Archived from groups: microsoft.public.windowsxp.perform_maintain (
More info?)
In a previous post I mentioned that the number of process modules is not
what matters - it's what those process modules are doing that counts.
You didn't mean to exclude me from "us normal folk" did you?
--
Ted Zieglar
"Bob Dietz" <rbdietz_1999@yahoo.com> wrote in message
news:e5d5ldv$EHA.608@TK2MSFTNGP15.phx.gbl...
> Ad-Aware and Process Viewer see the same modules, but total them up
> differently. For example:
> Process A
> Module 1
> Module 2
> Process B
> Module 1
> Module 3
> Process C
> Module 1
> Module 4
>
> Ad-aware would report:
> 3 Running Processes
> 6 Process Modules
>
> In Process Viewer, select the View> Module Usage menu item. Then look at
> the status bar of the newly opened window and you'd see '4 Module(s).'
>
> In both case there are exactly 4 modules in memory, but Module 1 is
> being used by three distinct processes.
>
> Your count of 1300+ modules is normal for Ad-Aware, but that doesn't
> tell you if they are all legit modules. If you're dealing with super
> critical data (access codes to Fort Knox, locations for the missing WMDs
> ...) and there has been an intrusion on the system --- you'd probably
> want to verify the location and version of each module as well as
> compare byte count and MD5 check sum of each module against a known good
> reference image.
>
> For us normal folk, if SpyBot, Ad-Aware and your anti-virus program all
> give clean scans we'll just assume the 400+ unique modules reported by
> Process Viewer are all OK.
>
> For more information see Robert Hensing's Weblog.
> http://weblogs.asp.net/robert_hensing/
> Robert Hensing is a member of the Microsoft Product
> Support Services Incident Response team.
>
> --
> Bob Dietz
>
> linda wrote:
> > i am having the same problem, im showing 1300 + modules , that info is
on the
> > ad ware when im doing a scan. is it normal to have that many modules?
and if
> > not how do u get rid of them or know which ones are okey to get rid of.
thx
> >
> > "Bob Dietz" wrote:
> >
> >
> >>jay wrote:
> >>
> >>>when i run adaware se, it says there are 36 process running and
1300+process
> >>>modules. what is a process module? also, when i come tothis site i can
never
> >>>sse the whole page, its cut off on the right. anyideas? thx, jay
> >>
> >>Typically they are DLLs opened by the parent EXE file.
> >>If you download Process Viewer -
> >>http://www.xmlsp.com/pview/prcview.htm
> >>you can see a list of running processes.
> >>If you right click on a process in the list one of the choices will be
> >>"Modules."
> >>
> >>--
> >>HTH
> >>Bob Dietz
> >>