Identify Malware Process Manually

This section provides a summary of advices on how to identify malware process when malware symptom appears on a Windows system.

If you have to remove malware manually, the first thing you should do is to identify the malware process. Here are some advices you can follow.

When you see the malware symptom appearing on your Windows system, record as much as you can about the current state of the system, including:

Try to find out processes that are possibly related to the malware symptom from the process list, using various techniques:

Review each of those recorded suspicious processes to identify which is truly related to the malware. Review detailed properties of the executable file of the suspicious process in the following areas:

If you failed to identify the malware process, you can publish the full process list to an anti-virus forum for help.

