PDA

View Full Version : INFO Questions about "Processes" in the reports



INFANTRY3219
14-01-2023, 01:18 AM
Hello. I have my own server and sometimes I ask people to scan for WarGods. But I noticed something in the reports: In some people's reports, there are many yellow processes in the Processes section, but in some people's reports, this section is empty. And sometimes known processes like chrome.exe also show up as yellow. And VirusTotal finds no results for some Processes, why? I'm hesitant about these issues as I don't know much and I think I should also use TeamViewer.

What are their reasons? How does the ''Processes'' system work? I'm waiting for your answer, thanks.

Tiger
14-01-2023, 01:58 PM
Validated (whitelisted) files (processes, modules, cstrike, etc.) are not shown.

Only files that are detected or "unknown" are shown. A file is marked as "unknown" because it couldn't be (yet) validated. We can't validate all these files on this planet because of multiple reasons (e.g.: new or modified files, not in known sources, few info about that file, etc.). wCD doesn't take the content of the files (for privacy reasons), only extracts some metadata from these files. Sometimes it's hard to whitelist a file only using its extracted metadata because there are not enough information. Just because a file couldn't be validated directly in a report, for example this week, doesn't necessarily mean it won't be validated in the (near) future.

Of course new files won't appear on VirusTotal. How is supposed VirusTotal to know about a file if that file was never uploaded to this service?!

These kind of messages are displayed in the report... learn to not ignore them...