[ Question ] Does Process Explorer Proactively Notifies You When VirusTotal Is Turned On?

C19FB5E2 21 Reputation points
2021-09-27T01:24:13.38+00:00

Hello, I just would like to inquire if Process Explorer will proactively notify you in case that a new process was detected.

Will Process Explorer...

  • Upload the new process to VirusTotal automatically?
  • If the result in VirusTotal produces a result with a hit, will Process Explorer notify me automatically that there's a new process that might be a virus?

If the two question answer is Yes, does enabling Options > VirusTotal.com > Check VirusTotal.com enables the scenario above or is there additional settings I need to configure to achieve the scenario above.

Please advise. Thank you

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,086 questions
0 comments No comments
{count} votes

Accepted answer
  1. steviefaux 181 Reputation points
    2021-10-07T09:30:30.497+00:00

    If you have VirusTotal enabled as a new process starts its HASH is submitted to VirusTotal. Be aware (I've only just found this out) that any app that is submitted to VirusTotal is then available to researchers who have the specific subscription and vetted with VirusTotal to then download that app for inspection.

    Process Explorer doesn't pop anything up telling you something has been "flagged" at VirusTotal, you have to look at ProcessExplorer to see as such in the VirusTotal column.

    However, don't rely on VirusTotal to be accurate, its not. Various legit apps are flagged by the engines it used when they are perfectly fine. For example, Sysinternals sysmon is flagged by at least one of the engines VirusTotal uses so you'll see a 1/73 next to sysmon in the Process Explorer trace.

    0 comments No comments

0 additional answers

Sort by: Most helpful