I have a habit you might call paranoia: I go hunting through the Task Manager once my computer's fan starts spinning louder than normal with the aim of "catching the burglar mid-heist." This habit paid off last week, except this time the "burglar" was a process I'd never questioned before.
Eventually, I realized the bigger problem wasn't that I didn't recognize a process. It was that I didn't have a reliable way to tell whether it deserved my attention.
While I scrolled through Process Explorer, the line that caught my attention was RuntimeBroker.exe, PID 18900. This process used about 7.8MB of private memory. Alone, I may not have bothered, but when I saw four additional instances of the same process, I became curious enough to investigate.
They were all running under different PIDs: 18900, 23036, 19616, 20936, and 7104, and they consumed slightly different amounts of memory.
The name itself — "RuntimeBroker" — wasn't giving me much to work with. In fact, at one point, I was convinced this was the kind of thing a scammer would name a fake process. It sounded both vague and official at once.
So I right-clicked on it and explored its properties. In the Properties window, I could see more than the name gave away, including the executable's path and its digital-signature information.
It took a few seconds for me to go from hunch to actual answers. This changed how I interact with processes. I didn't have to recognize every process, but I needed a way to learn more about them.
Source link







