What is the "svchost.exe" ?

Our database contains 5316 different files for filename svchost.exe . You can also check most distributed file variants with name svchost.exe. This files most often belongs to product Microsoft® Windows® Operating System. and were most often developed by company Microsoft Corporation. This files most often have description Host Process for Windows Services. Agregate rating is 3(3) stars - based on 115 reviews.This is executable file. You can find it running in Task Manager as the process svchost.exe.

What does svchost do?

svchost.exe is in most cases system process which hosts Windows Services. This genuine MS Windows process is marked as Generic Host Process for Win32 Services. Microsoft Windows Service is application processing background task required by system or non-system application asking for some service to run on operating system. Services have no user interface (UI) so they can't interact with user. It is common that user finds many svchost.exe processes running on every computer with MS Windows operating system. Each svchost.exe is hosting different set of services. Most of them are critical for stable run of the operating system.

Threats in svchost.exe

Some threats uses svchost.exe filename to cloak own process in task manager. All svchost.exe running in your system should be running in %SYSDIR% directory. (In most cases C:\WINDOWS\System32\). You can check it manually via Windows Task Manager or use System Explorer which automatically marks by red color all suspected svchost.exe processes. If you find some suspected svchost.exe process, check it via antivirus or virustotal service.

Troubleshooting svchost.exe

If you are experiencing performance or stability issues caused by some instance of system's svchost.exe then you must determine which service makes the problem. You can use system commandline tool tasklist.exe /svc /fi "imagename eq svchost.exe" to enumerate all svchost instances with list of running services. If you are not familiar with commandline tools, you can use System Explorer which shows list of hosted services in process tooltip.

If problematic process is hosting more services then you can configure this services to run in isolated processes. If you will have services isolated, you will easily find which service causes the issues. To isolate service use commandline tool sc config %service_name% type= own. To revert this setting use sc config %service_name% type= share. After change of service type you must also restart the service by commands sc stop %service_name% and sc start %service_name%.

If you are experiencing 100% cpu usage of the svchost process or cpu usage is very high for long time, most often is this issue linked to updating service but it can be something else...you must analyze it.

Problems with 100% cpu usage of svchost on Windows XP

In 10/2013 started issues with high CPU usage of the svchost caused by problems in Windows Update service. Many users are experiencing this problem and Microsoft is trying to fix it as soon as possible. This issue was still actual in 12/2013.

svchost.exe Process

File details of most used file with name "svchost.exe"

Product:
Microsoft® Windows® Operating System
Company:
Microsoft Corporation
Description:
Host Process for Windows Services
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
MD5:
c78655bc80301d76ed4fef1c1ea40a7d
SHA1:
619652b42afe5fb0e3719d7aeda7a5494ab193e8
SHA256:
93b2ed4004ed5f7f3039dd7ecbd22c7e4e24b6373b4d9ef8d6e45a179b13a5e8
Size:
27136
Directory:
C:\Windows\System32
Operating System:
Windows 7
Occurence:
High oc2

Is the Process "svchost.exe" Safe or Threat ?

Loading Graph
37% of reviewed files are marked as Safe .
52% of reviewed files are marked as Threat .
22% of reviewed files are marked as System file.
Latest new variant of the file with name "svchost.exe" was discovered yesterday. Our database contains 509 variants of the file "svchost.exe" with final rating Safe and 712 variants with final rating Threat . Final ratings are based on file reviews, discovered date, users occurence and antivirus scan results.
Process with filename "svchost.exe" can be Safe or Threat. You must define more file attributes to determine right rating. Our freeware awards winning tool provides easiest way to check your files via our database. Tool contains many useful functions for keep your system under control and uses minimum system resources.
Click Here to Download System Explorer for Free.
Filename "svchost.exe" is used by Microsoft Windows System files. Many threats uses filenames of System Processes to camouflage itself. You should consider suspected any file which uses system filename and is not stored in system directory or has invalid file version information. Correct system file contains full file version information from Microsoft.

User Reviews of the "svchost.exe"

There are multiple files in compliance with actual filter settings. All reviews for this files will be displayed.

Reviews for all files with name "svchost.exe"

  • SAFErating from user a for file C:\Windows\System32\svchost.exeflag ru

  • THREATrating from user upset for file C:\Windows\System32\svchost.exeflag ru

  • SAFErating from user MikeOne for file C:\Windows\SysWOW64\svchost.exe (Variant: 4942)

    MikeOne photo

    In origin, this file ia s core part of Windows system : The file svchost.exe is the Generic Host Process. For 64-bt versions, the file is moved to the SysWOW64 directory.

