Do not immediately end or delete an unfamiliar process. Open its file location, inspect the publisher and digital signature, identify its parent process, review network and startup activity, and scan the executable with Microsoft Defender.
Why the process name is not enough
Legitimate Windows components use names such as svchost.exe, RuntimeBroker.exe and SearchHost.exe. Malware can also use a similar-looking name. Exact spelling, full path, publisher and signature are more useful than the visible name alone.
1. Open the file location and properties
- Open Task Manager with Ctrl + Shift + Esc.
- Right-click the process and select Open file location.
- Open the file properties and review product name and publisher under Details.
- Check Digital Signatures when that tab is available.
A path under C:\Windows\System32 is useful context, but not an automatic clearance. A program under your user profile is not automatically malicious either. Combine multiple signals.
2. Identify the parent process and loaded components
Microsoft’s Process Explorer adds context beyond Task Manager: a process tree, owning account, open handles and loaded DLLs. The tree helps answer a key question: which program started the unfamiliar process?
An updater launched by known software is different from a randomly named executable starting from a temporary directory immediately after sign-in.
3. Match network activity to the owning process
Resource Monitor or Microsoft TCPView shows which process owns each TCP or UDP endpoint. Record the process, destination and time.
An internet connection is normal for browsers, cloud storage, messaging apps and updaters. It becomes more concerning when an unexpected connection appears together with an unusual path, missing signature or new startup entry.
4. Check whether the process starts automatically
Task Manager lists common startup apps. Microsoft Autoruns also covers services, scheduled tasks, Winlogon entries and other startup locations. Its filters can hide signed Microsoft entries so third-party items are easier to review.
Disable an entry only after you understand its purpose or have a reliable security assessment. Disabling is easier to reverse than deletion.
5. Scan the executable with Microsoft Defender
Right-click the file in Explorer, select Show more options if needed, and choose Scan with Microsoft Defender. Review the result in Protection history. If concern remains, run a full scan or Microsoft Defender Offline.
A clean scan is useful evidence, not an absolute guarantee. New or targeted malware may not be recognized immediately, so source, signature, startup behavior and observed activity still matter.
6. Weigh warning signs together
- Stronger warning: random name, temporary path, missing signature and unexpected startup occur together.
- Needs context: high CPU usage or one network connection can be completely legitimate.
- Urgent: the process immediately returns, disables security controls or appears during unauthorized remote control.
- Not proof: the name sounds technical or is unfamiliar to you.
7. What CMC Sentinel brings together
Sentinel combines process path, publisher context, connections, startup information and local events in a more guided interface. Findings can be marked as reviewed without disappearing from the local record.
The app deliberately separates an observation from its interpretation. “Unknown” does not automatically mean malicious, and “signed” does not automatically mean harmless.