usnsvc.exe is the Messenger Sharing USN Journal Reader Service installed with MSN Messenger (or Windows Live Messenger). It is located at "C:\Program files\MSN Messenger. If it is located elsewhere, then it could be
a variant of the IRCBot family of worms and IRC backdoor Trojans.
You can download and use
Process Explorer or
Glarysoft Process Manager to investigate all running processes and gather additional information to identify and resolve problems. These tools will show the process CPU usage, a description and its
path location. If you right-click on the file in question and select properties, you will see more details about the file.
The Process Explorer window shows two panes by default: the
upper pane is always a process list and the
bottom pane either shows the list of DLLs loaded into the process selected in the upper pane, or the list of operating system resource handles (files, Registry keys, synchronization objects) the process has open. In the menu at the top select View > Lower Pane View to change between DLLs and Handles.
Anytime you come across a suspicious file which you cannot find any information, the file has a legitimate name but is not located where it is supposed to be, or you want a second opinion, submit it to
jotti's virusscan or
virustotal.com. In the "
File to upload & scan" box, browse to the location of the suspicious file and submit (upload) it for scanning/analysis.
Post back with the results of the file analysis.