  • SAFErating from user миша for file C:\Windows\System32\svchost.exeflag ru

  • SAFErating from user Александр Щуров for file C:\Windows\System32\svchost.exeflag ru

  • THREATrating from user миша for file C:\Windows\System32\svchost.exeflag ru

  • SAFErating from user MikeOne for file C:\Windows\System32\svchost.exe (Variant: 10115369)

    MikeOne photo

    This file ia s core part of Windows system : The file svchost.exe is the Generic Host Process. For 64-bt versions, the file is moved to the SysWOW64 directory. "In the Windows NT family of operating systems, svchost.exe (Service Host, or SvcHost) is a system process which hosts multiple Windows services" - see more on Wikipedia : http://en.wikipedia.org/wiki/Svchost.exe

  • THREATrating from user felix for file C:\Windows\System32\svchost.exeflag ru

  • SAFErating from user Oddbrother for file C:\Windows\System32\svchost.exe (Variant: 108)

    Oddbrother photo

    Used to host all services in a Windows operating system.

  • SAFErating from user sergey2910 for file C:\Windows\System32\svchost.exeflag ru

  • THREATrating from user Zoran for file C:\Windows\System32\svchost.exe (Variant: 505275)

    Zoran photo

    svchost.exe has spiked my CPU at 100% since i unistall Microsoft Security Essential...

  • SAFErating from user Dieter for file C:\Windows\System32\svchost.exeflag de

  • THREATrating from user duc for file %APPDATA%\svchost.exeflag ru

  • SAFErating from user MikeOne for file C:\Windows\ime\svchost.exe (Variant: 100810)

    MikeOne photo

    svchost.exe is the "Generic Host Process" for native Windows services. The Svchost.exe file is located in the %SystemRoot%\System32 folder. At startup, Svchost.exe checks the services part of the registry to construct a list of services that it must load. Multiple instances of Svchost.exe can run at the same time. As a core Windows process, it can be a target for many viruses. Check the MD5 version. More info about the file can be found directly on http://support.microsoft.com/kb/314056. Commonly, this file is marked by ativiruses as not-a-virus : Proxy-CC

  • THREATrating from user Олег for file C:\Windows\System32\svchost.exeflag ru

  • SAFErating from user TuliodeBree for file C:\Windows\SysWOW64\svchost.exe (Variant: 503262)

    TuliodeBree photo

    Clean

  • SAFErating from user DJ for file C:\Windows\System32\svchost.exeflag ru

  • SAFErating from user Guibou for file C:\Windows\SysWOW64\svchost.exe (Variant: 503262)

    Guibou photo

    This one is marked with "-k Akamai". Probably provided with Akamai netsession interface, usefull for a better net service (web surfing quality, download speed).

  • SAFErating from user Flayro for file C:\Windows\SysWOW64\svchost.exeflag cs

  • SAFErating from user Anonymous for file C:\Windows\System32\svchost.exe (Variant: 110)

    Anonymous photo

    This is the "Generic Host Process" for native Windows services. As long as it is installed to %SystemRoot%\system32, it's part of Windows. You will see multiple copies of svchost.exe running.

  • SAFErating from user Admin for file C:\Windows\System32\svchost.exe (Variant: 23)

    Admin photo

    Svchost.exe is system process for hosting dynamically linked services.

  • SAFErating from user 29732B for file C:\Windows\System32\svchost.exe (Variant: 502181)

    29732B photo

    Depends on the MD5 - otherwise, it is safe, if not very annoying and memory-hogging.

  • SAFErating from user Admin for file C:\Windows\System32\svchost.exe (Variant: 12228963)

    Admin photo

    Windows 8 version of the Host Process for Windows Services.

  • SAFErating from user MikeOne for file C:\Windows\System32\svchost.exe (Variant: 10123471)

    MikeOne photo

    This file ia s core part of Windows system : The file svchost.exe is the Generic Host Process. For 64-bt versions, the file is moved to the SysWOW64 directory.

  • THREATrating from user Ericssonica for file C:\Windows\System32\svchost.exeflag ru

  • THREATrating from user Джексон for file C:\Windows\System32\svchost.exeflag ru

  • THREATrating from user Boris for file C:\Windows\System32\svchost.exeflag ru

  • SAFErating from user TuliodeBree for file C:\Windows\System32\svchost.exe (Variant: 500673)

    TuliodeBree photo

    Clean.

