How to get a service name from a process ID?


Recommended Posts

Services seem to run under services.exe -- A service always just looks like "services.exe" in the process list. Is there any way (any program, etc.) I can see which process is actually being executed?

My issue is that I have a service seemingly scanning my entire hard drive, and I have System Restore turned off, so I can't guess what it is.

where did you get the idea that services all run under services.exe?? Thats not true..

Anyway - what your looking for is tasklist

/SVC Displays services in each process.

tasklist /svc

example...
Image Name				   PID Services
========================= ====== =============================================
System Idle Process			0 N/A
System						 4 N/A
smss.exe					1012 N/A
csrss.exe				   1060 N/A
winlogon.exe				1084 N/A
services.exe				1128 Eventlog, PlugPlay
lsass.exe				   1140 ProtectedStorage, SamSs
svchost.exe				 1300 DcomLaunch, TermService
svchost.exe				 1460 RpcSs
svchost.exe				 1544 AudioSrv, CryptSvc, EventSystem, helpsvc,
								 HidServ, lanmanserver, lanmanworkstation,
								 Netman, Nla, seclogon, SENS,
								 ShellHWDetection, Themes, winmgmt, wuauserv
svchost.exe				 1588 Dnscache
svchost.exe				 1604 LmHosts, RemoteRegistry
spoolsv.exe				 1832 Spooler
agent.exe					204 AcronisAgent
schedul2.exe				 216 AcrSch2Svc
DkService.exe				304 Diskeeper
FrameworkService.exe		 352 McAfeeFramework
Mcshield.exe				 388 McShield
naPrdMgr.exe				 440 N/A

Ahhh! Thank you, BudMan!

(I have to admit I just went on intuition about all services being run under services.exe).

Okay so now I've determined the culprit: Eventlog (or PlugPlay). What would either of those services need to scan my hard drive for? In filemon I see a bunch of things like this:

8:33:54 AM	services.exe:964	READ 	C:\WINDOWS\system32\config\SYSTEM		Offset: 184320 Length: 4096	
8:33:54 AM	services.exe:964	QUERY INFORMATION	C:\WINDOWS\Help\iisHelp\iis\htm\asp\comp4dk5.htm	SUCCESS	FileNameInformation	
8:33:54 AM	services.exe:964	CLOSE	C:\WINDOWS\Help\iisHelp\iis\htm\asp\comp4d2o.htm	SUCCESS		
8:33:54 AM	services.exe:964	QUERY INFORMATION	C:\WINDOWS\Help\iisHelp\iis\htm\asp\comp4dk5.htm	SUCCESS	FileBasicInformation	
8:33:54 AM	services.exe:964	QUERY SECURITY	C:\WINDOWS\Help\iisHelp\iis\htm\asp\comp4dk5.htm	BUFFER OVERFLOW		
8:33:54 AM	services.exe:964	QUERY SECURITY	C:\WINDOWS\Help\iisHelp\iis\htm\asp\comp4dk5.htm	SUCCESS		
8:33:54 AM	services.exe:964	DIRECTORY	C:\WINDOWS\Help\iisHelp\iis\htm\asp	SUCCESS	FileNamesInformation	
8:33:54 AM	services.exe:964	OPEN	C:\WINDOWS\Help\iisHelp\iis\htm\asp\comp4ng2.htm	SUCCESS	Options: Open  Access: All	
8:33:54 AM	services.exe:964	QUERY INFORMATION	C:\WINDOWS\Help\iisHelp\iis\htm\asp\comp4ng2.htm	SUCCESS	FileNameInformation	

This is done for files all over my hdd. Any idea what this is all about?

Ahhh! Thank you, BudMan!

This is done for files all over my hdd. Any idea what this is all about?

Off the top I can not think why either of those would be accessing files?? I do not see my services.exe access files all over.. the eventlog sure, but not files from all over the drive..

If I had to guess I would guess some type of infection? Are you running any type of indexing software.. are you running a virus scan?

Could it have something to do with logging of people accessing websites? Your examples were IIS related..

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Personally, I think these things are way over rated and way over priced, even at this price. I recently had Frontier Fiber installed with 2 of these devices and although they worked, I switched back to my own router and AP setup and get way better consistency on wireless speed than with Eeros. Wired speed seems to be more consistent also. Will be returning Eeros soon. I had told Frontier I didn't want them to begin with.
    • Yes, exactly what I have been thinking. Don't make the context menu simpler, make it smarter to learn what I actually use. And then, give me the ability to pin settings that I rarely use but need forget where they are.
    • https://www.change.org/p/save-the-new-stargate-series-let-martin-gero-build-the-future-of-the-franchise?utm_source=share_petition&utm_medium=mobileNativeShare&utm_campaign=share_petition&recruited_by_id=376d0b10-cf3c-11e7-a513-03b837c94000&recruiter=836653795&share_id=jVyr5PGfkN Petition for anyone who's interested 
    • Here's how to watch Summer Game Fest 2026 and what to expect from the 2-hour showcase by Pulasthi Ariyasinghe The June game showcase schedule is packed, and with the Sony event already behind us, it's time for the next major presentation to come in swinging. Later today, Geoff Keighley will be bringing the 2026 edition of Summer Game Fest live from the Dolby Theatre in Los Angeles, California. For anyone wanting to tune in online, the Summer Game Fest showcase livestream will be kicking off at 2 PM PT | 5 PM ET | 10 PM BST later today, June 5. The jam-packed show is slated to run for about two hours, with platforms like YouTube (4K at 60FPS), Twitch, Facebook, or X being available for catching it. Like in previous years, separate streams featuring American Sign Language and Descriptive Audio are available on YouTube as well. Keighley has only dropped a few teasers about what gaming fans can expect to see at the show. This includes a new look at Star Wars Zero Company from EA, a major announcement from Guild Wars developer ArenaNet, more Clutch gameplay, and some sort of Sega presence. As for fan expectations, there is hype building about a Final Fantasy 7 Remake Part 3 reveal here, and we might see new details about announced games like Alien Isolation 2 as well. If you want even more games, keep in mind that right after the main kickoff event, the Day of the Devs showcase will begin its own festivities at 4 pm PT | 7 pm ET. This is focused entirely on upcoming indie games. Following this, the next major games showcase is slated to happen on June 7. Here, Microsoft is bringing the big guns with its Xbox Games Showcase and Gears of War E-Day Direct. Check out the full calendar for all of the June events over here.
    • AI is destroying jobs like nothing before
  • Recent Achievements

    • Conversation Starter
      FBSPL earned a badge
      Conversation Starter
    • Week One Done
      I2D earned a badge
      Week One Done
    • Week One Done
      Dr Jared Dental Studio earned a badge
      Week One Done
    • Week One Done
      RG INVESTMENT GROUP earned a badge
      Week One Done
    • Very Popular
      The Norwegian Drone Pilot earned a badge
      Very Popular
  • Popular Contributors

    1. 1
      +primortal
      487
    2. 2
      PsYcHoKiLLa
      262
    3. 3
      Skyfrog
      85
    4. 4
      FloatingFatMan
      64
    5. 5
      Michael Scrip
      62
  • Tell a friend

    Love Neowin? Tell a friend!