官术网_书友最值得收藏!

The Process explorer

In essence, the Process explorer tool is similar to the Task Manager, as demonstrated in the following screenshot:  

The advantage of this tool is that it can show more information about the process itself, such as how it was run, including the parameters used, and even its autostart location, as can be seen in the following example:

In addition, the process explorer has tools to send it VirusTotal identification, shows a list of strings identified from its image and the threads associated with it. From a reverser's point of view, the highly used information here is the command-line usage, and autostart location. VirusTotal is an online service that scans a submitted file or URL using multiple security software, as demonstrated in the following screenshot: 

The results are not conclusive, but it gives the submitter an idea about the file's credibility of being legit software or malware.

主站蜘蛛池模板: 乐业县| 左权县| 鞍山市| 昌平区| 如皋市| 昌乐县| 建始县| 芦溪县| 安阳市| 英山县| 阿坝县| 托里县| 桃园县| 文水县| 吴旗县| 望都县| 正定县| 汉中市| 张家界市| 昌都县| 剑川县| 仁怀市| 辛集市| 荔波县| 黄石市| 任丘市| 祁阳县| 天镇县| 湛江市| 大同市| 乐昌市| 博客| 两当县| 江安县| 巴里| 静乐县| 昔阳县| 城步| 漳州市| 六盘水市| 胶州市|