Process Explorer is a powerful Windows tool that provides detailed information about running processes, allowing users to monitor, troubleshoot, and detect suspicious activities. It can be used to detect potential malware or harmful processes by analyzing various aspects of running applications.
Here’s a step-by-step guide on how to use Process Explorer to identify suspicious processes on your system.
- Go to the official Microsoft Sysinternals website and download Process Explorer: Download Process Explorer.
- Once downloaded, extract the ZIP file to a folder.
- Open the folder where you extracted the files and run
procexp64.exe(64-bit) orprocexp.exe(32-bit) as Administrator by right-clicking and selecting "Run as Administrator."
When Process Explorer starts, you’ll see an interface that lists all running processes, showing their hierarchy, memory usage, CPU usage, and much more.
-
The main window shows a tree of all running processes, with each child process listed under its parent.
-
Processes are color-coded to indicate their status:
- Pink: Suspended processes.
- Light Blue: Processes running under the same user as you.
- Dark Blue: Services or processes running under system accounts.
- Green: New processes (appearing and disappearing quickly may be suspicious).
- Red: Processes that have just exited.
- Various columns show information such as:
- Process ID (PID)
- CPU usage
- Memory usage
- Other process information
Now that you are familiar with the interface, follow these steps to investigate potentially suspicious processes.
- Scan the list of running processes and identify any names that you don’t recognize.
- Some malware disguises itself with legitimate-looking names, but odd names can be a red flag.
- Legitimate processes should typically be from trusted sources (e.g., Microsoft, Intel, Adobe, etc.).
- Right-click any suspicious process and select Properties.
- Go to the Image tab and check if the process has a valid Digital Signature.
- Legitimate applications from trusted developers will have valid signatures.
- Processes without signatures or with invalid signatures are suspicious.
- In the Properties window of the suspicious process, look under the Image tab for the Path.
- Verify if the process is located in a legitimate directory.
- For example, legitimate system processes should reside in:
C:\Windows\System32
- If the process is running from a temporary folder, user folder, or a random directory, it might be malware.
- Look at the CPU, Memory, and Disk usage columns.
- A process that is using an unusual amount of resources without explanation could be malicious.
- For example, high CPU usage on a process like
svchost.execan indicate malware.
- Look at the Description and Company Name columns in Process Explorer.
- Legitimate processes usually provide clear descriptions and are tied to well-known companies.
- Lack of information or suspicious company names should prompt further investigation.
-
Some malware communicates with external servers.
-
You can inspect a process’s network connections:
- Right-click on the process and select Properties.
- Go to the TCP/IP tab to see network activity associated with the process.
- Unexpected or unexplained external connections can indicate a malicious process.
If you find a process that looks suspicious or unfamiliar:
- Perform a quick Google search using the process name (e.g.,
processname.exe) to find out whether the process is known to be safe or malicious.
- Use online databases such as VirusTotal or ProcessLibrary to verify whether the process is known for being part of malware.
If you find a process that you believe is malicious:
- Right-click the suspicious process and select Kill Process to terminate it immediately.
- If you are unsure and want to prevent the process from causing damage while you investigate further, right-click and select Suspend.
- Go to the location of the file using the Path from the Properties window and delete the executable file if confirmed to be malware.
- Be cautious, as some malware might prevent you from deleting it. In such cases, you may need to boot into Safe Mode or use a specialized tool.
After terminating any suspicious processes, it’s a good idea to:
- Run a full antivirus scan using trusted antivirus software.
- Use malware removal tools like Malwarebytes or Windows Defender to perform an in-depth scan of your system.
- You notice a process called
randomname123.exeusing an unusually high amount of CPU. - Right-click it, select Properties, and find it is running from a suspicious folder, not the system folder.
- You check the TCP/IP tab and see it is making external connections to unknown IP addresses.
- A quick search shows that this process is often associated with a specific type of malware.
- You kill the process and remove the executable file from the system.
Running processes were successfully monitored and analyzed using Process Explorer.
Process details such as digital signatures, file paths, resource usage and network activity were examined to identify potentially suspicious processes.