scvhost.eve - process or virus


  1. Posts : 3
    Windows 7 Home Premium 64 bit
       #1

    scvhost.eve - process or virus


    I have run different online scanners as well as my Norton AV, Malwarebytes, and Defender, and am fairly confident I am virus free. However, when going through the Norton Log, I came across numerous instances of where it blocked scvhost from accessing different processes. I downloaded UniBlues Process QuickLinks, to help decypher what process is what, and saw that for svchost.exe it can either be a legitimate process, or about 3 or 4 different Trojans. How on earth do you tell the legit processes apart from the virus? I understand that svchost process is needed to launch .dll files, and is legit, but can't find any info on how to tell a legit instance of it from a virus; other than understanding that enabling heuristic detection on Norton analyzes how something is running (which I always keep cranked up to High, or agressive)

    Thanks for helping me understand this! ;-)
      My Computer


  2. Posts : 2,497
    Windows 7 Pro 64 bit
       #2

    Instances of svchost.exe located in the windows\system32 folder will be legitimate. Elsewhere probably malware. You can determine this by adding the "command line" column in Task Manager, details tab. Don't confuse svchost.exe with scvhost.exe which would usually be malware. The name similarity is deliberately intended to cause confusion.
      My Computer


  3. whs
    Posts : 26,210
    Vista, Windows7, Mint Mate, Zorin, Windows 8
       #3

    The svchost.exe itself is no virus. If anything, Norton may tag a .dll running under the svchost.exe. I have, however, never seen a .dll that was found to be a virus.

    You may get more insight if you run Process Explorer and find out which .dlls are running (right click on the svchost.exe in question and go to Properties > Services tag).
      My Computer


  4. Posts : 53,363
    Windows 10 Home x64
       #4

    You might like this little program calles svchost Viewer. It will shwo you the PID of each running instance, and what processes are running under it

    svchost viewer - Home

    Clicking on each child process will give you a description. A Guy
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 09:22.
Find Us