here a list of handles that are opeed by Faxman4, created with sysinternals process explorer.
Martin
Process: FaxMan4.exe Pid: 5052
Type Name
Desktop \Default
Directory \KnownDlls
Directory \BaseNamedObjects
Event \BaseNamedObjects\DINPUTWINMM
Event \BaseNamedObjects\FAXMAN4Exec
Event \BaseNamedObjects\FAXMAN4Done
Event \BaseNamedObjects\-1819520406-0Event
File C:\WINDOWS\system32
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.3790.3959_x-ww_D8713E55
File \Device\WMIDataDevice
File \Device\WMIDataDevice
File \Device\KsecDD
File \Device\NamedPipe\net\NtControlPipe87
File D:\Server\PROG\faxServer7\faxman4.db
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_5.82.3790.3959_x-ww_78FCF8D0
File D:\Server\PROG\faxServer7\FaxMan-20091126.log
File D:\Server\PROG\faxServer7\FaxMan-20091126.log
File D:\Server\PROG\faxServer7\FaxMan-20091126.log
// Removed > 8100 FaxMan log entries for sake of readability and performance //
File D:\Server\PROG\faxServer7\Port01-20091130.log
File D:\Server\PROG\faxServer7\Port01-20091130.log
File D:\Server\PROG\faxServer7\Port01-20091130.log
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
Key HKLM
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
KeyedEvent \KernelObjects\CritSecOutOfMemoryEvent
Mutant \BaseNamedObjects\FaxMan4Svr
Mutant \BaseNamedObjects\FAXMAN4Free
Mutant \BaseNamedObjects\-1819520406-0EvtFree
Process FaxMan4.exe(5052)
Section \BaseNamedObjects\FAXMAN4
Section \BaseNamedObjects\-1819520406-0
Semaphore \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
Thread FaxMan4.exe(5052): 6028
Thread FaxMan4.exe(5052): 4340
Thread FaxMan4.exe(5052): 4064
WindowStation \Windows\WindowStations\WinSta0
WindowStation \Windows\WindowStations\WinSta0