Finding Malware with Sysinternals Process Explorer

Поділитися
Вставка
  • Опубліковано 13 січ 2025

КОМЕНТАРІ • 53

  • @Prof856
    @Prof856 3 роки тому +37

    I was paranoid about a program on my computer and my professor sent me this link. This was extremely helpful and set my mind at ease. Thank you!

    • @krah8052
      @krah8052  3 роки тому +10

      Glad it helped!

  • @kaylght2740
    @kaylght2740 2 роки тому +5

    Very useful and very good for beginners like me, you sir need a medal for this great tutorial.

  • @switchmusic2959
    @switchmusic2959 2 роки тому +17

    i have an svchost, isass and csrss that show no signatures, paths and cannot be scanned with virus total. what should i do?

    • @bazo0ky
      @bazo0ky Рік тому +5

      I have the same thing. Basically press Ctrl+D the look if it's verified by Microsoft.

    • @marlonhernandez6312
      @marlonhernandez6312 17 днів тому

      ​@@bazo0ky what if it says ristricted

    • @dovydasdovydas5465
      @dovydasdovydas5465 8 днів тому

      @@marlonhernandez6312 i have the same thing

  • @salvadorseekatzrisquez2947
    @salvadorseekatzrisquez2947 7 місяців тому +1

    Amazing video! I have been doing several of these for a lot of year but exceeded all the knowledge I had. Thanks for sharing... This is my first video.... So I am sure you should have some more great material... Subscribing!!!

  • @meckjoo
    @meckjoo 3 роки тому +1

    Great tutorial - I use this myself and instead of explaining to folks how to do it, I send them this link!

  • @aDenstech
    @aDenstech 7 місяців тому +1

    An awesome video, easy to understand and easy to implement. Thanks a lot.

  • @johnterdik4707
    @johnterdik4707 5 місяців тому +3

    In process explorer some entries for svchost.exe don't have a verified signature nor when I open the properties most of the items have no value. This is also true for csrss.exe, registry and other entries. Nor can they be verified in the properties window. Some of the entries can be Killed whereas others cannot. All of these have no verified signature.

  • @shibechef
    @shibechef 9 місяців тому +1

    for anyone struggling to open the folder as admin, you can just open the command prompt as admin, and then set your directory to the folder using cd (file path). for example mine was "cd C:\Users\Shibe\Downloads\SysinternalsSuite"

  • @redmockingbird4704
    @redmockingbird4704 Рік тому +1

    Excellen Video Professor - Great to the point presentation

  • @playmangostingiu2217
    @playmangostingiu2217 6 місяців тому

    Concise and effective teaching. Thank you sir.

  • @Craigdna
    @Craigdna Рік тому +1

    Thank you as that was an excellent presentation and made me much more informed. Very much appreciated.

  • @Martin-ot7xj
    @Martin-ot7xj Рік тому

    Hi there, it was a very useful and informative tutorial video. thnx

  • @jasonax1523
    @jasonax1523 Місяць тому

    This is great information, why doesn't Microsoft share this with consumers?

  • @icollided
    @icollided 11 місяців тому

    Great video. I had a trojan scare this week, and after doing these things, I'm thinking that it was a false positive.

  • @sechelemehesles7832
    @sechelemehesles7832 Рік тому

    Very useful and easy to understand. Thank you!

  • @austinmurphy9074
    @austinmurphy9074 5 місяців тому

    solid video. helpful tips and to the point!

  • @XtremuZ
    @XtremuZ 5 місяців тому +1

    This tool is underrated

  • @up9.
    @up9. 5 місяців тому

    at 1:55 * COMPANY NAME.
    my process explorer has a lot of programs running without COMPANY NAME.
    plus it is very unstable unlike your process explorer which is not moving. mine is very unstable and volatile programs are starting and ending every second.
    any suggestions?

