think tank forum

technology » track down the program

lucas's avatar
15 years ago
link
lucas
i ❤ demo
something keeps creating and writing to `C:\Log.txt`. i want to find out what program is doing this and kill it. how do i track it down?

here's what `C:\Log.txt` has in it:
呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌佇䙆਍䕓噒䍉彅佃呎佒彌䡓呕佄乗਍呗当佃华䱏彅佃乎䍅ൔ圊協卟卅䥓乏䱟䝏乏਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌佇䙆਍䕓噒䍉彅佃呎佒彌䡓呕佄乗਍呗当佃华䱏彅佃乎䍅ൔ圊協卟卅䥓乏䱟䝏乏਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌佇䙆਍䕓噒䍉彅佃呎佒彌䡓呕佄乗਍呗当佃华䱏彅佃乎䍅ൔ圊協卟卅䥓乏䱟䝏䙏െ匊剅䥖䕃䍟乏剔䱏卟啈䑔坏ൎ圊協卟卅䥓乏䱟䝏乏਍呗当佃华䱏彅佃乎䍅ൔ圊協卟卅䥓乏䱟䝏䙏െ匊剅䥖䕃䍟乏剔䱏卟啈䑔坏ൎ圊協䍟乏体䕌䍟乏䕎呃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍
nestor's avatar
15 years ago
link
nestor
nestor

Translation: Chinese (automatically detected) » English
呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌佇䙆਍䕓噒䍉彅佃呎佒彌䡓呕佄乗਍呗当佃华䱏彅佃乎䍅ൔ圊協卟卅䥓乏䱟䝏乏਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌佇䙆਍䕓噒䍉彅佃呎佒彌䡓呕佄乗਍呗当佃华䱏彅佃乎䍅ൔ圊協卟卅䥓乏䱟䝏乏਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌佇䙆਍䕓噒䍉彅佃呎佒彌䡓呕佄乗਍呗当佃华䱏彅佃乎䍅ൔ圊協卟卅䥓乏䱟䝏䙏െ匊剅䥖䕃䍟乏剔䱏卟啈䑔坏ൎ圊協卟卅䥓乏䱟䝏乏਍ 呗当佃华䱏彅佃乎䍅ൔ圊協卟卅䥓乏䱟䝏䙏െ匊剅䥖䕃䍟乏剔䱏卟啈䑔坏ൎ圊協䍟乏体䕌䍟乏䕎呃਍呗当䕓卓佉彎佌䭃਍呗当䕓卓佉彎乕佌䭃਍呗当䕓卓佉彎佌䭃਍ 呗当䕓卓佉彎乕佌䭃਍
Bai Sen, OU MU bends when䕓zhuo wretched ਍䭃chant when䕓zhuo bending Sen, OU MU乕਍ wretched䭃chant when䕓zhuo wretched bending Sen, OU MU䭃਍ chant when䕓zhuo bending Sen, OU MU乕਍ wretched䭃chant when䕓zhuo wretched bending Sen, OU MU䭃਍ chant when䕓Sen, OU MU乕zhuo bending䭃wretched ਍ Bai Zhuo䕓Sen, OU MU bends when wretched䙆queue䕓਍噒䍉Dianxiang彅feet佒indemnity䡓vomit when佄by Bai Dian Hua ਍䱏彅ൔ pigsty Dian䍅Association between porphyrin䥓thirty䱟lack䝏lack ਍ Bai Sen, OU MU bends when䕓zhuo wretched ਍䭃chant when䕓zhuo bending Sen, OU MU乕਍ wretched䭃chant when䕓zhuo wretched bending Sen, OU MU䭃਍ chant when䕓zhuo bending Sen, OU MU乕਍ wretched䭃chant when䕓zhuo wretched bending Sen, OU MU䭃਍ chant when䕓Sen, OU MU乕zhuo bending䭃wretched ਍ Bai Sen, OU MU bends when䕓zhuo䭃wretched ਍ Bai Zhuo䕓Sen, OU MU bends when乕wretched䭃਍ Bai Zhuo䕓Sen, OU MU bends when wretched䙆queue䕓਍噒䍉Dianxiang彅feet佒indemnity䡓vomit ਍佄by Bai When Dian Dian Hua䱏彅even䍅pigsty ൔ Association porphyrin thirty䥓lack䱟lack䝏਍ Bai Sen, OU MU bends when䕓zhuo wretched䭃਍ Bai Sen, OU MU bends when䕓zhuo乕wretched䭃਍ Bai Sen, OU MU bends when䕓zhuo wretched ਍䭃chant when䕓Sen, OU MU乕zhuo bending䭃wretched ਍ Bai Sen, OU MU bends when䕓zhuo䭃wretched ਍ Bai Zhuo䕓Sen, OU MU bends when乕wretched䭃਍ Bai Sen, OU MU bends when䕓zhuo䭃wretched ਍ Bai Zhuo䕓Sen, OU MU bends when乕wretched ਍䭃chant when䕓zhuo Sen, OU MU bending wretched䙆queue䕓਍噒䍉彅foot tenant佒indemnity by佄਍䡓vomit when Bai Hua Dian Dian䱏彅even䍅pigsty ൔ Association porphyrin䥓thirty䱟lack䝏䙏receive with both hands െ剅䥖䕃䍟lack porphyrin䱏tick啈䑔bad pigsty ൎ ADPL porphyrin䥓thirty䱟lack䝏lack ਍ chant when Dian Dian Hua䱏彅pigsty ൔ Association between䍅porphyrin䥓thirty䱟lack䝏䙏receive with both hands െ剅䥖䕃lack䍟tick䱏porphyrin啈䑔bad pigsty ൎ Association䍟poor body䕌uh䍟lack䕎਍ Bai Sen, OU MU bends when䕓zhuo wretched䭃਍ Bai Sen, OU MU bends when䕓zhuo wretched乕਍䭃Bai Sen, OU MU bends when䕓zhuo wretched䭃਍ Bai Sen, OU MU bends when䕓zhuo乕petty䭃਍

