procexp64.zip version 16.43 has virus

Shlomo Flam 6 Reputation points
2022-05-26T07:46:10.657+00:00

I downloaded procexp64.zip version 16.43 from sysinternals web site (linked below) and tested on virustotal.
it showed one virus "trojan shelma win32 13165.
I downloaded from: https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer

I also downloaded tools suite and got the same virus.
for some reason my window defender did not indicate these viruses

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,245 questions
Windows for business | Windows Client for IT Pros | User experience | Other
{count} vote

2 answers

Sort by: Most helpful
  1. Reza-Ameri 17,341 Reputation points Volunteer Moderator
    2022-05-26T15:05:06.623+00:00

    I just checked and only one vendor (CRDF) detected it as malicious (in the VirusTotal) and most trusted Anti-Malware vendors mark it as safe.
    I believe this is false-positive and you may report this issue to the Anti-Malware vendor.

    1 person found this answer helpful.

  2. Limitless Technology 44,766 Reputation points
    2022-06-01T07:28:37.063+00:00

    Hello

    Thank you for your question and reaching out. I can understand you are having issues related procexp64.zip detected as virus.

    I would suggest you to do the Full Virus Scan on your Computer then download again procexp64.zip from Microsoft.

    Also please Cleanup below Temp folders
    C:\Windows\Temp
    %USERPROFILE%\AppData\Local\Temp


    --If the reply is helpful, please Upvote and Accept as answer--

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.