Windows Security Tutorials - Herong's Tutorial Examples - v3.01, by Dr. Herong Yang
Identify Malware Process Manually
This section provides a summary of advices on how to identify malware process when malware symptom appears on a Windows system.
If you have to remove malware manually, the first thing you should do is to identify the malware process. Here are some advices you can follow.
When you see the malware symptom appearing on your Windows system, record as much as you can about the current state of the system, including:
Try to find out processes that are possibly related to the malware symptom from the process list, using various techniques:
Review each of those recorded suspicious processes to identify which is truly related to the malware. Review detailed properties of the executable file of the suspicious process in the following areas:
If you failed to identify the malware process, you can publish the full process list to an anti-virus forum for help.
Table of Contents
About This Windows Security Book
Windows 8: System Security Review
Windows 8: System Security Protection
Windows 8 Defender for Real-Time Protection
Windows 7: System Security Review
Windows 7: System Security Protection
Windows 7 Forefront Client Security
Norton Power Eraser - Anti-Virus Scan Tool
McAfee Virus and Malware Protection Tools
Spybot - Spyware Blocker, Detection and Removal
Keeping IE (Internet Explorer) Secure
►Malware (Adware, Spyware, Trojan, Worm, and Virus)
What Is Malware (Malicious Software)?
Common Ways of Getting Infected
Common Symptoms of an Infected System
Common Ways of Malware Executions
Malware Removal by Anti-Virus Tools
►Identify Malware Process Manually
Delete Malware Program Files Manually
HijackThis - Browser Hijacker Diagnosis Tool
IE Add-on Program Listing and Removal
"Conduit Search" - Malware Detection and Removal
"Tube Dimmer", "Scorpion Saver" or "Adpeak" Malware
Malware Manual Removal Experience
Vundo (VirtuMonde/VirtuMundo) - vtsts.dll Removal
Trojan and Malware "Puper" Description and Removal
VSToolbar (VSAdd-in.dll) - Description and Removal
PWS (Password Stealer) Trojan Infection Removal