Introduction to Process Hacker

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with

Already have an account? Sign In »

41 minutes
Video Transcription
Hello. My name is Dustin and welcome to virtual ization and operating systems.
Installing process Hacker
process Hacker is really easy to install. All you need to do is go to process hacker dot source for dot io slash downloads
down with the installer and then run it.
We'll walk you through that in just a second, but I did want to mention that you can also run the process hacker tool from a USB device, which is extremely helpful when you need to investigate someone else's computer.
Um, let's go ahead and hop in here. The first thing I did was actually download a Windows VM, and you can get those
from Microsoft as, like a developer tool. And if you go to developer dot Microsoft dot com slash
e n dash us slash Microsoft dash edge slash tools slash of'em you'll get to this machine. You can also just search for Microsoft edge developer tools and that'll take you here. But here you can actually pick a bunch different versions everything from Windows seven,
8.1 and 10.
So I went ahead and I downloaded 10 and I did it for a virtual box. If you don't remember, you can go ahead and view the previous section where we actually talked about installing it operating system onto virtual box.
Pretty easy. Pretty straightforward, though. So once you get that done,
you can actually let's pop into my Veum.
And here you go. So you can see this is just a window. 71 I have, um and then we'll go ahead and download the process. Hacker tool. And again, that is from process hacker dot source forged dot io.
Once you get here, it will tell you a little bit about the program which we have talked about. But you can go ahead and click the download button right here,
and we're gonna go ahead and get the installer file. That is for any of your regular Windows operating systems. The binaries is for the if you would like to run it from a U. S. B. So just click installer it'll download. And I've already got that here,
right here, you can see is the process hacker set up so really easy. Like I said, just double click it.
You do have to accept the agreement just like any software. Next, Leave it the same. Put it into the program files. Next, um, I like to double check, make sure all the plug ins are set up, and with the full installation they are. So go ahead and click. Next.
Um, if you'd like to rename it in the start menu, you can do that. I just leave it at its default. Next again,
we will create a desktop shortcut for the current user only. If you do want to create a shortcut for all users, you would mean to run. This is Administrator. You can also have it start up on system startup and minimized in the system tray. You can if you like,
set the process. Hackers, that default task manager. So you wouldn't have the regular Windows task manager.
Um, And you can't allow unrestricted access, which, as you can see, is not recommended. So we'll go and just leave it with the desktop shortcut. I don't want to start right away, but we'll click next.
And there you go. Pretty simple. It's already done. So I'd like to leave that check launch process hacker to, and we will hit, finish and pops right up. So this is quite a bit different. Like I said than the regular Windows tools.
If we open up just the regular task manager here, we can kind of compare them. So they're both on processes now. The nice thing I really, really liked about the process actor tool is it allows you to filter through the service's and processes that are running a lot simpler than the built in Windows one.
And you can actually see how things air launched. A CZ well,
right, the Windows one on here on the left. It's just a bunch of different names. You don't know what launched what and here you can actually see in the process hacker tool that it is kind of a tree of everything. So that's how the things got launched
in a couple of things we did want to talk about was actually detecting an identifying malware.
And with the process actor tool, it is pretty easy. There's a few things you want to look for,
and, um, let's take a look here.
We're gonna make this a little bit bigger. Sea is conceited.
You make the description bigger.
All right. So most malware that you'll run into uses packed, executed ALS and packed, executed ALS are compressed and usually encrypted, executed a LS that get decompressed and decrypted and then reconstructed and memory and mount. Where does this to try and hide from, like your regular
system tools to see
what's running
most malware is not digitally signed, as this usually requires extra work.
This used to be a pretty common fact. I have run into a lot more forms of mount where now that do have legitimate digital signatures, whether those were stolen where they have their own digital signing server. I'm not sure just to kind of depends on the malware, but you can
in the process hacker to tool. You can actually look for processes that have a verified signer
and a verification status to determine which processes are signs. If you see on your regular Windows sign processes, you know it's probably not malware.
And another thing that's really nice about the process Hacker tool is most Mel. Well, you run into will not quit without a fight. If you
try and kill it with just the regular task manager, it'll restart. And with that process hacker tool, you can actually
kill it, using what they call the Terminator and What that does is it tries a bunch of different ways to kill the process so it doesn't re launch. So let's go ahead and take a look here in the process hacker tool to see what we can do to help identify and remove malware.
Okay, remember I mentioned most. Mauer is not digitally signed, as this requires actual work, so this is a good place to start when you're looking for malware ending process. Hacker tool. You can go ahead and go to um oops, sorry with my VM. Let's go to view,
and we can actually hide all of the signed processes.
Now remember, this doesn't guarantee that your mouth if you do have Mauer that it's not sign. It's just most Mauer's not typically signed. But if you click that, that will hide all of the sign processes and just show the unsigned processes.
So let's go ahead and show all processes again. Another thing that Mauer likes to do is it likes to run hidden. So if you wantto search for hidden processes, if you go to tools, you can just click the hidden processes
and the normal need to hit scan. It'll scan for the running processes. And it does this based on the process I d
and you can see we've got two processes that are hidden and they actually show unknowns. You click the Terminate one which this could be assistant process. I don't actually want to add the
I'm sorry, terminated. But that's where you can see any hidden files.
So we will go ahead and close that
and back in our slide show now that you're a little more familiar with the process Hacker tool.
All right, so we have downloaded and ran that installer, and we've set it up to look for just a couple of different types of mount where so again,
that you may run into uses packed execute a bles and those of the compressed and encrypted ones that try and run in memory
with your normal task manager, you can't search for that with a process hacker, you can. Another thing you can do in process hacker
is actually search for processes or service. Is that air not signed?
You can then verify any signed ones
to determine if those are legitimate.
And if malware is running in your sous eminent, it's not quitting
you can actually right click a process and dio terminate or terminate tree and the Terminate will terminate just that route process. The tree will take any process in any processes that that process has spawned and kill them all.
Up Next
Virtualization and Operating Systems Fundamentals

In this course we will cover the fundamentals of virtualization and its relationship with operating systems. More specifically, we will cover the common use cases and discuss implementation on the common computing systems used in the industry today.

Instructed By