
Quote: Originally Posted by
jimbo45
Hi there
Therein Lies the rub

.
You can only DETECT what your "dectection" software can find. - If it doesn't find anything can you really say that there is NOTHING to detect.
Detection software can be pretty good - but you are really using a similar argument to people who think S.E.T.I is a waste of time -- the fact you haven't found / measured anything doesn't mean that it isn't there or doesn't exist.
That logic is a bit flawed and its clear you dont fully understand how ProcessHacker/ProcessExplorer is designed and used and why these tools are so great.
Your anti-virus signatures are created by humans after they detect and analyze something that they currently dont detect or know about, now if something could be that undetectable then how would they ever know about it to be able to ever analyze it and create a signature for it? Ill wait for you to explain that one
The difference between anti-virus detection and ProcessHacker is that the detection 'software' is you the user, we display everything about a process/module/thread/.../... etc.. you could ever possibly know, the exact same things your antivirus vendor uses when their staff analyze software, the difference being that its you the user that needs to know if its indeed legit.
We believe A human is much better at detection than an automated system like anti-virus could ever possibly hope to achieve and this is where Process Hacker and Process Explorer's true ability resides.
So yes 'therein Lies the rub', Process Hacker/Explorer is useless for anyone who doesn't know how things should be, doesn't know how things work, doesn't know any better, doesn't understand or doesn't care. If your in this group then you have no chance at detecting anything but your own stupidity