官术网_书友最值得收藏!

The Process explorer

In essence, the Process explorer tool is similar to the Task Manager, as demonstrated in the following screenshot:  

The advantage of this tool is that it can show more information about the process itself, such as how it was run, including the parameters used, and even its autostart location, as can be seen in the following example:

In addition, the process explorer has tools to send it VirusTotal identification, shows a list of strings identified from its image and the threads associated with it. From a reverser's point of view, the highly used information here is the command-line usage, and autostart location. VirusTotal is an online service that scans a submitted file or URL using multiple security software, as demonstrated in the following screenshot: 

The results are not conclusive, but it gives the submitter an idea about the file's credibility of being legit software or malware.

主站蜘蛛池模板: 元江| 曲麻莱县| 合阳县| 汶上县| 新邵县| 子长县| 宜兰市| 全椒县| 临朐县| 文山县| 阿瓦提县| 云龙县| 类乌齐县| 镇巴县| 桃江县| 邳州市| 临桂县| 南宫市| 桐庐县| 海伦市| 腾冲县| 潞西市| 郓城县| 阜新市| 施秉县| 乐平市| 旬邑县| 金沙县| 洛宁县| 莱西市| 中宁县| 梁平县| 盐山县| 大英县| 无极县| 绩溪县| 依兰县| 德州市| 玉溪市| 龙山县| 营山县|