asemisldkfj's avatar
15 years ago
r2, link
asemisldkfj
the law is no protection
this is a neat mystery.

Event Viewer is usually totally useless, but it can't hurt to check it. Administrative Tools/Event Viewer.
DaGr8Gatzby's avatar
15 years ago
link
DaGr8Gatzby
Drunk by Myself
HAHAHAHA!!!!

Larz,

I've had this issue on a customer's server before. I think it's funny I actually started to type Dear Customer as my first 2 words. You need to get Process Monitor and filter for C:\Log.txt. Anytime that file is accessed, the program will actually register a hit. It may not stay there for long. I'm pretty sure there is a switch you can use that doesn't automatically refresh the buffer. Here is the link for this program:

http://technet.microsoft.com/en-us/sysinterna … 96645.aspx

Try that and get back with me.
Carpetsmoker's avatar
15 years ago
link
Carpetsmoker
Martin
You can use the Process Monitor (procmon) from SysInternals, keep it running in the background and filter for C:\Log.txt.

My guess is something funny is running in the background (?) You can see a list of startup stuff with autoruns (Also from SysInternals).

Post a HijackThis logfile if you're not sure.
asemisldkfj's avatar
15 years ago
link
asemisldkfj
the law is no protection
great post, gatz! that is an excellent program to know about and I'm going to tell my boss about it tomorrow.
lucas's avatar
15 years ago
link
lucas
i ❤ demo
thanks, guys. i looked at event viewer and other ms mmc snap-ins, but none seemed to be what i wanted. then i tried spybot to no avail.

so now i'll try out procmon. :)
lucas's avatar
15 years ago
r1, link
lucas
i ❤ demo
procmon found it!

C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe

so it's a lenovo thinkpad application! cool--some fuckhead chinese developer wanted to write some fairy tale to C:\Log.txt. this makes me extremely angry.

the same issue on the lenovo forum
bluet's avatar
15 years ago
link
bluet
cool, an easter egg!
nestor's avatar
15 years ago
link
nestor
nestor
that's pretty lame, I hate c:\ stuff. miraculously mine is relatively clean.
asemisldkfj's avatar
15 years ago
link
asemisldkfj
the law is no protection
I just installed procmon. it seems seriously powerful. I can't wait for a reason to use it, haha.
maple's avatar
15 years ago
link
maple
i like large datasets
procmon is the shit. so is filemon. used them both alot before.
maple's avatar
15 years ago
link
maple
i like large datasets
and tcpview (also from sysinternals, but owned by MS now i think)
DaGr8Gatzby's avatar
15 years ago
link
DaGr8Gatzby
Drunk by Myself
WinDirStat is nice too :)
lucas's avatar
15 years ago
link
lucas
i ❤ demo

Summary of changes

Version 1.52

* [Important] End of support for Windows 2000.
o Note: For Windows 2000 users, use the version 1.51a.
* (New) Adds the new feature, 'Use Energy Saving Wallpaper', in Battery Stretch.
* (New) Makes changes to some parts of user interface.
* (New) Changes that the display brightness increases and decreases immediately while operating the slider control.
* (Fix) Fixed an issue where changes in a power scheme were applied even if the Apply button was not clicked.
* (Fix) Fixed an issue that did not restore settings when a power scheme was changed and then the Cancel button was clicked.
* (Fix) Fixed an issue where the Battery Maintenance... button was not displayed if PeakShift was installed.
* (Fix) Fixed an issue that could not disable the "Beep when power state changes" setting in Global Power Settings.
* (Fix) Fixed an issue that took long to display the Power Manager Gauge in the task bar when the "Show Power Manager Gauge in task bar" setting was once disabled and then enabled.
* (Fix) Fixed an issue that created an unnecessary file under the root directory in the C drive.
* (Fix) Fixed an issue where the "Closing the lid" setting was changed to "No action" when the setting was set to "Puts the computer is Hibernate" and then the computer resumed normal operation from hibernation state.
* (Fix) Fixed an issue that displayed an error message when a link for battery information was clicked in the battery tab.
* (Fix) Fixed an issue that did not apply the "Lower display brightness" setting after a power scheme was created.


http://www-307.ibm.com/pc/support/site.wss/do … MIGR-70602

:D

/o/