Process Explorer + VirusTotal (to check all processes with 50+ AV's)

   Information
Process Explorer by Sysinternals(Microsoft) is a more advanced alternative to Windows Task Manager

VirusTotal.com is a multi-engined scanner service from Google with more than 50 different anti-virus products including:
AVG, Avast, Avira, BitDefender, ESET, F-Secure, GData, Kaspersky, Malwarebytes, Microsoft, Norman, Panda, SUPERAntiSpyware, Sophos, Symantec, TrendMicro and many more.

The VirusTotal integration in Process Explorer is very fast because it only sends file hashes, a unique content identifier, and not the files itself. It's dependent of previous scans on VirusTotal for every specific file and version, but because VirusTotal is a heavily used worldwide service you often get fresh results for most files.

1. Download Process Explorer from its homepage: Process Explorer
or use the direct download link
Download



2. Extract the contents from the ZIP file preferably to a new folder. If you don't have a 3rd party Zip program you can use the Windows built-in function: right click the Zip file and select "Extract all..."

3. Double-click the file procexp.exe

4. Enable "Check VirusTotal.com"PE enable VT.png

The new column VirusTotal will be added automatically, and initially show "Hash submitted...". After a few seconds it will show the result:PE VT standard.png
5. Processes that run as System and not as standard user, won't show a VirusTotal result until we restart Process Explorer with elevated permissions:PE admin launch.png

If you get a UAC prompt click Yes. Now, after a few seconds, we will see the VirusTotal result for every process:PE admin.png

   Information
A VirusTotal result of 0/55 means that 55 anti-virus products have checked the file and that non of them detected anything!

Click the result/link to open the detailed report in a web browser. There you'll find when the scan was done and other useful information like what anti-virus products detected anything and what type of possible infection/malware.


Example of a VirusTotal detection:
PE VT detection.png

   Note
If only one AV detected something chances are that it's a "false positive" (wrongly detected) and that the file is clean. Click the VirusTotal link to get more details about it.

6. If you have processes that show "Unknown" in the VirusTotal column, it means that specific file and version has never been uploaded to VirusTotal. To automatically upload these files to VirusTotal select this option:PE submit unknown.png
7. To submit a file to VirusTotal manually, any file (not only "Unknown" ones), which means to upload and re-scan the file, double click a process, go to the Image tab and click this button:PE submit one.png

You can then exit the Properties window and wait until you see a result in the VirusTotal column for that process. It'll take a few minutes.
8. You can also do a VirusTotal check for all the DLL files a process uses. Select a process and press Ctrl+L to toggle the lower pane. It will submit the file hashes to VirusTotal and show the result after a few seconds:PE lower pane.png

If the VirusTotal column isn't shown in the lower pane, right-click a column header to select columns
If other files than DLL's are shown, go to menu View - Lower Pane View - and select DLLs
9. If you find more than one suspicious process and want to terminate them, it's recommended by Mark Russinovich, the author of Process Explorer, to first suspend(right click option) them. As many malware infections include multiple processes they can easily restart each other when only one is killed, so suspending them first is a safer way.
More info: Managing Risk

10. If you like Process Explorer you can easily replace Task Manager with it:PE replace TM.png

11.
If you want you can also verify image signatures. You do this by selecting "Verify Image Signatures" from the Options menu. In the screenshot above you can see how it looks like when that option is checked, the second row in the drop-down Options menu. When you select this option you'll see a new column in the process list: "Verified Signer". Example: PEverified.png
An unsigned software doesn't mean it's bad, but it may be more suspicious. Besides looking for unsigned or revoked signatures, also look out for empty or strange names (also in the columns Description and Company Name)
12. Another useful feature is "Process Timeline". To add it go to menu View - Select Columns... then go to tab "Process Performance" and select "Process Timeline".timeline.png
The green part indicates how long a process have been running. So in the above example all processes have been running since start except these that have been started in this order:
- iexplore x 3, started just after the start of Windows
- firefox
- procexp, recently started (almost no green visible)
So how can this information be useful?
Example: Let's say you start a browser and end up on a web site that has a drive-by-download that is able to start a new process. You can then check process timeline for any processes that has started after the browser was started.

   Note
You won't see details for all processes until Process Explorer is run as Administrator!


   Information
The default colors used in Process Explorer are set in the Options menu - Configure colors. Not all colors are used by default, so if you want you can enable the unchecked ones too:
PE colors.png
Most programs are not "packed"(purple color) which can mean they are obfuscated or encrypted, so watch out for those as they would probably be more suspicious than other processes!



This Tutorial has showed you how to check all running processes. If it finds any malware it means it's already running on your system. To try and prevent new malware from infecting your system I recommend my other Tutorial mentioned below. It's an easy way to check downloaded software before running or installing them.

 
Last edited:
Very well done. :thumbsup:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 10 Pro
CPU
AMD Ryzen 5 2400G Processor with Radeon RX Vega 11 Graphics
Motherboard
ASRock X470 Master SLI/AC AM4 AMD Promontory X470 SATA 6Gb/s
Memory
G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-Pin DDR4 SDRAM D
Graphics Card(s)
2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Sound Card
Motherboard Built in
Monitor(s) Displays
Acer R240HY bidx 23.8-Inch IPS HDMI DVI VGA (1920 x 1080) Wi
Screen Resolution
1920 x 1080
Hard Drives
1TB Sandisk SSD PLUS (Main drive)
500 GB Seagate 7200 RPM (Games)
500 GB Western Digital 7200 RPM (Virtual Machines)
PSU
CORSAIR TX Series TX650M 650W 80+ Gold Modular Power Supply
Case
CORSAIR CARBIDE SPEC-02 Mid-Tower Gaming Case, Red LED Fan
Cooling
220mm, two 120mm, and four 60mm fans
Keyboard
Wired Dell keyboard
Mouse
Wireless Logitech mouse
Internet Speed
250mb down, 30mb up
Antivirus
Panda Cloud Antivirus
Browser
Chrome-ish x64
Other Info
Your awesome for reading this.
Ok mate it is going to take me a few reads to rally get the hang of this but it sounds such a good tool to have.:)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Update: added info on how to verify image signatures (step 11)
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
Update: added info for "Process Timeline" (step 12) + minor improvements
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
Hey, thanks very much for all this information, especially the Process Timeline!
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 x64 Pro, Windows 8.1 x64 Pro, Windows 10 TP 10041
How can I use this program to find out why my PC will not go into sleep mode?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Puget Systems
OS
Windows 7 Home Premium 64bit
CPU
Intel core i5
Motherboard
ASUSTeK Computer INC. P8Z68-V PRO GEN3 (LGA1155)
Memory
8GB
Graphics Card(s)
AMD Radeo HD 7700 series
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Acer Al2002W
Screen Resolution
1680x1050
Hard Drives
500GB
298GB Western Digital WD 3200AAJ External
2794GB Western Digital WD My Book 1230
PSU
Antec TruePower New Series 650W
Case
Lancool C-K7B
Cooling
Cooler Master Hyper TX3
Antivirus
windows security essentials
Browser
IE10, Firefox
Back
Top