    • @gtm5650
      @gtm5650 5 місяців тому

      Reinstall Windows

  • @RaeuberFotzenRotz
    @RaeuberFotzenRotz Рік тому

    Quick Guide thanks a lot.

  • @johnlemes
    @johnlemes 2 роки тому

    Hello!! thanks for the tutorial Great information. Would you please tell me how can find, using Process Explorer, which process creates temp files in the respective temp folder? Thank you

  • @anta-zj3bw
    @anta-zj3bw Рік тому

    Excellent, Sir!

  • @marlonbonilla919
    @marlonbonilla919 2 роки тому

    Thank you for the great work!

  • @sdfffdsf3t
    @sdfffdsf3t Рік тому +1

    ik i have malware or smth but the thing is i cant see the path command line current directory autostart location or really anything but ik its a virus that injected itself into the svchost.exe

  • @wznzgq1354
    @wznzgq1354 Рік тому

    what if the process has no handles and no dlls??

  • @AA-mc5il
    @AA-mc5il Рік тому

    oh sir this video is so awesome thak you

  • @W1llella
    @W1llella 7 місяців тому

    There are some in virustotal check that has count like 1/78 and some have "the system cannot find the file specified". What do i do to those?

    • @cyberoffense3808
      @cyberoffense3808 7 місяців тому +1

      I would say the file is suspect but most probably a false positive. The missing files are probably a permission issue or you need to clean out your system and registry.

  • @Heelo_0
    @Heelo_0 Рік тому

    it says The term 'procexp64.exe' is not recognized as the name of a cmdlet, function, script file, or operable
    program.

  • @rafaloleksiak2587
    @rafaloleksiak2587 2 роки тому

    very good help, thx

  • @gullible119
    @gullible119 9 місяців тому +1

    >finding malware
    >has CCleaner installed🚨

  • @wznzgq1354
    @wznzgq1354 Рік тому +1

    i have a bunch of processes with are without description and also have no dll's when i use ctrl+d, what could that mean?
    example smss.exe, Memory Compression, Interrupts, crss.exe, dllhost.exe, postgres.exe etc

  • @thaqvaylith1151
    @thaqvaylith1151 Рік тому

    thank you

  • @chriss1402
    @chriss1402 Рік тому

    ty, very nice

  • @captainspaulding7612
    @captainspaulding7612 2 роки тому +1

    hey man i have like 14 svchost.exe running is that normal ?

    • @Edison-newworldBlogspot
      @Edison-newworldBlogspot 2 роки тому +1

      It's normal only. You can check the location of the svchost.exe and if it is not from system folder and found in temp location or app data, then that process must be malicious.

    • @switchmusic2959
      @switchmusic2959 2 роки тому +3

      @@Edison-newworldBlogspot i have an svchost, isass and csrss that show no signatures, paths and cannot be scanned with virus total. what should i do?

    • @Arch50281
      @Arch50281 Рік тому

      I’ve also had a problem with this file occasionally spiking

  • @GordonMelsom
    @GordonMelsom 2 роки тому

    Too Good hank you

  • @notrhythm
    @notrhythm 10 місяців тому

    prime youtube content

  • @DumindaSamaranayake
    @DumindaSamaranayake Рік тому

    I notice 1 virus running on my machine
    I think it might be a false positive

  • @lynnbrandywgdrive7676
    @lynnbrandywgdrive7676 3 місяці тому

    Omg im about two weeks late watching this. I has the IOBITmalware on my computer n couldnt delete it. I cant believe microsoft knows about them but still they are on the microsoft store. Smdh

  • @doumi4570
    @doumi4570 2 роки тому

    Hey, i would like som sort of help. When i want to scan it with VirusTotal it normally writes hash submitted, but after few seconds it says The device connected to the system is not working on mostly apps. VirusTotal scans max of 10 apps. Thank You for your help. To the error i used translator, so it might be not acurrate.

  • @ЭльвираШамсутдинова-р1ю

    nice, thank you