Have you checked out the latest version of Sysinternals Process Explorer? This remains one of my favorite tools to use when trying to get a grip of what’s really going on in a Windows machine.
Ever wondered which program has a particular file or directory open? Now you can find out. Process Explorer shows you information about which handles and DLLs processes have opened or loaded.
Now there’s one more really handy feature: it will submit the running processes to VirusTotal.com for further analysis. Don’t panic! It isn’t sending the actual files; it is sending hashes of them and it does it all very quickly. VirusTotal submits each process to up to 50 AV scanners and sends back the results of the scan. Just click the link in the right-most column to see the scan results.
Slick. Read more →