  • THREATrating from user fgd for file C:\Windows\System32\svchost.exeflag ru

  • THREATrating from user Lscr prz for file C:\Windows\System32\svchost.exeflag es

  • THREATrating from user Vlad_St_2016 for file C:\Windows\System32\svchost.exeflag ru

  • SAFErating from user Xearo for file C:\Windows\System32\svchost.exe (Variant: 110)

    Xearo photo

    This service/File is generally part of the Microsoft operating system.. Due to the threat this file has If it is not located in %systemroot%windows/system32 Is is more than likely a virus.. If in doubt scan it with a good antivirus program.

  • SAFErating from user 808 for file C:\Windows\System32\svchost.exe (Variant: 180478)

    808 photo

    Part of Vista version 6.0.6000.16386 (vista_rtm.061101-2205)

  • THREATrating from user SpyFly for file C:\Windows\System32\svchost.exe (Variant: 502181)

    SpyFly photo

    As far as I can see, Svchost.exe es pretty easy hijacked. It takes 50% of my CPU all time. But, whatever get into it jumps to another program to keep using the 50% procesor. I "saw" when it moved to iexplorer.exe. When this happend, the svchst.exe moved down in the procesor consumtion while iexplorer.exe took over the top position with constant 50% +-2% CPU consumtion. Don't know what it is, I have used Microsoft site procedures with MS site programs (Antivirus, Checkdisk) along with McAffy Antivirus, AnviSmart, GlaryUtilities with results all the same: Sistem with no-problems. However mi PC has been taken by some program and can do no much with little part of the CPU time. Also, Idle Time of the CPU is constantly hi leaving less than 10% all the time of the CPU available to other programs.

  • THREATrating from user stillokie for file C:\Windows\System32\svchost.exe (Variant: 506308)

    stillokie photo

    I got jammed with this instance multiple times. Listed in connections tab system explorer were connections to my ports 2266 - 2270 from one IP address. Yet another connection showed connections to my ports 2161 - 2169 from a different IP address. In fact there were so many connections happening my CPU was maxed out with High Usage.

  • THREATrating from user 546354 for file C:\Windows\svchost.exeflag ru

  • THREATrating from user Ilya for file %APPDATA%\svchost.exeflag ru

  • THREATrating from user MX for file %USERPROFILE%\pwo5\svchost.exeflag pl

  • THREATrating from user MikeOne for file %SystemDiskRoot%\system32\svchost.exe (Variant: 17606)

    MikeOne photo

    Check carefully the MD5 sumcheck of this file. In this version, it is not an original part of the operating system (Generic Host Process for Win32 Services), but a Trojan.Generic.2780678 virus.

  • SAFErating from user Longwood for file C:\Windows\System32\svchost.exe (Variant: 1140279)

    Longwood photo

    The only svchost.exe i have found to be malicious was svchost.exe.32

  • SAFErating from user degert for file C:\Windows\System32\svchost.exe

  • SAFErating from user Mike for file C:\Windows\System32\svchost.exe

  • SAFErating from user its as much of a threat as Microsoft for file C:\Windows\System32\svchost.exe (Variant: 1140279)

    its as much of a threat as Microsoft photo

    Microsoft creating malicious software to combat "malicious software" (see competitors) that causes more problems than the "malicious software" ever could. -since before their was "malicious software"

  • THREATrating from user Aurikk for file C:\Windows\System32\svchost.exe

  • SAFErating from user Демерол for file C:\Windows\System32\svchost.exeflag ru

  • THREATrating from user Александр for file C:\Windows\System32\svchost.exe (Variant: 1140279)

    Александр photo

    Задрали эти файлы... опасный!

  • SAFErating from user xXx-Oimel-xXx for file C:\Windows\SysWOW64\svchost.exe (Variant: 503262)

    xXx-Oimel-xXx photo

    Jotti´s Malware Scan checker,if the Data are correct.

  • SAFErating from user young1125 for file C:\Windows\SysWOW64\svchost.exe

  • SAFErating from user Moraxv for file C:\Windows\System32\svchost.exe

  • SAFErating from user OperRu32 for file C:\Windows\System32\svchost.exe

  • SAFErating from user UPieper for file C:\Windows\System32\svchost.exe

  • SAFErating from user komele8 for file C:\Windows\SysWOW64\svchost.exe

  • SAFErating from user pablo pawlacco for file C:\Windows\System32\svchost.exe

  • SAFErating from user uasia for file C:\Windows\System32\svchost.exeflag ru

  • SAFErating from user jiku for file C:\Windows\SysWOW64\svchost.exeflag es

  • THREATrating from user husein for file C:\Windows\System32\svchost.exeflag es

  • SAFErating from user holly for file C:\Windows\SysWOW64\svchost.exeflag de

  • SAFErating from user Admin for file C:\Windows\System32\svchost.exe

  • SAFErating from user baxti1965 for file C:\Windows\System32\svchost.exe

  • SAFErating from user focu for file C:\Windows\System32\svchost.exe (Variant: 37098725)

