KioskeaKioskeaCommentCaMarcheSign up, it's free !
Friday July 4, 2008 - 10:22:59 pm BST

Processes - wmiprvse - wmiprvse.exe

 

Windows Processes System processes Application Processes Other processes

wmiprvse - wmiprvse.exe

wmiprvse.exe (wmiprvse stands for Microsoft Windows Management Instrumentation ) is a generic process that manages clients in Windows XP. It is automatically launched the first time a client application connects, and is used to monitor system resources.

It is an essential system process which may not be terminated.

However, it may also be the Trojan horse W32/Sonebot-B, which creates a copy of itself in the folder %Windows%\System32, with the filename WMIPRVSE.EXE. The following entry in the registry confirms that the Trojan is present:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Kernel_check = wmiprvse.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Kernel_check = wmiprvse.exe

This document entitled « Processes - wmiprvse - wmiprvse.exe » from Kioskea (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the licence, as this note appears clearly.