

For example, one of the most famous is VirusTotal. Perform virtual file scanning – via special online services with malware database. Emsisoft Anti-Malware for fast results and extra features.System Mechanic Ultimate Defence with several levels of protection.IObit Malware Fighter – effective and lightweight.Here is a shortlist of anti-malware suggestions: Launch an antivirus of choice, select svchost folder, and scan it. For this task, it is recommended to use a reliable antivirus with an extensive database of viruses/malware. Task Manager or Resource Monitor won’t necessarily point out malicious files. Scanning files for viruses is a simple and effective method to identify the original file.

Go to C:\Windows\System32, find the perfmon.exe file and run it.Īfter launching it, go to the CPU tab, select all svchost processes, and view all the information about the services, modules, and associated files.Go to Start>Windows System>Run (or Win+R), type in resmon and press Enter.Go to Start and find the Resource Monito r.There are several ways to run this program: Check the digital signature and other details.įor more information use the Windows Resource Monitor utility.Right click the file, check the folder and the service it is working for.Open the Task Manager (Ctrl+Shift+Esc).If data does not match the original Microsoft file, we recommend deleting it. Keep in mind that the original file should be located in C:\Windows\System32 (32-bit) or C:\Windows\SysWOW64 (64-bit). Use Task Manager to determine location of the file, as well as to detect what service is loading the system. There are a few simple ways to test all svchost.exe processes. The original file may load CPU and/or RAM due to a malfunction of the service that was started by it. What if svchost consumes a large amount of system resources? Don’t rush to conclusions. How to find out what process is original? Generally, it could be banking viruses, trojans, password stealers attempting to steal data. In rare cases, a virus creates a dummy service and uses the original file to enact malicious operations. It is challenging to notice a fake process, as attackers may copy the original file description and set it for minimum resource use. Each service needs a new launch of svchost. In terms of infection, many viruses and malware try to disguise as svchost, because Windows run multiple of these processes. Possible issues include: a) incorrect service work (in most cases) b) malware infection c) fake process d) file missing or accidental deletion (unlikely). In this article, we take a closer look at common issues and offer tips to fix svchost.exe. Due to such importance, this file often gets affected by viruses. In Windows OS it is responsible for various processes, such as network connection, checking for system updates, connecting devices, Windows Defender, etc. Straight away, note that svchost.exe is not a virus.
