping startup processes is autoruns
    http://www.windowsbbs.com/showthread.php?t=53427

    If you unchecked this line in msconfig, under the Logon tab in autoruns, that line will also be unchecked with more info. You can "jump" to the registry location for it as well.

    Regards - Charles
     
  6. 2006/04/13
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    alpwazungy--Following up on what charlesvar said, you may be able to clean up the cosmetics of msconfig by deleting that entry from the Registry location(s) given. (As always, back up the Registry before making changes, in case you want to restore.)
    I suspect the process was not at fault, but rather some corruption that occurred for an obscure reason. :)
     
  7. 2006/04/13
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hi Jim,

    In autoruns, a right click > delete a startup line also deletes the reg entry and removes the line in msconfig.

    Regards - Charles
     
  8. 2006/04/13
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    also, fyi, when deleting regkeys using autoruns it creates a new regkey of its own of "deleted items ".
     
  9. 2006/04/13
    alpwazungy

    alpwazungy Inactive Thread Starter

    Joined:
    2006/03/15
    Messages:
    3
    Likes Received:
    0
    OK, good news.
    I downloaded and am using autoruns.
    It is a nice utility. I managed to find and delete a little bit of trash that my other reg-cleaner missed.

    Bad news...
    Autoruns does not show the "invisible" entry. I looked under the logon tab and under Everything. All entries have a name.
    Nor was I able to find a null entry in the registry.

    It definately exists when I run msconfig. The listing under STARTUP ITEM and COMMAND have absolutely nothing there, probably not even proper ascii space.
    I can even turn this invisible entry it on and off (with a tick mark) but I have no idea what is being enabled and disabled when I do so.
    I notice the location descriptor changes whether the entry is enabled or not. Is that normal?? When un-enabled the location is missing the "HKCU" part.

    I took two screenshots of the msconfig just in case someone wanted to see what an invisible entry looks like. I'd upload them but don't know if that is possible here.

    Thanks for your advice.

    Waz
     
  10. 2006/04/14
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hi Waz,

    I'd love to see it, never ran into something like this - but only contributing members can upload images.

    Regards - Charles
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.