Unknown Process in Task Manager: How to Identify It

Learn to trace a strange process name back to its source and tell a legitimate one from a suspicious one.

Intermediate 2 min read Published on 2026 By Equipo SolucionaPC

Seeing a process with a strange name using up resources is unsettling, but most of the time it has a simple explanation. Here's how to find out what it is in under a minute.

What you'll learn

  • Tracing a process's origin from Task Manager itself
  • Telling a legitimate process apart from a suspicious one
  • What to do if it turns out to be malware

Simple explanation

Every process has a file name and a location on disk. Legitimate Windows processes live in system folders (C:\Windows\System32); malware usually hides elsewhere with names similar to real processes to go unnoticed.

Step by step

1. Right-click → Open file location

On the process in question, this option takes you straight to the folder where that program lives — the fastest clue as to whether it is legitimate.

2. Search for the exact name online

Copy the process name exactly as it is (for example, RuntimeBroker.exe) and search for it. Legitimate Windows processes have plenty of official documentation.

3. Check the digital signature

Right-click the file -> Properties -> Digital Signatures tab
If "Microsoft Windows" or the program's manufacturer appears, it can be trusted.
If it has no digital signature and was in a strange location, be suspicious.

Tips

Tip: before worrying, check whether the name matches any program you installed recently — that is the most common cause, not malware.

If it turns out suspicious

If after checking you still don't trust it, run a full scan following our guide to removing viruses and malware for free.

Warning: don't close the process immediately just on suspicion before investigating — if it turns out to be legitimate, you could cause unnecessary instability.

Common mistakes

Searching for the process name and trusting the first result without checking whether the site is reliable — there are low-reputation pages that label legitimate processes as dangerous to sell you unnecessary software.

Final summary

File location + digital signature + a quick search resolve 95% of doubts about an unknown process, with no need to panic.

Frequently asked questions

Are all processes with no icon suspicious?

No, it's very common for legitimate system processes to have no icon. What matters is their location and digital signature, not whether they have an icon or not.

What do I do if the file has no digital signature?

It's not automatically malware, but it's a sign to investigate further: check the location and search for the exact name before deciding.

Share: