Author Topic: Windows XP Help-- Process Tracking?  (Read 1397 times)

Ben

  • Administrator
  • Senior Member
  • *****
  • Posts: 46,074
  • I'm an Extremist!
Windows XP Help-- Process Tracking?
« on: April 04, 2006, 04:10:33 AM »
Does anyone have any suggestions for (preferably free) software that can track process history to some kind of output file (or a way to make windoze do it)? I think this is what I need, but if not maybe someone can enlighten me:

I just noticed last night that on my XP machine, every five or so minutes (I haven't actually timed it) I get one of those "minimized" boxes popping up in the toolbar. The icon on it is just the little white and blue generic windows icon for a running exe. it lasts for a few seconds, then goes away. I can't be sure when this started, so can't trace it to any specific software install, and I don't want to have to uninstall a bunch of stuff to see what's causing it. I figure if  I can track my process history, I can track the mystery down by proccess/program name.

It worries me in that its behavior is indicative of what I might expect spyware to do. I've already done full spyware, etc. checks using multiple programs and have come up clean.
"I'm a foolish old man that has been drawn into a wild goose chase by a harpy in trousers and a nincompoop."

Sergeant Bob

  • friend
  • Senior Member
  • ***
  • Posts: 5,861
Windows XP Help-- Process Tracking?
« Reply #1 on: April 04, 2006, 06:27:54 AM »
You could try hitting "Control-Alt-Delete" and bring up the Task Manager.
Click on "Applications" to see what is running at the moment.
Check "Processes" to see what is using the CPU at any given moment.
You can see when it is happening and whether it is accessing the internet using "Performance" and "Networking" tabs.
Have you updated your spyware definitions and antivirus lately?
Personally, I do not understand how a bunch of people demanding a bigger govt can call themselves anarchist.
I meet lots of folks like this, claim to be anarchist but really they're just liberals with pierced genitals. - gunsmith

I already have canned butter, buying more. Canned blueberries, some pancake making dry goods and the end of the world is gonna be delicious.  -French G

Sindawe

  • friend
  • Senior Member
  • ***
  • Posts: 2,938
  • Vashneesht
Windows XP Help-- Process Tracking?
« Reply #2 on: April 04, 2006, 06:28:49 AM »
Not process tracking, but the utility Process Explorer ( http://www.sysinternals.com/Utilities/ProcessExplorer.html ) will show you ALL the running processes on a machine, along with their originationg file name and path, vender and a host of other usefull tidbits of information.  It also can be used to kill most of them at will.  The only thing I've not been able to kill with it was an errant zombie from a hosed remote desktop session on a server.

On Edit: Oh, and its free.
I am free, no matter what rules surround me. If I find them tolerable, I tolerate them; if I find them too obnoxious, I break them. I am free because I know that I alone am morally responsible for everything I do.

Ben

  • Administrator
  • Senior Member
  • *****
  • Posts: 46,074
  • I'm an Extremist!
Windows XP Help-- Process Tracking?
« Reply #3 on: April 04, 2006, 06:58:57 AM »
Yeah, I've tried watching the process window, but the little sucker is too fast for me. I'm thinking if I can find something that does a log file of some kind, I can watch the clock a few times when it pops up try and match up process / program name to times it appeared in the history.

Maybe Sysinternals has an easier to read window for catching stuff on the fly. I'll give that a try.
"I'm a foolish old man that has been drawn into a wild goose chase by a harpy in trousers and a nincompoop."

Sergeant Bob

  • friend
  • Senior Member
  • ***
  • Posts: 5,861
Windows XP Help-- Process Tracking?
« Reply #4 on: April 04, 2006, 08:13:55 AM »
Looks like a pretty handy prog Sindawe, thanks.
Personally, I do not understand how a bunch of people demanding a bigger govt can call themselves anarchist.
I meet lots of folks like this, claim to be anarchist but really they're just liberals with pierced genitals. - gunsmith

I already have canned butter, buying more. Canned blueberries, some pancake making dry goods and the end of the world is gonna be delicious.  -French G

client32

  • friend
  • Senior Member
  • ***
  • Posts: 537
Windows XP Help-- Process Tracking?
« Reply #5 on: April 04, 2006, 08:27:39 AM »
I think you can do this without any extra programs.

You will have to go to your local security settings. (Control Panel -> Administrative Tools -> Local Security Settings)
In there, expand Local Policies.  Single left click Audit Policy.  In the right hand pane, there will be a list of stuff.  
Double click "Audit process tracking" and check the boxes on the new screen.  Click OK.

What you have accomplished is that all processes (starting, stopping and other things) will now be placed in the event viewer.  You can go there to see what the process was after it pops up again.  (control panel -> admin tools -> event viewer)

Hope that works.
Admit nothing, deny everything, make counter-accusations - APS homepage 3/4/05 - 5/20/05

Never ask a man where he is from. If he is from Texas he will tell you. If he isn't there's no need to embarass him.

Ben

  • Administrator
  • Senior Member
  • *****
  • Posts: 46,074
  • I'm an Extremist!
Windows XP Help-- Process Tracking?
« Reply #6 on: April 04, 2006, 10:08:16 AM »
Cool -- I'll try that when I get back to the house tonight.
"I'm a foolish old man that has been drawn into a wild goose chase by a harpy in trousers and a nincompoop."

Ben

  • Administrator
  • Senior Member
  • *****
  • Posts: 46,074
  • I'm an Extremist!
Windows XP Help-- Process Tracking?
« Reply #7 on: April 04, 2006, 07:41:49 PM »
Well, running the process audit did the trick (thanks client32!). Checking after a few runs, I found the .exe to be a core component of the stupid software for my HP multifunction. Harmless, just annoying to see the minimized window show up in the taskbar.
"I'm a foolish old man that has been drawn into a wild goose chase by a harpy in trousers and a nincompoop."

client32

  • friend
  • Senior Member
  • ***
  • Posts: 537
Windows XP Help-- Process Tracking?
« Reply #8 on: April 05, 2006, 04:55:29 AM »
glad I could help

Wink
Admit nothing, deny everything, make counter-accusations - APS homepage 3/4/05 - 5/20/05

Never ask a man where he is from. If he is from Texas he will tell you. If he isn't there's no need to embarass him.