官术网_书友最值得收藏!

The Process explorer

In essence, the Process explorer tool is similar to the Task Manager, as demonstrated in the following screenshot:  

The advantage of this tool is that it can show more information about the process itself, such as how it was run, including the parameters used, and even its autostart location, as can be seen in the following example:

In addition, the process explorer has tools to send it VirusTotal identification, shows a list of strings identified from its image and the threads associated with it. From a reverser's point of view, the highly used information here is the command-line usage, and autostart location. VirusTotal is an online service that scans a submitted file or URL using multiple security software, as demonstrated in the following screenshot: 

The results are not conclusive, but it gives the submitter an idea about the file's credibility of being legit software or malware.

主站蜘蛛池模板: 舞阳县| 科技| 保靖县| 南澳县| 龙海市| 西乡县| 北票市| 新河县| 海淀区| 陆川县| 延吉市| 叙永县| 东海县| 昔阳县| 华坪县| 平原县| 郑州市| 宜昌市| 阿图什市| 吉木乃县| 鸡东县| 河南省| 浦城县| 繁峙县| 拉萨市| 镶黄旗| 平原县| 阜新| 太和县| 阿巴嘎旗| 汶上县| 瑞丽市| 大港区| 汤原县| 丰宁| 金门县| 石楼县| 舞阳县| 东明县| 保康县| 琼中|