Process Explorer Question: Odd Path?

Carbonyl

New member
Power User
Local time
10:19 PM
Messages
76
Hi everyone. Sorry if this is the wrong place to ask this question, but I thought I might as well ask here.

A lot of the time I use Sysinternal's Process Explorer. Usually when running process explorer, hovering the mouse over a process shows both its list of services, and also the path from which that process is running. Typically I see "C:\{whatever}", which is what I'd expect.

This morning something peculiar happened while I was watching my computer boot up. A process named 'WMIADAP.exe' started to run (I think it was daughter to svchost, but I'm not sure). I know WMIADAP.exe is typically considered a legit program, but the copy on my harddrive isn't what's worrying me so much as the path of the one Process Explorer saw running. It only stayed running for a moment or two before closing itself, but I still managed to get the tooltip in that time. The path for this process was listed as below:



\\?\C:\Windows\System32\wbem\WMIADAP.exe



Now, I'm not sure what "\\?\C:\" means as a path, but my gut feeling is that it's a remote, network, or hidden drive, and not my hard drive, that this program is running from. Can anyone provide any insight, please, on why process explorer would list such a peculiar path name? For the record, I'm using the latest process explorer on Windows 7 Professional. Thanks!
 

My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 RTM
CPU
i7 920
Motherboard
eVGA x58 SLi
Memory
6 GB Patriot
Graphics Card(s)
eVGA GeForce 275 GTX
Sound Card
Soundblaster X-Fi Gamer
Monitor(s) Displays
Acer 225Tw
Hard Drives
WD 1 TB
PSU
Corsair 750 W
Case
Antec Twelve Hundred
Cooling
Stock
I believe that's just the fully qualified network name (UNC name) of your local C drive :)

If it were a remote machine the ? would be replaced by the machine name.


[Edit] Just looked it up, the \ \ ? \ part of the path specifies that it is a "long UNC name" actually. So the real path is just the C:... part [/edit]
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Scratch built
OS
Windows 7 x64 Ultimate
CPU
i7 960
Motherboard
Asus P6X58D
Memory
12 Gig Corsair Dominator
Graphics Card(s)
Nvidia 480
Sound Card
Maudio Delta 44 + breakout box
Monitor(s) Displays
Dell UltraSharp U2410 24in and Samsung 21 dual monitors
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
Primary: Intel X-25M G2 160G SSD
Secondary: Segate baracuda 1.0 TB
HDs in AHCI mode.
PSU
Corasair TX850
Case
Cooler Master HAF
Cooling
Corsair H50
Keyboard
Logitech G15 + N52 game pad
Mouse
Logitech MX518
Internet Speed
15kbs down 4.5kbps up
Other Info
WEI 7.6
CPU & RAM 7.6
Graphics 7.9
Hard disk 7.7
I believe that's just the fully qualified network name (UNC name) of your local C drive :)

If it were a remote machine the ? would be replaced by the machine name.

Huh, really? Well, that's good to know! I'm just perplexed because this seems to be the only process, and the only time, that the path has ever been displayed that way. Everything else seems happy to just call it 'C:\{Path}'. And I suppose I would have expected 'Localhost' or '127.0.0.1' over '?'.

Anyhow, if what you're saying is true, then I guess it's nothing to worry over! Thanks for the input.
 

My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 RTM
CPU
i7 920
Motherboard
eVGA x58 SLi
Memory
6 GB Patriot
Graphics Card(s)
eVGA GeForce 275 GTX
Sound Card
Soundblaster X-Fi Gamer
Monitor(s) Displays
Acer 225Tw
Hard Drives
WD 1 TB
PSU
Corsair 750 W
Case
Antec Twelve Hundred
Cooling
Stock
Back
Top