    focu photo

    windows host service

  • SAFErating from user frangkygosal for file C:\Windows\System32\svchost.exe

  • THREATrating from user catilley1092 for file C:\Windows\System32\svchost.exe (Variant: 505275)

    catilley1092 photo

    This is obviously some type of threat, as only recently, my CPU has spiked at 100% for long periods of time. Task Manager reveals this file as being the culprit. XP Pro, OEM reinstall twice has this issue. In past reinstalls, this hasn't been an issue.

  • SAFErating from user ПУРГЕН for file C:\Windows\System32\svchost.exeflag ru

  • SAFErating from user Jurij for file C:\Windows\System32\svchost.exe

  • SAFErating from user Mindconnect2020 for file C:\Windows\System32\svchost.exe

  • SAFErating from user qwqazx for file C:\Windows\System32\svchost.exeflag ja

  • SAFErating from user doooallo for file C:\Windows\System32\svchost.exe

  • SAFErating from user robcaligari for file C:\Windows\System32\svchost.exe

  • SAFErating from user dkk for file C:\Windows\System32\svchost.exe

  • SAFErating from user GhostWalker for file C:\Windows\System32\svchost.exe

  • SAFErating from user coles for file C:\Windows\System32\svchost.exe

  • SAFErating from user msanei for file C:\Windows\System32\svchost.exe

  • SAFErating from user destiny for file C:\Windows\System32\svchost.exe

  • SAFErating from user Morphus for file C:\Windows\System32\svchost.exe (Variant: 18591755)

    Morphus photo

    its safe but stupid programmed

  • SAFErating from user SadasPoeta for file C:\Windows\System32\svchost.exe

  • THREATrating from user markpol for file %TEMP%\svchost.exe (Variant: 17473280)

    markpol photo

    svchost.exe file located in the user temp directory is most likely malicious. In this case, it was a bitcoin mining program running in the background consuming lots cpu resources.

  • THREATrating from user qq for file %TEMP%\svchost.exe (Variant: 31982324)

    qq photo

    some unknown in temp folder - Worm.Win32.Vasor virus

  • SAFErating from user noel for file %PROGRAMFILES%\sscvhost1\svchost.exe (Variant: 1338284)

    noel photo

    Good

  • THREATrating from user Jhon for file %APPDATA%\System32\svchost.EXE (Variant: 9796593)

    Jhon photo

    50% CPU; Trojan.Generic.KDV.630223 virus

  • THREATrating from user Admin for file %APPDATA%\Microsoft\svchost.exe (Variant: 2092)

    Admin photo

    Many Antiviruses detects this file as Threat (Worm.Win32.Carrier.mm).

  • THREATrating from user MikeOne for file %APPDATA%\Microsoft\svchost.exe (Variant: 2024)

    MikeOne photo

    The file svchost.exe is the Generic Host Process for Win32 Services used for administering 16-bit-based dynamically linked library files (DLL files) including other supplementary support applications. As a such file can be a common target for virus attack, so in case of any doubts scan it. Can have multiple instances in the memory. This file should be located in the %SYSTEM% directory, this location is suspicious, even that the file was marked as not containing any virus.

  • THREATrating from user MikeOne for file C:\Windows\svchost.exe (Variant: 6591)

    MikeOne photo

    Check carefully the MD5 sumcheck of this file. In this version, it is not an original part of the operating system (Generic Host Process for Win32 Services), but a Trojan.Win32.Buzus.czoc familly virus.

  • THREATrating from user MikeOne for file D:\installs\007spy\007.Spy.Software.v3.81-TBE\svchost.exe (Variant: 8332)

    MikeOne photo

    In origin, this file ia s core part of Windows system : The file svchost.exe is the Generic Host Process for Win32 Services used for administering 16-bit-based dynamically linked library files (DLL files) including other supplementary support applications. However, it can be and commonly is a target for lot of viruses. In this MD5 version, this file was marked by most antiviruses as Virus.Monitor.Win32.007SpySoft virus.

  • THREATrating from user MikeOne for file C:\Windows\System32\drivers\svchost.exe (Variant: 9684)

    MikeOne photo

    The file svchost.exe is the Generic Host Process for Win32 Services used for administering 16-bit-based dynamically linked library files (DLL files) - as such it is a common target for lot of viruses. In this MD5 version, this file was marked as Trojan-Downloader.Win32.Small by most antiviruses.

  • THREATrating from user Admin for file %APPDATA%\Microsoft\svchost.exe (Variant: 2024)

    Admin photo

    This file is not in the System directory and file description contain wrong values. This makes the file suspicious. The antiviruses don't detect it as threat but be careful.

  • THREATrating from user MikeOne for file C:\Windows\System32\0305\svchost.exe (Variant: 23633)

    MikeOne photo

    In this MD5 version, this file was marked by most antiviruses as Gen:Win32.Malware.euW@aaO!oAni virus. Remove it from Your computer. Scan is recommended. Check the MD5 hash and file location, there can more files with this name.

  • THREATrating from user MikeOne for file C:\Windows\help\svchost.exe (Variant: 29548)

    MikeOne photo

    Check carefully the MD5 sumcheck of this file. In this version, it is not an original part of the operating system (Generic Host Process for Win32 Services), but a Win-Trojan/Agent virus.

  • THREATrating from user MikeOne for file C:\Windows\svchost.exe (Variant: 45360)

    MikeOne photo

    Check carefully the MD5 sumcheck of this file. In this version, it is not an original part of the operating system (Generic Host Process for Win32 Services), but a Virus.Win32.Hidrag / Win32.Jeefo.A virus.

  • THREATrating from user MikeOne for file %USERPROFILE%\Local Settings\Application Data\Thinstall\Cache\Stubs\6346a4c562e48f33887812119671204d23f49e\svchost.exe (Variant: 62801)

    MikeOne photo

    In this MD5 version, this file was marked by most antiviruses as Win-Trojan/Unpacked virus. Remove it from Your computer. Scan is recommended. Check the MD5 hash and file location, there can more files with this name.

  • THREATrating from user MikeOne for file C:\Windows\system\svchost.exe (Variant: 68446)

    MikeOne photo

    In this MD5 version, this file was marked by most antiviruses as Backdoor.Win32.SdBot virus. Remove it from Your computer. Scan is recommended. Check the MD5 hash and file location, there can more files with this name.

  • THREATrating from user MikeOne for file %PROGRAMFILES%\Simopro\WinMatrix2\Agent\svchost.exe (Variant: 86216)

    MikeOne photo

    This file was hacked, the info is invalid. Definitelly it is not related to the Simopro Technology, Inc., the file was marked as Backdoor / Win32:Trojan-gen virus.

  • THREATrating from user Melbar for file C:\Windows\svchost.exe (Variant: 947599)

    Melbar photo

    Malware MD5: 5216AEAF53755EB5977553BA579ED3AB Dir: %WINDIR%\svchost.exe

  • THREATrating from user MikeOne for file C:\Windows\svchost.exe (Variant: 947599)

    MikeOne photo

    svchost.exe is the "Generic Host Process" for native Windows services. The Svchost.exe file is located in the %SystemRoot%\System32 folder. At startup, Svchost.exe checks the services part of the registry to construct a list of services that it must load. As a core Windows process, it can be a target for many viruses - which happend in case of this specific file. This file was infected by Trojan.Win32.Generic virus, clear it from Your computer. Check the MD5 version, there are many files with this name.

  • THREATrating from user MikeOne for file C:\Windows\System32\WinDefense32\wdi\init\svchost.exe (Variant: 154762)

    MikeOne photo

    Caught by some antivirus aplication to a virus vault - this file in this MD5 version is a virus : Backdoor.Trojan. Remove it from Your computer.

  • THREATrating from user картинки 240 320 for file C:\Windows\System32\WinDefense32\wdi\init\svchost.exe

  • THREATrating from user нержавеющие дымоходы из стали от производителя for file C:\Windows\System32\WinDefense32\wdi\init\svchost.exe (Variant: 154762)

    нержавеющие дымоходы из стали от производителя photo

    Backdoor.Trojan

  • SAFErating from user Alex for file %APPDATA%\svchost.exe

  • SAFErating from user rots for file %APPDATA%\Data\svchost.exe

  • SAFErating from user spook for file C:\Windows\System32\svchost.exe (Variant: 1140279)

    spook photo

    seems to be well behaved

  • SAFErating from user Sam for file C:\Windows\System32\svchost.exeflag ru