Advice Request Is Process Hacker safe?

Please provide comments and solutions that are helpful to the author of this topic.

SumTingWong

Level 28
Thread author
Verified
Top Poster
Well-known
Apr 2, 2018
1,717
Is Processor Hacker safe? I got a warning from ESET Nod32 said "a variant of Win64/Processes Hacker.A potentially unsafe application". Then I uploaded the downloaded file to VirusTotal, and holy molly it got detected more than 10 engines. Is it safe? If it safe then why it got detected more than 10 engines like it is an actual malware?
 
F

ForgottenSeer 85911

Is Processor Hacker safe? I got a warning from ESET Nod32 said "a variant of Win64/Processes Hacker.A potentially unsafe application". Then I uploaded the downloaded file to VirusTotal, and holy molly it got detected more than 10 engines. Is it safe? If it safe then why it got detected more than 10 engines like it is an actual malware?

process hacker can be used to tamper with security services and other malicious actions
hence soem av rate it as hack tool or PUA
 

SumTingWong

Level 28
Thread author
Verified
Top Poster
Well-known
Apr 2, 2018
1,717
100% safe. Nothing to worry about. Just a false positive
If it's signed then I assume it's safe.
Anything that can kill a process or service is considered as an "Hack Tool" hence the definition name.
note that the word "hack" means "tampering with" , not only for malicious intents.
process hacker can be used to tamper with security services and other malicious actions
hence soem av rate it as hack tool or PUA

I got the download file here:


Anything that can kill a process or service is considered as an "Hack Tool" hence the definition name.

Why Process Explorer not detected but Process Hacker does?
 
  • Like
Reactions: DDE_Server

TairikuOkami

Level 35
Verified
Top Poster
Content Creator
Well-known
May 13, 2017
2,486
process hacker can be used to tamper with security services and other malicious actions
Indeed, just like PsExec made by MS. Weapons do not kill people, people do. Tools can be beneficial or dangerous depending on, who uses them.
Petya Ransomware is also taking advantage of WMIC and PSEXEC tools to infect fully-patched Windows computers, you are also advised to disable WMIC.
If it's signed then I assume it's safe.
I am using Nightly version, that is not signed, but I take it as a bonus, malware can not easily exploit it, since it can not be simply elevated. :D
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top