Determining the services running under a SVCHOST.EXE process in Windows 8 The Windows 8 Task Manager makes it much easier to find what services are running under a particular SVCHOST.exe instance.

This will let you see a description of what each process is and may help you to make a decision of what to do.

I guess I can have some sleep finally! July 14, 2009 Machuku This is great, I now understand all the instances, i do hope no virus will resemble the process July 17, 2009 angel my computer ihave try so January 14, 2009 jd2066 @sawmaster: Those are not locations, they are hidden users that Windows creates for security purposes.

  • I work with .dll and .exe programs daily but am new to the field.
  • January 26, 2008 lankapo gosh, thanks for the info.
  • December 3, 2009 chris avg says this is a trojan horse… dumb ass AVG not as bad a mcafee tho lol December 4, 2009 chrisma THANK YOU for the information!
  • THANK YOU:) November 12, 2008 Dennis Thanks for the well written explaination November 13, 2008 [email protected]@noid Thanx for the info man !!
  • Added by an unidentified VIRUS, WORM or TROJAN! "Internet Config" definitely not required.
  • Great stuff!
  • Microsoft needs to take some lessons.

How can I tell if this is a legitimate svchost addition or a masquereding virus?

Such viruses auto launch because all there really is is a single exe telling what dll when to run, the moment the dll is run the dormant virus hijacks your system.

This program has been modified since it was last used." It shows the path as C:\WINDOWS\system32\ and asks me what I want to do? It is highly recommended that you run a FREE performance scan to automatically optimize memory, CPU and Internet settings. Now you can easily determine what services a particular SVCHOST process is running in Windows Vista or Windows 7.

The service tag for each thread is stored in the SubProcessTag of its thread environment block (TEB). Some examples are Ssearch.biz and Home Search Assistant.

Do you think it's safe to allow? Just a comment, I think it's irresponsible to just say "Find the service in the list that you would like to disable" How many people know what each of those services

Three run under the username "System," two under "Network Service," and one under "Local Service." Since svchost.exe has a history of being an uninvited guest to a masquerade party (i.e. Microsoft. ^ http://www.spiegel.de/media/media-35688.pdf Further reading[edit] Russinovich, Mark; Solomon, David; Ionescu, Alex (2009), Windows® Internals (5th ed.), Microsoft Press, ISBN0-7356-2530-1 Russinovich, Mark; Solomon, David; Ionescu, Alex (2012), Windows Internals.

I've only 5 instances of svchost running on my box - I think thats pretty good, though I feel that I could do without one or two instances. The .exe extension on a filename indicates an executable file. Keep up the good work.

But I do have a questions before I try all the above.

At home running McAfee and have just had BDC problems with Vista recovery - hoping trojan is not in there but heaps more svchost programs running than I recall.

The application uses ports to connect to or from a LAN or the Internet.

it mention something like "autohotkey" and its icon is a "H" letter in a green box.

An example would be: C:\WINDOWS\system32\svchost.exe -k DcomLaunch In the above command line, the svchost process will look up the ServiceDLL associated with the service name from the DcomLaunch group and load sc config trkwks start= disabled