Executables getting "Locked" in the System (PID 4) process.
**EDIT I really should not be saying "Programs" because I've not run them, they've been placed there, or removed from a spot, not run, and are still "There" for a minute or longer after I remove them, I have to log out and log back in to fix it, and it is getting SERIOUSLY tedious. For some reason programs are just recently on my windows 7 install getting "Locked" in the System process. For instance, if I remove a program (With Programs and Features or by straight up Shift+Deleting them) while they are NOT running (can't do anyway?) they "delete" but THEN if you refresh the directory the files are STILL THERE. As far as I know, this is ONLY happening with Executable programs, and just today I had it happen when I installed an application. I couldn't figure out why I couldn't patch it immediately after I installed raided security permissions took ownership just to open Process Explorer and search for the executable name to find it was being held inside System process. There is neither a virus nor rootkit doing it, unless it fooled both GMER and Combofix. And even if it did then, it would have to fool me. I'm mainly looking for people to throw ideas at this. No I've not recently updated windows, I have that off. Do not write a single post about it, you will be ignored and if I can, reported for thread hijacking, unless you have something TRULY constructive to say as in "It was fixed in this kb******** update." I do not have antivirus, previous rant applies.
July 6th, 2012 2:50am

To say the truth, I cannot retrieve any important information from your description. I guess that you use more than one antivirus-antimalware software and the situation is result of this "mess". Either use AV programs removal and test the functionality, or install vanilla plain operating system, place drivers in recommended order (chipset first), update, install applications while checking functionality after every install and finaly use MS Security Essentials, update and check it. For tools that you tested use their repective support of contact mails. Regards Milos
Free Windows Admin Tool Kit Click here and download it now
July 6th, 2012 4:27am

Okay let me roll this by you. I use no Antivirus-Antimalware software. Plain and simple. All drivers are stock, and there are no "unnecessary" drivers installed except specific ones such as the ones used in programs like DS3_Tool which is a program that enables you to hook up controllers to your PC and emulate functions. You're not grasping the nature of my issue. Windows, ITSELF, the System (PID 4) process is at times, taking hold of files. For instance, if I run an installer for "Program X" the program will install correctly but there will be a time, shortly after installing it, that the windows System process has hold over any executables that were created by the installer (ex. programx.exe) will be in use by the System process for up to 5 minutes. I believe a related issue comes when uninstalling programs as well - if I uninstall a program with Programs and Features *OR* if I shift+delete the files, not using windows installer, it will "successfully" (By this I mean it does not come up saying it couldn't delete a file) delete the files I select, however when I refresh the folder the folder shows back up and the only things inside are the executable files. Let me throw you an example: I'm working in C:\Program Files(x86)\. From this directory I delete the directory ProgramX (C:\Program Files(x86)\ProgramX\). It will disappear, but if REFRESH the folder (F5) the folder reappears and has only executables in it. It doesn't matter what program it is, either. But after about 5 minutes, most of the time a little less, it finally goes away. Now let me reiterate. I do not have antiviruses installed, I do not have ANY viruses, or rootkits, or malware, or spyware. Brush this out of your mind. This is a WINDOWS issue, possibly there could feasibly be a driver issue to go along with this, but I doubt it because I've not installed anything recently that is not from a reputable source, EX. Electronic Arts, Blizzard Entertainment, and this problem started happening out of the blue. Now with all that said, I would like some suggestions and I will appropriately apply with feedback. Also if you do not know what GMER and Combofix are, I would be more than happy to explain them to you and get you some appropriate sourcing. Put simply GMER is a rootkit detection tool that only runs as an executable, there is only ever a driver loaded when the program runs. Combofix is as the name implies a spyware/malware/rootkit fix-it-all tool that is very frequently updated and takes care of a LOT of very bad malware. Some versions of TDSS (Alueron), fake antiviruses, and many more.
July 6th, 2012 5:33pm

Hi, Firstly, I would like to verify when did this issue occur? What you have done before this issue happened? Meanwhile, I suggest you try the following: 1. Perform a system restore to check the result 2. Use Microsoft Security Essentials to scan the system to ensure there is no virus 3. Run System File Checker tool to check the system files 4. Test the issue in Safe Mode Hope this helps Vincent Wang TechNet Community Support
Free Windows Admin Tool Kit Click here and download it now
July 9th, 2012 5:18am

Hi, Firstly, I would like to verify when did this issue occur? What you have done before this issue happened? Meanwhile, I suggest you try the following: 1. Perform a system restore to check the result 2. Use Microsoft Security Essentials to scan the system to ensure there is no virus 3. Run System File Checker tool to check the system files 4. Test the issue in Safe Mode Hope this helps Vincent Wang TechNet Community Support
July 9th, 2012 5:19am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics