PROCESS11 records

Windows Process Reference

What the processes in Task Manager actually do: purpose, publisher, normal file path, expected instances, resource behaviour and safe ways to investigate.

Each record explains what the process does, who publishes it, where its genuine executable lives, whether several copies are normal, and when unusual behaviour is worth investigating. A file name alone never proves a process is malware; the path and digital signature do. To check either, right-click the process in Task Manager → Open file location and → Properties → Digital Signatures.

Core system processes

Processes Windows cannot run without. Never end these.

Service hosts & workers

Processes that host services or do background work; high resource use here is worth understanding.

Shell & desktop

The visible desktop, window management and console hosting.

A note on "is this a virus?"

Malware often names itself after a real Windows process to blend in. The genuine process runs from a specific folder (usually C:\Windows\System32) and is signed by Microsoft. A process with the right name in the wrong folder, or with no valid signature, is the thing to investigate. Each record below gives the correct path so you can check.