Hi Guys , The http sites down so Im using a newsreader, I apologize if
Ive missed a post that explains this, Are we sure its not the genuine
Microsoft wmiprvse.exe file ?? It could start up for alot of different
reasons and doesnt run for very long.
To Make it appear in task manager and MSAS under running processes
(Advanced Tools), Goto Start Menu and right click My Computer, Next
choose Manage , Click the Plus (+) next to 'Services and Applications'
then Left click WMI Control then Right click and choose 'Properties'
It will then show in task manager and in running processes of MS Antispy
Microsoft Antispyware shows it as Microsoft WMI for the name and
wmiprvse.exe (C:WINDOWS\System32\wbem\wmiprvse.exe) as the path to the
file.
It only runs for about 1 minute then stops and Microsoft Antispy will
display the details while its running and say its a known process plus
you can stop it with MSAS,
After about 1 minute it will stop running which you can see that by
using Task Manager, It will be showing as a Network Service (Right click
a empty space on the system tray and choose Task Manager) but it doesnt
automatically remove itself from MS Antispy's running processes if you
stay on the runnings processes screen, If you click on it when its not
running then MSAS will not display any details about it and pressing
"Stop The Process From Running Now" will not do anything. If you go back
to "System Explorers" then open "Running Processes" again you will then
see its not listed.
Here's the locations you will find this file in and the sizes are based
on my XP SP2 machine(To view the size right click and choose properties)
C:\WINDOWS\$NtServicePackUninstall$\wmiprvse.exe 199 KB (203,776 bytes)
C:\WINDOWS\Prefetch\WMIPRVSE.EXE 26.7 KB (27,362 bytes)
C:\WINDOWS\ServicePackFiles\i386\wmiprvse.exe 213 KB (218,112 bytes)
C:\WINDOWS\system32\wbem\wmiprvse.exe 213 KB (218,112 bytes)
On Mine under Version is shows (Version 5.1.2600.2180)
To find out more about what it does follow the same path we used to make
it show up :
Goto Start Menu and right click My Computer, Next choose Manage , Click
the Plus (+) next to 'Services and Applications' then Left click WMI
Control then Right click and choose 'Help'
Here you find alot of details and different explanations for why it starts.
If you want a second opinion then upload the file at jotti's site and
have it checked for malware but it sounds like it's the genuine
Microsoft file and with it staying in running processes untill you leave
and reopen the page plus losing its details when it stops It maybe is
causing some confusion.
http://virusscan.jotti.org/
Hope That Helps
Andy