Finding Malware with Sysinternals Process Explorer

Поделиться
HTML-код
  • Опубликовано: 27 авг 2024
  • Finding Malware with Sysinternals Process Explorer
    In this short video, Professor K shows you how to find malware that may be running as a process on your PC using Sysinternals Process Explorer.
    Process Explorer is a tool that lets us access a lot of information about processes running on a machine and offers some excellent functionalities out of the box, which we can leverage to analyze and determine if something is malicious.
    docs.microsoft...
    docs.microsoft...
    www.udemy.com/...

Комментарии • 48

  • @Prof856
    @Prof856 3 года назад +31

    I was paranoid about a program on my computer and my professor sent me this link. This was extremely helpful and set my mind at ease. Thank you!

    • @krah8052
      @krah8052  2 года назад +10

      Glad it helped!

  • @kaylght2740
    @kaylght2740 Год назад +5

    Very useful and very good for beginners like me, you sir need a medal for this great tutorial.

  • @aDenstech
    @aDenstech 3 месяца назад +1

    An awesome video, easy to understand and easy to implement. Thanks a lot.

  • @playmangostingiu2217
    @playmangostingiu2217 Месяц назад

    Concise and effective teaching. Thank you sir.

  • @shibechef
    @shibechef 4 месяца назад +1

    for anyone struggling to open the folder as admin, you can just open the command prompt as admin, and then set your directory to the folder using cd (file path). for example mine was "cd C:\Users\Shibe\Downloads\SysinternalsSuite"

  • @meckjoo
    @meckjoo 2 года назад +1

    Great tutorial - I use this myself and instead of explaining to folks how to do it, I send them this link!

  • @switchmusic2959
    @switchmusic2959 Год назад +15

    i have an svchost, isass and csrss that show no signatures, paths and cannot be scanned with virus total. what should i do?

    • @bazo0ky
      @bazo0ky Год назад +2

      I have the same thing. Basically press Ctrl+D the look if it's verified by Microsoft.

  • @XtremuZ
    @XtremuZ 19 дней назад

    This tool is underrated

  • @icollided
    @icollided 6 месяцев назад

    Great video. I had a trojan scare this week, and after doing these things, I'm thinking that it was a false positive.

  • @redmockingbird4704
    @redmockingbird4704 10 месяцев назад +1

    Excellen Video Professor - Great to the point presentation

  • @salvadorseekatzrisquez2947
    @salvadorseekatzrisquez2947 2 месяца назад

    Amazing video! I have been doing several of these for a lot of year but exceeded all the knowledge I had. Thanks for sharing... This is my first video.... So I am sure you should have some more great material... Subscribing!!!

  • @austinmurphy9074
    @austinmurphy9074 Месяц назад

    solid video. helpful tips and to the point!

  • @sechelemehesles7832
    @sechelemehesles7832 8 месяцев назад

    Very useful and easy to understand. Thank you!

  • @Martin-ot7xj
    @Martin-ot7xj 8 месяцев назад

    Hi there, it was a very useful and informative tutorial video. thnx

  • @Craigdna
    @Craigdna 11 месяцев назад

    Thank you as that was an excellent presentation and made me much more informed. Very much appreciated.

  • @johnterdik4707
    @johnterdik4707 Месяц назад

    In process explorer some entries for svchost.exe don't have a verified signature nor when I open the properties most of the items have no value. This is also true for csrss.exe, registry and other entries. Nor can they be verified in the properties window. Some of the entries can be Killed whereas others cannot. All of these have no verified signature.

  • @anta-zj3bw
    @anta-zj3bw Год назад

    Excellent, Sir!

  • @johnlemes
    @johnlemes 2 года назад

    Hello!! thanks for the tutorial Great information. Would you please tell me how can find, using Process Explorer, which process creates temp files in the respective temp folder? Thank you

  • @AA-mc5il
    @AA-mc5il 11 месяцев назад

    oh sir this video is so awesome thak you

  • @marlonbonilla919
    @marlonbonilla919 2 года назад

    Thank you for the great work!

  • @up9.
    @up9. 26 дней назад

    at 1:55 * COMPANY NAME.
    my process explorer has a lot of programs running without COMPANY NAME.
    plus it is very unstable unlike your process explorer which is not moving. mine is very unstable and volatile programs are starting and ending every second.
    any suggestions?

    • @gtm5650
      @gtm5650 15 дней назад

      Reinstall Windows

  • @notrhythm
    @notrhythm 5 месяцев назад

    prime youtube content

  • @sdfffdsf3t
    @sdfffdsf3t Год назад +1

    ik i have malware or smth but the thing is i cant see the path command line current directory autostart location or really anything but ik its a virus that injected itself into the svchost.exe

  • @wznzgq1354
    @wznzgq1354 Год назад

    what if the process has no handles and no dlls??

  • @rafaloleksiak2587
    @rafaloleksiak2587 2 года назад

    very good help, thx

  • @chriss1402
    @chriss1402 10 месяцев назад

    ty, very nice

  • @thaqvaylith1151
    @thaqvaylith1151 Год назад

    thank you

  • @wznzgq1354
    @wznzgq1354 Год назад +1

    i have a bunch of processes with are without description and also have no dll's when i use ctrl+d, what could that mean?
    example smss.exe, Memory Compression, Interrupts, crss.exe, dllhost.exe, postgres.exe etc

  • @W1llella
    @W1llella 2 месяца назад

    There are some in virustotal check that has count like 1/78 and some have "the system cannot find the file specified". What do i do to those?

    • @cyberoffense3808
      @cyberoffense3808 2 месяца назад +1

      I would say the file is suspect but most probably a false positive. The missing files are probably a permission issue or you need to clean out your system and registry.

  • @Heelo_0
    @Heelo_0 9 месяцев назад

    it says The term 'procexp64.exe' is not recognized as the name of a cmdlet, function, script file, or operable
    program.

  • @GordonMelsom
    @GordonMelsom 2 года назад

    Too Good hank you

  • @gullible119
    @gullible119 4 месяца назад

    >finding malware
    >has CCleaner installed🚨

  • @RaeuberFotzenRotz
    @RaeuberFotzenRotz 9 месяцев назад

    Quick Guide thanks a lot.

  • @DumindaSamaranayake
    @DumindaSamaranayake Год назад

    I notice 1 virus running on my machine
    I think it might be a false positive

  • @captainspaulding7612
    @captainspaulding7612 Год назад +1

    hey man i have like 14 svchost.exe running is that normal ?

    • @Edison-newworldBlogspot
      @Edison-newworldBlogspot Год назад +1

      It's normal only. You can check the location of the svchost.exe and if it is not from system folder and found in temp location or app data, then that process must be malicious.

    • @switchmusic2959
      @switchmusic2959 Год назад +3

      @@Edison-newworldBlogspot i have an svchost, isass and csrss that show no signatures, paths and cannot be scanned with virus total. what should i do?

    • @Arch50281
      @Arch50281 Год назад

      I’ve also had a problem with this file occasionally spiking

  • @doumi4570
    @doumi4570 Год назад

    Hey, i would like som sort of help. When i want to scan it with VirusTotal it normally writes hash submitted, but after few seconds it says The device connected to the system is not working on mostly apps. VirusTotal scans max of 10 apps. Thank You for your help. To the error i used translator, so it might be not acurrate.

    • @Aury-H
      @Aury-H Год назад +1

      Same issue