• PROCEXP152.SYS

    Author
    Topic
    #2544980

    Hello. I’ve used Process Explorer in the past, but I deleted it (it’s portable).

    Then I found the file “C:\Windows\System32\drivers\PROCEXP152.SYS” was left behind by an old Process Explorer version.

    Can I just delete this file or will it cause mayhem?

    Viewing 2 reply threads
    Author
    Replies
    • #2544999

      How much free space do you have and what % of that does the file take up?

    • #2545158

      This appears to be a helper device driver. I did not see a reference to it in my registry. Apparently, the driver was loaded when running Process Explorer in administrative mode.

      Some software flags the driver as a vulnerability:
      https://learn.microsoft.com/en-us/answers/questions/989267/process-explorer-procexp152-sys-driver-flagged-as

      On the other hand, my AV gives the driver a trusted rating, saying thousands run it, and it was released over 3 years ago.

      In your case, I would make sure your system is backed up, then remove it from your system, then reboot. In theory, you should be fine without it.

      Windows 10 22H2 desktops & laptops on Dell, HP, ASUS; No servers, no domain.

      1 user thanked author for this post.
    • #2545209

      I deleted the old PROCEXP152.SYS driver and rebooted, no problem.

      I ran the latest version of ProcessExplorer v17.02 in admin mode, and an updated PROCEXP152.SYS driver was placed in the C:\Windows\System32\drivers directory.

      This time AV said the new driver was trusted and only 4 months old.

      Not clear if only old versions of PROCEXP152.SYS are marked vulnerable by XDR (extended detection and response) security software.

      Windows 10 22H2 desktops & laptops on Dell, HP, ASUS; No servers, no domain.

      1 user thanked author for this post.
    Viewing 2 reply threads
    Reply To: PROCEXP152.SYS

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: