So what is SVCHOST.EXE?

If svchost.exe is located in C:\, the security rating is 55% dangerous.

Svchost can also be a target of a host of viruses, intrusion software can embed itself. If svchost.exe is located in a subfolder of the user's "Documents" folder, the security rating is 68% dangerous.

A virus made its way on to my jump drive and put itself as a hidden file, I deleted it but it just recreated itself and I think it made its way to my computer. Restart the computer.

Change the Startup type to Disabled, press OK and restart your computer. Always remember to perform periodic backups, or at least to set restore points. In XP click the start button, click the run button, type "services.msc" in the run box without quotes, and hit enter, does the same thing. Microsoft's Sysinternals Process Explorer also provides information about services running under svchost.exe processes when the user hovers the mouse over the svchost instance.

how do you recognize a virus that uses an svchost.exe as a front from a real windows process? The true svchost.exe file is a safe Microsoft Windows system process, called "Generic Host Process". Acting as a host, the file svchost.exe creates multiple instances of itself. So let's say one of them is running at an excessively high CPU usage of 100 percent, how can we identify the actual application running?

According to Microsoft: "svchost.exe is a generic host process name for services that run from dynamic-link libraries". Such service's registry key must have a value named ServiceDll under the Parameters subkey, pointing to the respective service's DLL file. This issue occurs because a handle leak occurs in the Winmgmt service after you install Windows Management Framework 3.0 on the computer.[9] Note:The Winmgmt service is the Windows Management Instrumentation (WMI)

Added by the BANKER-AE TROJAN!

B proud of it :P. If svchost.exe is located in the C:\Windows folder, the security rating is 62% dangerous. Reply Iain Sep 24, 2015 @ 04:11:43 Worked perfectly, solved so many other issues I was having. Added by the AUTOTROJ-C TROJAN! "SystemReg" definitely not required.

i accidently downloaded a file that gave me a trojan called dopper.generic bhhp and it has infected my svchost and i cant. The file size is 689,664bytes. You should run a scan to be sure.

Even if it's Windows Update or the Firewall, don't worry, you can re-enable it later. Often viruses and spyware will disguise themselves as legitimate services by either using the same name, or similar names with spelling errors. If you want more info on the Task Manger, check out my articles on understanding the Task Manager.

Click on OK to terminate the application.