New
#1
Dual csrss.exe and conhost.exe are they virited?
Hi
I have seen two copies of csrss.exe in the run of Process Explorer, and can't figure out why there are two. Also is csrss.exe supposed to have this extra stuff on after the .exe part? (the added stuff looks like opening ports for sharing which is off)
=====
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
=====
The same file is loading up with csrss.exe it is conhost.exe and each occurrence of the conhost file has a different set of numbers after the .exe part as well.
=====(NT Authority/System in PE)
\??\C:\Windows\system32\conhost.exe "-19462917881928618761-14517701611313678421-1909588746-743542847-290976386389256608
=====
and the other is:
=====(NT Authority/Network Service in PE)
\??\C:\Windows\system32\conhost.exe "251829604-254933148129903086818709497291982502722-82799778550413321-274352356
=====
What is all this extra stuff after the .exe part of each file?
Any help would be great or is someone could look at their copies of these files in the system32 folder(win 7 64bit)