is a generic host
process name for a group of services that are run from dynamic-link libraries (DLLs) and can run other services underneath itself. This is a valid system process that belongs to the Windows Operating System which handles processes executed from DLLs. It runs from the registry key, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost where details of the services running under each instance of svchost.exe can be found. At startup, Svchost.exe checks the services portion of the registry to construct a list of services that it needs to load.
It is not unusual for multiple instances of Svchost.exe running at the same time
in Task manager in order to optimise the running of the various services.
svchost.exe LOCAL SERVICE
svchost.exe NETWORK SERVICE
Each Svchost.exe session can contain a grouping of services, therefore, separate services can run, depending on how and where Svchost.exe is started. This grouping of services permits better control and easier debugging. The process ID's (PID's) are not static and can change with each logon but generally they stay nearly the same because they are running services all the time. The PID's must be checked in real time to determine what services each instance of svchost.exe is controlling at that particular time. Read "How to determine what services are running under a Svchost.exe process
Determining whether a file is malware or a legitimate process sometimes depends on the location (path) it is running from. One of the ways that malware tries to hide is to give itself the same name as a critical system file like svchost.exe. However, it then places itself in a different location on your computer. In XP, the legitimate Svchost.exe file is located in your C:\WINDOWS\system32\
Other legitimate copies can be found in the following folders:
and a prefetch file located here: C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf
If svchost.exe is running as a startup (shows in msconfig), it can be bad as shown here
. Make sure of the spelling
. If it is scvhost.exe
, then that is Trojan
There are several ways to investigate svchost.exe and related processes.
You can download and use Process Explorer
or System Explorer
to investigate all running processes and gather additional information to identify and resolve problems. These tools will show the process CPU usage, a description and its path location
. If you right-click on the file in question and select properties, you will see more details about the file. To get a list of processes shown by Process Explorer, go to file and choose Save as...
to create a log named Procexp.txt
in the same folder where Process Explorer resides.
The Process Explorer window shows two panes by default: the upper pane
is always a process list and the bottom pane
either shows the list of DLLs loaded into the process selected in the upper pane, or the list of operating system resource handles (files, Registry keys, synchronization objects) the process has open. In the menu at the top select View > Lower Pane View to change between DLLs and Handles.
If you have XP Pro, you can use Tasklist /SVC
to view the list of services processes that are running in Svchost. The /SVC switch shows the list of active services in each process.
Go to Start > Run and type: cmd
At the command prompt type: tasklist /svc >c:\taskList.txt
Go to Start > Run and type: C:\taskList.txt
press Ok to view the list of processes
For help and syntax information, type the following command, and then press ENTER:tasklist /?
Also see Syntax options
and Tasklist Syntax
You can also use the WMI command-line utility
to view and list processes.
Go to Start > Run and type: cmd
At the command prompt type:WMIC /OUTPUT:C:\ProcessList.txt PROCESS get Caption,Commandline,Processid
You can also use (type):WMIC /OUTPUT:C:\ProcessList.txt path win32_process get Caption,Processid,Commandline
Go to Start > Run and type: C:\ProcessList.txt
press Ok to view the details of all the processes.
You can search the process name using Google or BC's File Database
If you cannot find any information, the file has a legitimate name but is not located where it is supposed to be, or you want a second opinion, submit it to jotti's virusscan
. In the "File to upload & scan
" box, browse to the location of the suspicious file and submit (upload) it for scanning/analysis.