CMC Sentinel Deutsch Windows guide

AN UNFAMILIAR NAME IS NOT AUTOMATICALLY A MALWARE FINDING

How to check an unknown Windows process safely

Windows runs many processes that most people never recognize by name. The useful evidence is the combination of file location, publisher, signature, parent process, startup path and behavior.

A repeatable check instead of guessingOfficial Microsoft toolsNo file judged by its name aloneSentinel separates observation from conclusion
SHORT ANSWER

Do not immediately end or delete an unfamiliar process. Open its file location, inspect the publisher and digital signature, identify its parent process, review network and startup activity, and scan the executable with Microsoft Defender.

Why the process name is not enough

Legitimate Windows components use names such as svchost.exe, RuntimeBroker.exe and SearchHost.exe. Malware can also use a similar-looking name. Exact spelling, full path, publisher and signature are more useful than the visible name alone.

Do not end processes blindly. Stopping a system process can crash applications, force a sign-out or destabilize Windows without removing the actual cause.

1. Open the file location and properties

  1. Open Task Manager with Ctrl + Shift + Esc.
  2. Right-click the process and select Open file location.
  3. Open the file properties and review product name and publisher under Details.
  4. Check Digital Signatures when that tab is available.

A path under C:\Windows\System32 is useful context, but not an automatic clearance. A program under your user profile is not automatically malicious either. Combine multiple signals.

2. Identify the parent process and loaded components

Microsoft’s Process Explorer adds context beyond Task Manager: a process tree, owning account, open handles and loaded DLLs. The tree helps answer a key question: which program started the unfamiliar process?

An updater launched by known software is different from a randomly named executable starting from a temporary directory immediately after sign-in.

3. Match network activity to the owning process

Resource Monitor or Microsoft TCPView shows which process owns each TCP or UDP endpoint. Record the process, destination and time.

An internet connection is normal for browsers, cloud storage, messaging apps and updaters. It becomes more concerning when an unexpected connection appears together with an unusual path, missing signature or new startup entry.

4. Check whether the process starts automatically

Task Manager lists common startup apps. Microsoft Autoruns also covers services, scheduled tasks, Winlogon entries and other startup locations. Its filters can hide signed Microsoft entries so third-party items are easier to review.

Disable an entry only after you understand its purpose or have a reliable security assessment. Disabling is easier to reverse than deletion.

5. Scan the executable with Microsoft Defender

Right-click the file in Explorer, select Show more options if needed, and choose Scan with Microsoft Defender. Review the result in Protection history. If concern remains, run a full scan or Microsoft Defender Offline.

A clean scan is useful evidence, not an absolute guarantee. New or targeted malware may not be recognized immediately, so source, signature, startup behavior and observed activity still matter.

6. Weigh warning signs together

  • Stronger warning: random name, temporary path, missing signature and unexpected startup occur together.
  • Needs context: high CPU usage or one network connection can be completely legitimate.
  • Urgent: the process immediately returns, disables security controls or appears during unauthorized remote control.
  • Not proof: the name sounds technical or is unfamiliar to you.

7. What CMC Sentinel brings together

Sentinel combines process path, publisher context, connections, startup information and local events in a more guided interface. Findings can be marked as reviewed without disappearing from the local record.

The app deliberately separates an observation from its interpretation. “Unknown” does not automatically mean malicious, and “signed” does not automatically mean harmless.

SHIELD + CMC SENTINEL

Stop switching between several Windows tools when something looks wrong.

Sentinel combines process, connection, startup and remote-access signals with deliberate Shield checks. It complements Microsoft Defender and keeps the limits of each finding visible.

€19.90for 1 month · up to 5 Windows PCs in one household

The total price and renewal period are shown before payment. Future renewal can be cancelled for the end of the paid period.

Common questions

Is every unsigned Windows process dangerous?

No. Some legitimate software is unsigned. Treat a missing signature as one signal and consider path, source, startup behavior and network activity as well.

Can I safely end svchost.exe?

Do not end it blindly. Multiple Windows services run under svchost.exe. First verify the exact path and identify which service belongs to that process instance.

Does a clean Defender scan prove the process is safe?

No. It is useful evidence, not an absolute guarantee. Source, signature, startup behavior and observed activity still matter.

How is Process Explorer different from Sentinel?

Process Explorer is a detailed Microsoft diagnostic utility. Sentinel brings selected process, connection, remote-access and Shield checks into a more guided interface and adds focused response controls.

Official Microsoft references

Updated 30 September 2026. If an attack is active, money was lost or important accounts were compromised, also contact the relevant provider, bank or law-enforcement authority.